<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dtlogin security in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/dtlogin-security/m-p/3297874#M746192</link>
    <description>My prescribed solution is as follows directed by my Platform Specialist...&lt;BR /&gt;&lt;BR /&gt;--------------------------------------------------------&lt;BR /&gt;The current fix is as follows:&lt;BR /&gt;10.x systems:  turn off dtlogin - unless users show a need for the process.  No other fix is available for this OS.&lt;BR /&gt;11.x systems:  turn off dtlogin - unless users show a need for the process - until the patches are released on thpatch.  The patches are PHSS_30668 for 11.00 and PHSS_30669 for 11.11&lt;BR /&gt;After the patches have been installed, dtlogin can be turned back on.  Patches are being tested now and are in the "stage" process - it is expected that they will be released in our next patch bundle.&lt;BR /&gt;&lt;BR /&gt;Please check if your users are using any of the "dt" processes:   dtterm, dtsession, dtgreet, etc. before you turn off dtlogin.  If they're using them, determine if they can access the server another way&lt;BR /&gt;&lt;BR /&gt;To stop the dtlogin process, type "/sbin/init.d/dtlogin.rc stop".  &lt;BR /&gt;Then, to prevent dtlogin from starting after a reboot, edit /etc/rc.config.d/desktop.  Change the value of the DESKTOP variable from CDE to "".  Here's what it looks like:&lt;BR /&gt; DESKTOP=CDE&lt;BR /&gt;  change to:&lt;BR /&gt; DESKTOP=""&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Mon, 07 Jun 2004 10:23:46 GMT</pubDate>
    <dc:creator>Todd McDaniel_1</dc:creator>
    <dc:date>2004-06-07T10:23:46Z</dc:date>
    <item>
      <title>dtlogin security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dtlogin-security/m-p/3297873#M746191</link>
      <description>I got an email regarding a security alert for dtlogin.&lt;BR /&gt;&lt;BR /&gt;-------------------------------------------------------&lt;BR /&gt;Risk Profile:  Most Unix / Linux workstations come configured with CDE and dtlogin to handle login authentication. Systems that only support ASCII login from the console and do not support any XDMCP login to a server are not affected by this vulnerability.&lt;BR /&gt;&lt;BR /&gt;Exploit:  There are exploits in the wild that an attacker can use to cause a DOS; it is not certain if there are exploits that will allow an attacker to execute arbitrary code.&lt;BR /&gt;&lt;BR /&gt;Feedback:  Future Use  &lt;BR /&gt;Products known affected: Dtlogin process associated with CDE.&lt;BR /&gt;OS known affected:  UNIX / Linux&lt;BR /&gt;-------------------------------------------------------&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;My question is this, I have users who do terminal emulation with exporting the DISPLAY. Will this affect them if I turn off dtlogin??? &lt;BR /&gt;&lt;BR /&gt;OR &lt;BR /&gt;&lt;BR /&gt;Is DTlogin ONLY for console login access? I never use it b/c we have text only consoles on all our boxes. Will this even matter?</description>
      <pubDate>Mon, 07 Jun 2004 10:22:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dtlogin-security/m-p/3297873#M746191</guid>
      <dc:creator>Todd McDaniel_1</dc:creator>
      <dc:date>2004-06-07T10:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: dtlogin security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dtlogin-security/m-p/3297874#M746192</link>
      <description>My prescribed solution is as follows directed by my Platform Specialist...&lt;BR /&gt;&lt;BR /&gt;--------------------------------------------------------&lt;BR /&gt;The current fix is as follows:&lt;BR /&gt;10.x systems:  turn off dtlogin - unless users show a need for the process.  No other fix is available for this OS.&lt;BR /&gt;11.x systems:  turn off dtlogin - unless users show a need for the process - until the patches are released on thpatch.  The patches are PHSS_30668 for 11.00 and PHSS_30669 for 11.11&lt;BR /&gt;After the patches have been installed, dtlogin can be turned back on.  Patches are being tested now and are in the "stage" process - it is expected that they will be released in our next patch bundle.&lt;BR /&gt;&lt;BR /&gt;Please check if your users are using any of the "dt" processes:   dtterm, dtsession, dtgreet, etc. before you turn off dtlogin.  If they're using them, determine if they can access the server another way&lt;BR /&gt;&lt;BR /&gt;To stop the dtlogin process, type "/sbin/init.d/dtlogin.rc stop".  &lt;BR /&gt;Then, to prevent dtlogin from starting after a reboot, edit /etc/rc.config.d/desktop.  Change the value of the DESKTOP variable from CDE to "".  Here's what it looks like:&lt;BR /&gt; DESKTOP=CDE&lt;BR /&gt;  change to:&lt;BR /&gt; DESKTOP=""&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 07 Jun 2004 10:23:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dtlogin-security/m-p/3297874#M746192</guid>
      <dc:creator>Todd McDaniel_1</dc:creator>
      <dc:date>2004-06-07T10:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: dtlogin security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dtlogin-security/m-p/3297875#M746193</link>
      <description>shameless bump...&lt;BR /&gt;&lt;BR /&gt;*taps microphone* is this thing on???&lt;BR /&gt;&lt;BR /&gt;*crickets chirping*&lt;BR /&gt;&lt;BR /&gt;*wind blows*&lt;BR /&gt;&lt;BR /&gt;*time passes*&lt;BR /&gt;&lt;BR /&gt;*paint dries* ... again.&lt;BR /&gt;&lt;BR /&gt;*counted popcorn on my ceiling* ... twice.&lt;BR /&gt;</description>
      <pubDate>Mon, 07 Jun 2004 14:29:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dtlogin-security/m-p/3297875#M746193</guid>
      <dc:creator>Todd McDaniel_1</dc:creator>
      <dc:date>2004-06-07T14:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: dtlogin security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dtlogin-security/m-p/3297876#M746194</link>
      <description>You can actually do this safely.&lt;BR /&gt;&lt;BR /&gt;Use ssh for X login.&lt;BR /&gt;&lt;BR /&gt;Hummingbird offers an add in tha uses Secure shell/oppenssh instead of the vulnerable r-protocols.&lt;BR /&gt;&lt;BR /&gt;Totally disable the nasty r-stuff in inetd.conf&lt;BR /&gt;&lt;BR /&gt;Case closed.&lt;BR /&gt;&lt;BR /&gt;Never saw this one before, sorry.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Mon, 07 Jun 2004 14:43:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dtlogin-security/m-p/3297876#M746194</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-06-07T14:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: dtlogin security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dtlogin-security/m-p/3297877#M746195</link>
      <description>Well we never use that type of console login anyway, and we dont use SSH.&lt;BR /&gt;&lt;BR /&gt;So I am really asking can I perform this without disabling any non-root exporting of DISPLAY to their desktop? Until I can get the patch loaded in a few weeks from now.</description>
      <pubDate>Mon, 07 Jun 2004 14:50:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dtlogin-security/m-p/3297877#M746195</guid>
      <dc:creator>Todd McDaniel_1</dc:creator>
      <dc:date>2004-06-07T14:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: dtlogin security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dtlogin-security/m-p/3297878#M746196</link>
      <description>btw, this is a new security problem that just came out this week...</description>
      <pubDate>Mon, 07 Jun 2004 14:50:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dtlogin-security/m-p/3297878#M746196</guid>
      <dc:creator>Todd McDaniel_1</dc:creator>
      <dc:date>2004-06-07T14:50:54Z</dc:date>
    </item>
    <item>
      <title>Re: dtlogin security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dtlogin-security/m-p/3297879#M746197</link>
      <description>Here is the CERT on it... sorry for so many posts..&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.kb.cert.org/vuls/id/179804" target="_blank"&gt;http://www.kb.cert.org/vuls/id/179804&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 07 Jun 2004 14:51:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dtlogin-security/m-p/3297879#M746197</guid>
      <dc:creator>Todd McDaniel_1</dc:creator>
      <dc:date>2004-06-07T14:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: dtlogin security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dtlogin-security/m-p/3297880#M746198</link>
      <description>Todd,&lt;BR /&gt;&lt;BR /&gt;Turning off "dtlogin" will not affect your 'export-display' programs as they use the local X-server to run.&lt;BR /&gt;&lt;BR /&gt;Only CDE-login is disabled.&lt;BR /&gt;&lt;BR /&gt;-Sri</description>
      <pubDate>Mon, 07 Jun 2004 14:53:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dtlogin-security/m-p/3297880#M746198</guid>
      <dc:creator>Sridhar Bhaskarla</dc:creator>
      <dc:date>2004-06-07T14:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: dtlogin security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/dtlogin-security/m-p/3297881#M746199</link>
      <description>Shamless plug:&lt;BR /&gt;&lt;BR /&gt;Note that HP-UX Bastille can disable this and other network listening deamons for you.&lt;BR /&gt;&lt;BR /&gt;On 11.23(and up), if you pick a security-level, this won't be on in the first place.  This can help lower the stress level for admins that prefer a "default off" approach, or want to decide interactively which services they want/need.&lt;BR /&gt;&lt;BR /&gt;The tool helps walk you through the choices by telling you what's affected when you turn something off.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=B6849AA" target="_blank"&gt;http://www.software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=B6849AA&lt;/A&gt;</description>
      <pubDate>Tue, 08 Jun 2004 10:50:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/dtlogin-security/m-p/3297881#M746199</guid>
      <dc:creator>Robert Fritz</dc:creator>
      <dc:date>2004-06-08T10:50:59Z</dc:date>
    </item>
  </channel>
</rss>

