<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: security issues in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/security-issues/m-p/3211221#M748713</link>
    <description>No there is no security patch bundle per se.&lt;BR /&gt;&lt;BR /&gt;The easiest way to address security patches is with the security_patch_check tool.  Download and install this tool.  &lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=B6834AA" target="_blank"&gt;http://software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=B6834AA&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;(Note that this requires Perl which can be obtained here: )&lt;BR /&gt;&lt;A href="http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=PERL" target="_blank"&gt;http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=PERL&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Then run it:&lt;BR /&gt;&lt;BR /&gt;# /opt/sec_mgmt/spc/bin/security_patch_check -r&lt;BR /&gt;&lt;BR /&gt;It will give you a list of security patches required to get your system up to date.&lt;BR /&gt;&lt;BR /&gt;With that list you can then go to the ITRC Patch database&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www1.itrc.hp.com/service/patch/mainPage.do" target="_blank"&gt;http://www1.itrc.hp.com/service/patch/mainPage.do&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Search for each patch, add it to your list and then download the whole bundle.  This will also resolve any patch dependencies as well.</description>
    <pubDate>Sat, 06 Mar 2004 12:03:41 GMT</pubDate>
    <dc:creator>Patrick Wallek</dc:creator>
    <dc:date>2004-03-06T12:03:41Z</dc:date>
    <item>
      <title>security issues</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-issues/m-p/3211220#M748712</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Is there a security patch bundle released by HP? I actually wanted to address the following issues raised by a customer.&lt;BR /&gt;&lt;BR /&gt;-NFS Exported Directories Mountable by unathorized users . &lt;BR /&gt;&lt;BR /&gt;-statd service may be vulnerable to a format string attack . &lt;BR /&gt;&lt;BR /&gt;-rpc. mountd daemon might be vulnerable to an off-by one overflow . &lt;BR /&gt;&lt;BR /&gt;-Sendmail Header Processing Buffer Overflow Vulnerability . &lt;BR /&gt;&lt;BR /&gt;-Sendmail Addredd  Prescan Possible Memory Corruption Vulnerability . &lt;BR /&gt;&lt;BR /&gt;-Sendmail  Prescan() Remote Buffer Overrun Vulnerability . &lt;BR /&gt;&lt;BR /&gt;-Multiple Vendor SNMP Request And Trap Handling Vulnerabilities. &lt;BR /&gt;&lt;BR /&gt;Thanks and Regards,&lt;BR /&gt;&lt;BR /&gt;Omar Alvi&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sat, 06 Mar 2004 06:53:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-issues/m-p/3211220#M748712</guid>
      <dc:creator>Omar Alvi_1</dc:creator>
      <dc:date>2004-03-06T06:53:25Z</dc:date>
    </item>
    <item>
      <title>Re: security issues</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-issues/m-p/3211221#M748713</link>
      <description>No there is no security patch bundle per se.&lt;BR /&gt;&lt;BR /&gt;The easiest way to address security patches is with the security_patch_check tool.  Download and install this tool.  &lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=B6834AA" target="_blank"&gt;http://software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=B6834AA&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;(Note that this requires Perl which can be obtained here: )&lt;BR /&gt;&lt;A href="http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=PERL" target="_blank"&gt;http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=PERL&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Then run it:&lt;BR /&gt;&lt;BR /&gt;# /opt/sec_mgmt/spc/bin/security_patch_check -r&lt;BR /&gt;&lt;BR /&gt;It will give you a list of security patches required to get your system up to date.&lt;BR /&gt;&lt;BR /&gt;With that list you can then go to the ITRC Patch database&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www1.itrc.hp.com/service/patch/mainPage.do" target="_blank"&gt;http://www1.itrc.hp.com/service/patch/mainPage.do&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Search for each patch, add it to your list and then download the whole bundle.  This will also resolve any patch dependencies as well.</description>
      <pubDate>Sat, 06 Mar 2004 12:03:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-issues/m-p/3211221#M748713</guid>
      <dc:creator>Patrick Wallek</dc:creator>
      <dc:date>2004-03-06T12:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: security issues</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-issues/m-p/3211222#M748714</link>
      <description>Looking for the magic security patch bundle.&lt;BR /&gt;&lt;BR /&gt;Stop looking.&lt;BR /&gt;&lt;BR /&gt;Security is based on the dilligence and time of the systems administrator. You have to stay on top of patches, keep your eyes on the net for new threats.&lt;BR /&gt;&lt;BR /&gt;There are other tools that help though.&lt;BR /&gt;&lt;BR /&gt;Security Patch Check &lt;BR /&gt;&lt;A href="http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=B6834AA" target="_blank"&gt;http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=B6834AA&lt;/A&gt; &lt;BR /&gt;&lt;BR /&gt;TCP Wrappers &lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=TCPWRAP" target="_blank"&gt;http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=TCPWRAP&lt;/A&gt; &lt;BR /&gt;&lt;BR /&gt;IDS/9000 (Intrusion Detection Sytstem) &lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=J5083AA" target="_blank"&gt;http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=J5083AA&lt;/A&gt; &lt;BR /&gt;&lt;BR /&gt;Get all these products working you'll be quite secure.&lt;BR /&gt;&lt;BR /&gt;Secure shell&lt;BR /&gt;&lt;A href="http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=T1471AA" target="_blank"&gt;http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=T1471AA&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;ipfilter&lt;BR /&gt;&lt;A href="http://software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=B9901AA" target="_blank"&gt;http://software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=B9901AA&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Also, dump any logins or transfers based on the insecure Berkley protocols. rsh.remesh.rcp.&lt;BR /&gt;&lt;BR /&gt;Permissions are key. Especially when exposed to the public Internet.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Sat, 06 Mar 2004 20:00:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-issues/m-p/3211222#M748714</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-03-06T20:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: security issues</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-issues/m-p/3211223#M748715</link>
      <description>Omar, HP can perform a security analysis/audit for you, and give solid recommendations to secure your servers.  Ping me if you want more info....&lt;BR /&gt;&lt;BR /&gt;berlene.herren@hp.com</description>
      <pubDate>Sun, 07 Mar 2004 07:13:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-issues/m-p/3211223#M748715</guid>
      <dc:creator>Berlene Herren</dc:creator>
      <dc:date>2004-03-07T07:13:47Z</dc:date>
    </item>
    <item>
      <title>Re: security issues</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-issues/m-p/3211224#M748716</link>
      <description>I might also suggest the Bastille lockdown tool.  It will help turn off services that you don't need, and help configure a firewall.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=B6849AA" target="_blank"&gt;http://www.software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=B6849AA&lt;/A&gt;</description>
      <pubDate>Sun, 07 Mar 2004 18:06:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-issues/m-p/3211224#M748716</guid>
      <dc:creator>Robert Fritz</dc:creator>
      <dc:date>2004-03-07T18:06:54Z</dc:date>
    </item>
  </channel>
</rss>

