<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: security issue using mc/sg in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595549#M715992</link>
    <description>Thanks for you suggestions Eugen.&lt;BR /&gt;&lt;BR /&gt;Chris,&lt;BR /&gt;so what your saying is that when the package switches from server 1 to server 2 and mounts the files systems the .profile that I created will be over written by the correct .profile which is part of the mounted file system thus enabling the users to carry on working. &lt;BR /&gt;&lt;BR /&gt;we user Kea which is a terminal emulator and all user have an icon for both apps on the workstation. It is when they open the wrong icon they are allowed to login even though the ip is set to the virtual address, not the hardware address.&lt;BR /&gt;&lt;BR /&gt;the mount points are on both servers so they get so far, but because there was no .profile they just drop to '/'. If you use SG maybe you could try it with one of your users and see what results you get.&lt;BR /&gt;&lt;BR /&gt;I have now asked our apps supplier to log a call with HP.&lt;BR /&gt;&lt;BR /&gt;Thanks for the help.</description>
    <pubDate>Tue, 16 Oct 2001 11:04:16 GMT</pubDate>
    <dc:creator>Jane-Marie Smith</dc:creator>
    <dc:date>2001-10-16T11:04:16Z</dc:date>
    <item>
      <title>security issue using mc/sg</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595543#M715986</link>
      <description>Have any of you guys found a security issue using mc/sg.&lt;BR /&gt;We have a two node cluster on two n4000 servers with hp-ux 11.&lt;BR /&gt;We have identical passwd files in root on both of the servers, so when the packages switch the users can carry on working. The problem is that users of server 1 package 1, can logon on to server 2, ( and vice verser)this gives the user access to file systems they should have access to.&lt;BR /&gt;Example:-&lt;BR /&gt;login: dayc&lt;BR /&gt;Password: &lt;BR /&gt;Unable to change directory to "/web/u01/home/live"&lt;BR /&gt;Logging in with home = "/".&lt;BR /&gt;They can now cause some damage if they want.&lt;BR /&gt; I have now put a block on this by creating a .profile which logs then straight backout if the do login. &lt;BR /&gt;&lt;BR /&gt;But the questions is. Will this affect the failover. IE will the .profile be over written by the correct .profile when the packages switch?&lt;BR /&gt;Any answer would be gratefull&lt;BR /&gt;</description>
      <pubDate>Tue, 16 Oct 2001 09:36:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595543#M715986</guid>
      <dc:creator>Jane-Marie Smith</dc:creator>
      <dc:date>2001-10-16T09:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: security issue using mc/sg</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595544#M715987</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Is the disk /web/.... mirrored on the other node?&lt;BR /&gt;&lt;BR /&gt;By the way, I don't see any problem with users logging on with home '/'. They don't have write access (or they shouldn't have) on it, have they?&lt;BR /&gt;&lt;BR /&gt;E.</description>
      <pubDate>Tue, 16 Oct 2001 09:43:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595544#M715987</guid>
      <dc:creator>Eugen Cocalea</dc:creator>
      <dc:date>2001-10-16T09:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: security issue using mc/sg</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595545#M715988</link>
      <description>Eugen&lt;BR /&gt;I'm afraid they do! I logged in as an application user and was able to go to my home dir and delete a file.&lt;BR /&gt;&lt;BR /&gt;the structure of the file systems exists on both servers. you have to have the mount points for SG.</description>
      <pubDate>Tue, 16 Oct 2001 10:07:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595545#M715988</guid>
      <dc:creator>Jane-Marie Smith</dc:creator>
      <dc:date>2001-10-16T10:07:25Z</dc:date>
    </item>
    <item>
      <title>Re: security issue using mc/sg</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595546#M715989</link>
      <description>Probably a silly question, but do you have that directory on server 2 for the users to go to upon logon.  Second, is this filesystem a part of the package, or is it on one of the non-shared volumes on the servers?&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Chris</description>
      <pubDate>Tue, 16 Oct 2001 10:12:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595546#M715989</guid>
      <dc:creator>Christopher McCray_1</dc:creator>
      <dc:date>2001-10-16T10:12:40Z</dc:date>
    </item>
    <item>
      <title>Re: security issue using mc/sg</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595547#M715990</link>
      <description>Hi again,&lt;BR /&gt;&lt;BR /&gt;Are you sure they don't have the same rights on the first server? I mean, if they can log on the server1 and delete a file from another users' directory?&lt;BR /&gt;&lt;BR /&gt;My assumption is that even if you log on with home / you are not root.&lt;BR /&gt;&lt;BR /&gt;Well, since I don't use mc/sg I rest my case :)&lt;BR /&gt;&lt;BR /&gt;E.</description>
      <pubDate>Tue, 16 Oct 2001 10:23:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595547#M715990</guid>
      <dc:creator>Eugen Cocalea</dc:creator>
      <dc:date>2001-10-16T10:23:18Z</dc:date>
    </item>
    <item>
      <title>Re: security issue using mc/sg</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595548#M715991</link>
      <description>I think maybe I understand your question (???)&lt;BR /&gt;&lt;BR /&gt;You have a package on server 1 that users log into.  Your issue is that when the package is there, people who log into server2 can't go to the directory they need to because it's onn the other server, so it puts them into /.  You want to know what the implications are?  One, your package has an ip address to which you should have a "virtual hostname" defined for it in either /etc/hosts or in dns.  That "hostname" is the one you should give to your users so that no matter where the package is, they will always log into where the application is and not /, where they can do damage.  This will not impact the failover because the filesystems are umounted off server1 and remounted on server2.&lt;BR /&gt;&lt;BR /&gt; Hope this helps,&lt;BR /&gt;Chris</description>
      <pubDate>Tue, 16 Oct 2001 10:29:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595548#M715991</guid>
      <dc:creator>Christopher McCray_1</dc:creator>
      <dc:date>2001-10-16T10:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: security issue using mc/sg</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595549#M715992</link>
      <description>Thanks for you suggestions Eugen.&lt;BR /&gt;&lt;BR /&gt;Chris,&lt;BR /&gt;so what your saying is that when the package switches from server 1 to server 2 and mounts the files systems the .profile that I created will be over written by the correct .profile which is part of the mounted file system thus enabling the users to carry on working. &lt;BR /&gt;&lt;BR /&gt;we user Kea which is a terminal emulator and all user have an icon for both apps on the workstation. It is when they open the wrong icon they are allowed to login even though the ip is set to the virtual address, not the hardware address.&lt;BR /&gt;&lt;BR /&gt;the mount points are on both servers so they get so far, but because there was no .profile they just drop to '/'. If you use SG maybe you could try it with one of your users and see what results you get.&lt;BR /&gt;&lt;BR /&gt;I have now asked our apps supplier to log a call with HP.&lt;BR /&gt;&lt;BR /&gt;Thanks for the help.</description>
      <pubDate>Tue, 16 Oct 2001 11:04:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595549#M715992</guid>
      <dc:creator>Jane-Marie Smith</dc:creator>
      <dc:date>2001-10-16T11:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: security issue using mc/sg</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595550#M715993</link>
      <description>Again, I may be just a little off here, but you have identical /etc/passwds on both machines and each user has there home directory defined there.  From what I  can tell, the home directory you have each user accessing is at the very least /web, which is a packaged file system.  That being the case, if the package is on server1 and a user logs directly into server2, they will not be able to access their home directory because its on the other server.  I believe that your created .profile will be overwritten by the one in  the package, but that is okay.  Again I don't have any actual data from your machine, but this is what I think you are experiencing.  Prevent your users from logging into the other server when the package is not there by providing them with the "virtual host" associated with the package.  I hope I cleared things up for you.&lt;BR /&gt;&lt;BR /&gt;Chris</description>
      <pubDate>Tue, 16 Oct 2001 12:05:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595550#M715993</guid>
      <dc:creator>Christopher McCray_1</dc:creator>
      <dc:date>2001-10-16T12:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: security issue using mc/sg</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595551#M715994</link>
      <description>One solution is to create that home directory on both servers when the filesystem is NOT mounted. This will ensure that the directory exists when the user performs the login. You can put a .profile into the directory that logs a message that the package is currently not running on this node and performs an exit (ie. the user is logged off). &lt;BR /&gt;&lt;BR /&gt;When the package is started the logical volume will be mounted and will simply cover these directories, thus replacing everything with the real environment. &lt;BR /&gt;&lt;BR /&gt;When you do this, you should make sure to use one of the latest package control scripts (SG 11.12) that frees busy mountpoints (when processes/users keep the mountpoint busy, the mount command will fail, hence the package won't start). &lt;BR /&gt;&lt;BR /&gt;Carsten</description>
      <pubDate>Tue, 16 Oct 2001 12:50:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595551#M715994</guid>
      <dc:creator>Carsten Krege</dc:creator>
      <dc:date>2001-10-16T12:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: security issue using mc/sg</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595552#M715995</link>
      <description>Another suggestion would be put something in /etc/profile so that if the user doesn't have a valid home directory, it kicks them off, i.e. something like:&lt;BR /&gt;&lt;BR /&gt;# Check for valid home directory&lt;BR /&gt;&lt;BR /&gt;if [ ! -d ${HOME} ]&lt;BR /&gt;then&lt;BR /&gt;        echo "Unable to change directory to ${HOME}"&lt;BR /&gt;        exit 1&lt;BR /&gt;fi&lt;BR /&gt;&lt;BR /&gt;-Santosh</description>
      <pubDate>Tue, 16 Oct 2001 14:51:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595552#M715995</guid>
      <dc:creator>Santosh Nair_1</dc:creator>
      <dc:date>2001-10-16T14:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: security issue using mc/sg</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595553#M715996</link>
      <description>Santosh,&lt;BR /&gt;&lt;BR /&gt;Thanks very much. It worked.&lt;BR /&gt;JMS</description>
      <pubDate>Wed, 17 Oct 2001 07:10:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595553#M715996</guid>
      <dc:creator>Jane-Marie Smith</dc:creator>
      <dc:date>2001-10-17T07:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: security issue using mc/sg</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595554#M715997</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;I have not read the whole thread but I had something similar in the past.  So if it is a repeat of an above solution sorry.&lt;BR /&gt;&lt;BR /&gt;1 users must have a home directory on the serviceguarded VG that is mounted on (for example) /home/SGusers/&lt;BR /&gt;&lt;BR /&gt;2 in the SG filesystem have the regular user .profile&lt;BR /&gt;&lt;BR /&gt;3 create a dummy .profile on both/all hosts in /home/SGusers/. that kicks off the users.&lt;BR /&gt;&lt;BR /&gt;What happens when the user logs into the active node the mounted filesystem .profile will be used.  If they log in and SG is not active the .profile under the mount point will now be visible &amp;amp; log them off.&lt;BR /&gt;&lt;BR /&gt;Just one observation the users should really only use the floating IP, then the above would be redundant!&lt;BR /&gt;&lt;BR /&gt;Cheers&lt;BR /&gt;&lt;BR /&gt;Tim</description>
      <pubDate>Wed, 17 Oct 2001 14:07:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595554#M715997</guid>
      <dc:creator>Tim D Fulford</dc:creator>
      <dc:date>2001-10-17T14:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: security issue using mc/sg</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595555#M715998</link>
      <description>ServiceGuard has a relocatable IP/package alias feature which routes login attempts to the server operating the package, precluding any need for a user attempt to login to a specific server.&lt;BR /&gt;&lt;BR /&gt;Can it be implemented with the terminal emulator involved?&lt;BR /&gt;&lt;BR /&gt;-Stephen</description>
      <pubDate>Thu, 18 Oct 2001 15:34:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-issue-using-mc-sg/m-p/2595555#M715998</guid>
      <dc:creator>Stephen Doud</dc:creator>
      <dc:date>2001-10-18T15:34:36Z</dc:date>
    </item>
  </channel>
</rss>

