<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Telnet LD_LIBRARY_PATH in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/telnet-ld-library-path/m-p/2823617#M754713</link>
    <description>After Cybercop scan, a vulnerability of my workstation (HPUX10.20) was found: 'Telnet LD_LIBRARY_PATH'.&lt;BR /&gt;  How to resolve it?</description>
    <pubDate>Fri, 11 Oct 2002 03:48:10 GMT</pubDate>
    <dc:creator>Platinum</dc:creator>
    <dc:date>2002-10-11T03:48:10Z</dc:date>
    <item>
      <title>Telnet LD_LIBRARY_PATH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/telnet-ld-library-path/m-p/2823617#M754713</link>
      <description>After Cybercop scan, a vulnerability of my workstation (HPUX10.20) was found: 'Telnet LD_LIBRARY_PATH'.&lt;BR /&gt;  How to resolve it?</description>
      <pubDate>Fri, 11 Oct 2002 03:48:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/telnet-ld-library-path/m-p/2823617#M754713</guid>
      <dc:creator>Platinum</dc:creator>
      <dc:date>2002-10-11T03:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet LD_LIBRARY_PATH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/telnet-ld-library-path/m-p/2823618#M754714</link>
      <description>Have a look at this posting:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums.itrc.hp.com/cm/QuestionAnswer/1,,0x87ce35067c18d6118ff40090279cd0f9,00.html" target="_blank"&gt;http://forums.itrc.hp.com/cm/QuestionAnswer/1,,0x87ce35067c18d6118ff40090279cd0f9,00.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;You could also look into utilising HP-UX Bastille for a second opinion.&lt;BR /&gt;&lt;A href="http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=B6849AA" target="_blank"&gt;http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=B6849AA&lt;/A&gt;</description>
      <pubDate>Fri, 11 Oct 2002 04:04:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/telnet-ld-library-path/m-p/2823618#M754714</guid>
      <dc:creator>Michael Tully</dc:creator>
      <dc:date>2002-10-11T04:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet LD_LIBRARY_PATH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/telnet-ld-library-path/m-p/2823619#M754715</link>
      <description>As long as the suid bit is not set on telnet (the one that Cybercop found with the problem), then this is not a security problem.  LD_LIBRARY_PATH and SHLIB_PATH can in some cases be used to modify the behavior of a binary.&lt;BR /&gt;&lt;BR /&gt;If, however, no suid bit is set, then the user could instead copy the binary and hack it himself to do whatever he wanted.  It would still run in that user's process space; there would be no additional risks of privilege elevation.&lt;BR /&gt;&lt;BR /&gt;As far as Bastille is concerned, it currently only supports HP-UX 11.00 and 11.11.  However, if you were to run it, it would recommend that you change to Secure Shell.  Telnet is by nature a clear-text, spoofable protocol.  It's still around because a lot of people are used to it, but it can be completely replaced with Secure Shell which uses an encrypted, spoof-protected protocol.&lt;BR /&gt;&lt;BR /&gt;If you care enough about security to run Cybercop, then it's probably best to start running secure protocols to start with.&lt;BR /&gt;&lt;BR /&gt;Now, if you'd like to make Cypercop stop complaining about a false alarm, the 'chatr' command may be used to modify the binary to get rid of LD_LIBRARY_PATH.  Be careful...if you depend on telnet and it breaks, then you'll be a bit stuck.  (I'd give more details, but I don't want to confuse the issue talking about telnet vs. telnetd...and I don't know which Cybercop is really complaining about.)</description>
      <pubDate>Sat, 12 Oct 2002 15:13:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/telnet-ld-library-path/m-p/2823619#M754715</guid>
      <dc:creator>Keith Buck</dc:creator>
      <dc:date>2002-10-12T15:13:04Z</dc:date>
    </item>
  </channel>
</rss>

