<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CD/DVD WRITE DISABLE in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265897#M472689</link>
    <description>To disallow CD/DVD writing, simply don't create a /dev/rscsi/c#t#d# device for the CD/DVD burner. You cannot burn CDs without that device, and HP-UX won't create it automatically for you: root must always create that device manually, or using a script that comes with the CD burning software.&lt;BR /&gt;&lt;BR /&gt;If someone has already created that device node, remove it, or set its permissions to root access only. &lt;BR /&gt;&lt;BR /&gt;You seem to be trying to prepare a HP-UX system for processing some sort of sensitive information. Would you like some friendly advice?&lt;BR /&gt;&lt;BR /&gt;(Whoa, I think I was channeling Clippy there. Anyway...)&lt;BR /&gt;&lt;BR /&gt;You should keep in mind that physical access (the ability to poke the server with fingers and tools) to the server will trump most software security mechanisms. If you are planning to handle sensitive information, putting the server behind locked doors should be your *first* step. &lt;BR /&gt;&lt;BR /&gt;Once your server is physically accessible by trusted personnel only, the problem of a writable CD/DVD should also be mostly solved: a writable CD/DVD drive is not useful to an unauthorized person if he/she cannot insert a blank CD/DVD.&lt;BR /&gt;&lt;BR /&gt;When thinking about software-level security mechanisms, you should remember this: *anything* root can do, root can also undo. The OS cannot protect the system against a malicious person who has real root access, because with root access the malicious person can disable or override the protection mechanisms of the OS.&lt;BR /&gt;&lt;BR /&gt;MK</description>
    <pubDate>Wed, 08 Dec 2010 19:55:29 GMT</pubDate>
    <dc:creator>Matti_Kurkela</dc:creator>
    <dc:date>2010-12-08T19:55:29Z</dc:date>
    <item>
      <title>CD/DVD WRITE DISABLE</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265896#M472688</link>
      <description>&lt;!--!*#--&gt;If a system has a writable CD/DVD, is there an EASY method for root to permanently disable that facility, IE: via specific device file changes and/or any other mods?&lt;BR /&gt;&lt;BR /&gt;Please be specific.&lt;BR /&gt;&lt;BR /&gt;Thx.&lt;BR /&gt;</description>
      <pubDate>Wed, 08 Dec 2010 18:08:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265896#M472688</guid>
      <dc:creator>john guardian</dc:creator>
      <dc:date>2010-12-08T18:08:41Z</dc:date>
    </item>
    <item>
      <title>Re: CD/DVD WRITE DISABLE</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265897#M472689</link>
      <description>To disallow CD/DVD writing, simply don't create a /dev/rscsi/c#t#d# device for the CD/DVD burner. You cannot burn CDs without that device, and HP-UX won't create it automatically for you: root must always create that device manually, or using a script that comes with the CD burning software.&lt;BR /&gt;&lt;BR /&gt;If someone has already created that device node, remove it, or set its permissions to root access only. &lt;BR /&gt;&lt;BR /&gt;You seem to be trying to prepare a HP-UX system for processing some sort of sensitive information. Would you like some friendly advice?&lt;BR /&gt;&lt;BR /&gt;(Whoa, I think I was channeling Clippy there. Anyway...)&lt;BR /&gt;&lt;BR /&gt;You should keep in mind that physical access (the ability to poke the server with fingers and tools) to the server will trump most software security mechanisms. If you are planning to handle sensitive information, putting the server behind locked doors should be your *first* step. &lt;BR /&gt;&lt;BR /&gt;Once your server is physically accessible by trusted personnel only, the problem of a writable CD/DVD should also be mostly solved: a writable CD/DVD drive is not useful to an unauthorized person if he/she cannot insert a blank CD/DVD.&lt;BR /&gt;&lt;BR /&gt;When thinking about software-level security mechanisms, you should remember this: *anything* root can do, root can also undo. The OS cannot protect the system against a malicious person who has real root access, because with root access the malicious person can disable or override the protection mechanisms of the OS.&lt;BR /&gt;&lt;BR /&gt;MK</description>
      <pubDate>Wed, 08 Dec 2010 19:55:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265897#M472689</guid>
      <dc:creator>Matti_Kurkela</dc:creator>
      <dc:date>2010-12-08T19:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: CD/DVD WRITE DISABLE</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265898#M472690</link>
      <description>&lt;!--!*#--&gt;Define "permanently".&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Please be specific.&lt;BR /&gt;&lt;BR /&gt;You first.  What is your actual requirement?&lt;BR /&gt;The best actual solution may be to lock the&lt;BR /&gt;door, not to try to hobble the software, and&lt;BR /&gt;keep it hobbled "permanently".  (Or did you&lt;BR /&gt;intend to run a cron job to check on this&lt;BR /&gt;stuff every few minutes to make sure that no&lt;BR /&gt;one has removed the hobbles?)&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums.itrc.hp.com/service/forums/questionanswer.do?threadId=1459606" target="_blank"&gt;http://forums.itrc.hp.com/service/forums/questionanswer.do?threadId=1459606&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Spreading the same problem across multiple&lt;BR /&gt;threads may not be the best path to the best&lt;BR /&gt;solution.  (My first thought on reading this&lt;BR /&gt;post was, "What about the USB ports?".)</description>
      <pubDate>Wed, 08 Dec 2010 20:10:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265898#M472690</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2010-12-08T20:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: CD/DVD WRITE DISABLE</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265899#M472691</link>
      <description>We have a similar requirement and our solution it to only ever install read-only CD/DVD drives in our servers.</description>
      <pubDate>Thu, 09 Dec 2010 00:19:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265899#M472691</guid>
      <dc:creator>KathyL1</dc:creator>
      <dc:date>2010-12-09T00:19:05Z</dc:date>
    </item>
    <item>
      <title>Re: CD/DVD WRITE DISABLE</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265900#M472692</link>
      <description>&lt;!--!*#--&gt;&amp;gt; [...] our solution [...]&lt;BR /&gt;&lt;BR /&gt;Some years ago, I had occasion to visit a&lt;BR /&gt;certain government-operated facility which&lt;BR /&gt;employed armed guards and labyrinthine&lt;BR /&gt;hallways.  It was a "medium motel":  The&lt;BR /&gt;media check in, but they don't check out.&lt;BR /&gt;&lt;BR /&gt;Physical security has its limitations, too&lt;BR /&gt;(like, say, a trusted senior employee with a&lt;BR /&gt;9-track tape under his coat), but it's&lt;BR /&gt;probably wiser to be aware of those&lt;BR /&gt;limitations than it is to believe that&lt;BR /&gt;there's some simple technical fix to a very&lt;BR /&gt;complex problem, and then relax.</description>
      <pubDate>Thu, 09 Dec 2010 03:59:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265900#M472692</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2010-12-09T03:59:26Z</dc:date>
    </item>
    <item>
      <title>Re: CD/DVD WRITE DISABLE</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265901#M472693</link>
      <description>but there is a simple way........&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;physically remove the CD/DVD RW hardware from the server</description>
      <pubDate>Thu, 09 Dec 2010 22:23:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265901#M472693</guid>
      <dc:creator>Tim Nelson</dc:creator>
      <dc:date>2010-12-09T22:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: CD/DVD WRITE DISABLE</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265902#M472694</link>
      <description>&lt;!--!*#--&gt;&amp;gt; but there is a simple way........&lt;BR /&gt;&amp;gt;&lt;BR /&gt;&amp;gt;&lt;BR /&gt;&amp;gt; physically remove the CD/DVD RW hardware&lt;BR /&gt;&amp;gt; from the server&lt;BR /&gt;&lt;BR /&gt;Simple, but not particularly effective, if a&lt;BR /&gt;user can plug in his own USB-interface drive.&lt;BR /&gt;(Or SCSI, or ...)&lt;BR /&gt;&lt;BR /&gt;Everything's complicated.  (If you don't&lt;BR /&gt;think so, then think more.  Or better.  But,&lt;BR /&gt;"If you don't think too good, don't think too&lt;BR /&gt;much.")</description>
      <pubDate>Thu, 09 Dec 2010 23:24:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265902#M472694</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2010-12-09T23:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: CD/DVD WRITE DISABLE</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265903#M472695</link>
      <description>Kinda late to this post, but i've just run across a similar requirement on some Linux systems to disable CD/DVD write access.&lt;BR /&gt;&lt;BR /&gt;This was accomplished by removing read/execute permissions on the following executables that perform these write operations:&lt;BR /&gt;&lt;BR /&gt;chmod 770 /usr/bin/cdrecord&lt;BR /&gt;chmod 770 /usr/bin/growisofs&lt;BR /&gt;&lt;BR /&gt;You may want to start with these and then check for other programs that do this and restrict read/execute to them as well.</description>
      <pubDate>Thu, 03 Feb 2011 20:05:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265903#M472695</guid>
      <dc:creator>Autocross.US</dc:creator>
      <dc:date>2011-02-03T20:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: CD/DVD WRITE DISABLE</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265904#M472696</link>
      <description>I'm not sure where the issue is.&lt;BR /&gt;&lt;BR /&gt;If you want to write to a CD, you must have physical access to the CD drive to insert a media.&lt;BR /&gt;&lt;BR /&gt;Restrict the physical access like everyone is doing.&lt;BR /&gt;&lt;BR /&gt;Since you usually need to be root to have write access, don't allow root access to others.&lt;BR /&gt;&lt;BR /&gt;Any action done by root to prevent write access can be reverted by "another" root user.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;However, IMHO to allow any kind of  network access is much more dangerous ... ;-)&lt;BR /&gt;</description>
      <pubDate>Thu, 03 Feb 2011 20:14:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265904#M472696</guid>
      <dc:creator>Torsten.</dc:creator>
      <dc:date>2011-02-03T20:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: CD/DVD WRITE DISABLE</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265905#M472697</link>
      <description>All input was appreciated. Ultimately, the physical devices were removed as I had originally advised my mgmt to do.&lt;BR /&gt;&lt;BR /&gt;Thx to all who responded.</description>
      <pubDate>Thu, 03 Feb 2011 20:31:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265905#M472697</guid>
      <dc:creator>john guardian</dc:creator>
      <dc:date>2011-02-03T20:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: CD/DVD WRITE DISABLE</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265906#M472698</link>
      <description>Please allow this question:&lt;BR /&gt;&lt;BR /&gt;Is this requirement made by non-technical management alerted by some articles in newspapers about swiss bank account data sold to several european governments on CD-Rs?&lt;BR /&gt;&lt;BR /&gt;LOL! &lt;BR /&gt;&lt;BR /&gt;If anyone would like to get some data from the server with bad intentions, I think the very last choice would be to burn them on the server itself ...&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;just my 2 cents ...</description>
      <pubDate>Thu, 03 Feb 2011 20:45:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cd-dvd-write-disable/m-p/5265906#M472698</guid>
      <dc:creator>Torsten.</dc:creator>
      <dc:date>2011-02-03T20:45:17Z</dc:date>
    </item>
  </channel>
</rss>

