<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: root access by oracle - how? in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454142#M744121</link>
    <description>Login as oracle and try "newgrp wheel" if this works fine ,u need to remove the group from oracle's account&lt;BR /&gt;&lt;BR /&gt;Kaps</description>
    <pubDate>Mon, 03 Jan 2005 12:59:30 GMT</pubDate>
    <dc:creator>KapilRaj</dc:creator>
    <dc:date>2005-01-03T12:59:30Z</dc:date>
    <item>
      <title>root access by oracle - how?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454136#M744115</link>
      <description>Hi all:&lt;BR /&gt;&lt;BR /&gt;HPUX 11.11 on rp7410 systems.&lt;BR /&gt;&lt;BR /&gt;I have the /etc/default/security file setup so that only the members of the group 'wheel' have access to the root account. Have tested numerous times and the respponse is "not a member of the group wheel ..." The date stamp on this file is Aug 30.&lt;BR /&gt;&lt;BR /&gt;The /etc/group file has a date stamp of Dec 6.&lt;BR /&gt;&lt;BR /&gt;Looking in the /var/adm/sulog file shows that oracle has become root on several occasions, most recently on Dec 27. &lt;BR /&gt;&lt;BR /&gt;When I login as oracle as su - I get the "not in wheel group" message. So how is oracle becoming root?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 03 Jan 2005 12:46:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454136#M744115</guid>
      <dc:creator>Rick Garland</dc:creator>
      <dc:date>2005-01-03T12:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: root access by oracle - how?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454137#M744116</link>
      <description>How many groups are associated with user oracle?? Also pwck, grpck OK??&lt;BR /&gt;&lt;BR /&gt;Anil</description>
      <pubDate>Mon, 03 Jan 2005 12:48:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454137#M744116</guid>
      <dc:creator>RAC_1</dc:creator>
      <dc:date>2005-01-03T12:48:40Z</dc:date>
    </item>
    <item>
      <title>Re: root access by oracle - how?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454138#M744117</link>
      <description>Oracle version 8.1.7.4</description>
      <pubDate>Mon, 03 Jan 2005 12:49:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454138#M744117</guid>
      <dc:creator>Rick Garland</dc:creator>
      <dc:date>2005-01-03T12:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: root access by oracle - how?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454139#M744118</link>
      <description>I don't know if this will happen if u have $ROOT_HOME/.rhosts with a line &lt;BR /&gt;&lt;BR /&gt;+ oracle&lt;BR /&gt;&lt;BR /&gt;Kaps</description>
      <pubDate>Mon, 03 Jan 2005 12:55:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454139#M744118</guid>
      <dc:creator>KapilRaj</dc:creator>
      <dc:date>2005-01-03T12:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: root access by oracle - how?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454140#M744119</link>
      <description>Also when you do su - (from oracle user), oracle's primary group should be wheel and not secondary.&lt;BR /&gt;&lt;BR /&gt;/usr/sbin/logins -d&lt;BR /&gt;&lt;BR /&gt;Anil</description>
      <pubDate>Mon, 03 Jan 2005 12:57:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454140#M744119</guid>
      <dc:creator>RAC_1</dc:creator>
      <dc:date>2005-01-03T12:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: root access by oracle - how?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454141#M744120</link>
      <description>Hi Rick,&lt;BR /&gt;&lt;BR /&gt;can you post an example of what you see in /var/adm/sulog&lt;BR /&gt;&lt;BR /&gt;grep oracle /var/adm/sulog&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;</description>
      <pubDate>Mon, 03 Jan 2005 12:57:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454141#M744120</guid>
      <dc:creator>Sanjay_6</dc:creator>
      <dc:date>2005-01-03T12:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: root access by oracle - how?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454142#M744121</link>
      <description>Login as oracle and try "newgrp wheel" if this works fine ,u need to remove the group from oracle's account&lt;BR /&gt;&lt;BR /&gt;Kaps</description>
      <pubDate>Mon, 03 Jan 2005 12:59:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454142#M744121</guid>
      <dc:creator>KapilRaj</dc:creator>
      <dc:date>2005-01-03T12:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: root access by oracle - how?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454143#M744122</link>
      <description>Example of the sulog as requested.&lt;BR /&gt;&lt;BR /&gt;grep 'oracle-root' /var/adm/sulog&lt;BR /&gt;&lt;BR /&gt;SU 12/06 09:45 - 2 oracle-root&lt;BR /&gt;SU 12/06 09:45 - 2 oracle-root&lt;BR /&gt;SU 12/06 09:45 - 2 oracle-root&lt;BR /&gt;SU 12/06 09:45 - 2 oracle-root&lt;BR /&gt;SU 12/06 09:45 - 2 oracle-root&lt;BR /&gt;SU 12/06 09:46 + 2 oracle-root&lt;BR /&gt;SU 12/06 11:39 - 1 oracle-root&lt;BR /&gt;SU 12/06 11:39 - 1 oracle-root&lt;BR /&gt;SU 12/06 11:39 - 1 oracle-root&lt;BR /&gt;SU 12/06 11:39 + 1 oracle-root&lt;BR /&gt;SU 12/07 09:37 - 2 oracle-root&lt;BR /&gt;SU 12/07 09:38 + 2 oracle-root&lt;BR /&gt;SU 12/07 09:38 - 2 oracle-root&lt;BR /&gt;SU 12/07 09:39 + 2 oracle-root&lt;BR /&gt;SU 12/13 00:55 - tb oracle-root&lt;BR /&gt;SU 12/13 00:56 - tb oracle-root&lt;BR /&gt;SU 12/13 00:56 - tb oracle-root&lt;BR /&gt;SU 12/13 00:56 + tb oracle-root&lt;BR /&gt;SU 12/14 08:57 - 6 oracle-root&lt;BR /&gt;SU 12/14 08:57 - 6 oracle-root&lt;BR /&gt;SU 12/14 08:57 + 6 oracle-root&lt;BR /&gt;SU 12/14 09:16 - 6 oracle-root&lt;BR /&gt;SU 12/14 09:17 + 6 oracle-root&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Oracle has no need to be in the wheel group and has never been. Also looked in the .rhost for root and oracle is not in there.</description>
      <pubDate>Mon, 03 Jan 2005 13:02:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454143#M744122</guid>
      <dc:creator>Rick Garland</dc:creator>
      <dc:date>2005-01-03T13:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: root access by oracle - how?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454144#M744123</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Is it possible that they have sudo access to become root. You can check that. &lt;BR /&gt;&lt;BR /&gt;You can run the last command to find out who was logged into the terminal from which the oracle became root.&lt;BR /&gt;&lt;BR /&gt;last -R -number oracle&lt;BR /&gt;&lt;BR /&gt;It may list the ip address / name of the pc/laptop from where this login session was initiated as oracle and then su'ed to root.&lt;BR /&gt;&lt;BR /&gt;on one of the system, last -R -200 oracle gave me the last 200 sessions initiated as oracle and it tells me the hostname from where the session started. Find one on the port mentioned in sulog at the time mentioned over there.&lt;BR /&gt;&lt;BR /&gt;Hope this helps.&lt;BR /&gt;&lt;BR /&gt;Regds&lt;BR /&gt;</description>
      <pubDate>Mon, 03 Jan 2005 13:15:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454144#M744123</guid>
      <dc:creator>Sanjay_6</dc:creator>
      <dc:date>2005-01-03T13:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: root access by oracle - how?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454145#M744124</link>
      <description>Hi Rick,&lt;BR /&gt;&lt;BR /&gt;did you check for scripts which are executable for "oracle" and have s-bit set for group wheel ? &lt;BR /&gt;&lt;BR /&gt;Volker&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 03 Jan 2005 13:46:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454145#M744124</guid>
      <dc:creator>Volker Borowski</dc:creator>
      <dc:date>2005-01-03T13:46:24Z</dc:date>
    </item>
    <item>
      <title>Re: root access by oracle - how?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454146#M744125</link>
      <description>did u try newgrp wheel as oracle user ? &lt;BR /&gt;&lt;BR /&gt;Kaps</description>
      <pubDate>Mon, 03 Jan 2005 14:30:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454146#M744125</guid>
      <dc:creator>KapilRaj</dc:creator>
      <dc:date>2005-01-03T14:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: root access by oracle - how?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454147#M744126</link>
      <description>Hi,&lt;BR /&gt;it might be possible for a user sharing the same uid as oracle, being a member of the wheel group. &lt;BR /&gt;Just a thought..&lt;BR /&gt; &lt;BR /&gt;regards,&lt;BR /&gt;John K.&lt;BR /&gt;</description>
      <pubDate>Mon, 03 Jan 2005 15:00:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454147#M744126</guid>
      <dc:creator>john korterman</dc:creator>
      <dc:date>2005-01-03T15:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: root access by oracle - how?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454148#M744127</link>
      <description>Issue solved.&lt;BR /&gt;&lt;BR /&gt;The PC is connecting to CDE via Reflections. Direct login via oracle. Do an su - $USER where $USER is a user that is allowed root access via the wheel group. Once this su is complete can then become root. &lt;BR /&gt;&lt;BR /&gt;Look into the sulog and it shows oracle-root. This is a logging bug. &lt;BR /&gt;&lt;BR /&gt;The oracle was not in the wheel group, could not newgrp to wheel, no rhosts entry, etc. &lt;BR /&gt;Everything is setup as it should be. It is a logging issue with the sulog.&lt;BR /&gt;&lt;BR /&gt;Many thanks to all for the ideas!&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 03 Jan 2005 15:34:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/root-access-by-oracle-how/m-p/3454148#M744127</guid>
      <dc:creator>Rick Garland</dc:creator>
      <dc:date>2005-01-03T15:34:25Z</dc:date>
    </item>
  </channel>
</rss>

