<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: rlogin security in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/rlogin-security/m-p/2438185#M759593</link>
    <description>/etc/hosts.equiv has nothing to do with root.&lt;BR /&gt;In host-b, first, check what is the root home directory.&lt;BR /&gt;more /etc/passwd | grep root&lt;BR /&gt;and see the very right field.&lt;BR /&gt;cd to that directory.&lt;BR /&gt;ls -al |more&lt;BR /&gt;If .rhosts exists, check for host-a, or for + sign.&lt;BR /&gt;You can have something as: +   root, that allowed root from all hosts to login. &lt;BR /&gt;As a note, if you'll like to implement high security here, disable rlogin, create /etc/securetty and so on...&lt;BR /&gt;See as well&lt;BR /&gt;s700_800 11.00 r-commands cumulative mega-patch(PHNE_17028) &lt;BR /&gt; s700_800 11.00 R6.11.00 SNAplus2 services, TN3270 patch(PHNE_19613) &lt;BR /&gt; s700_800 11.00 Cumulative STREAMS Patch(PHNE_20008) &lt;BR /&gt; s700_800 11.00 cumulative ARPA Transport patch(PHNE_21767) &lt;BR /&gt; s700_800 11.00 HP DCE/9000 1.7 Integrated Login cum. patch(PHSS_17811) &lt;BR /&gt;</description>
    <pubDate>Mon, 21 Aug 2000 16:24:51 GMT</pubDate>
    <dc:creator>Antoanetta Naghiu</dc:creator>
    <dc:date>2000-08-21T16:24:51Z</dc:date>
    <item>
      <title>rlogin security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rlogin-security/m-p/2438183#M759591</link>
      <description>We have two 800 series hosts.  One of them (I'll call it host-a  ) is visible from the Internet, while the other (host-b) is not.  If I attach to host-a with an X terminal as root, I can rlogin to host-b with no password requirement.  I'm not happy with this condition.  I've looked at, and even altered, the hosts.equiv file on host-b to make sure there is no mention of host-a.  I've made sure there is, alternately, no .rhosts file in /home/root or an .rhosts file that does not include host-a at all.  No change.  I can always rlogin straight from host-a to host-b.  &lt;BR /&gt;&lt;BR /&gt;Am I missing something obvious here?  Might there be a patch for this?  I've even tried putting -host-a in the hosts.equiv file on host-b.  No change.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 21 Aug 2000 16:12:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rlogin-security/m-p/2438183#M759591</guid>
      <dc:creator>Kurt Henning</dc:creator>
      <dc:date>2000-08-21T16:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: rlogin security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rlogin-security/m-p/2438184#M759592</link>
      <description>Are you shure you have no .rhosts in / ?&lt;BR /&gt;</description>
      <pubDate>Mon, 21 Aug 2000 16:15:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rlogin-security/m-p/2438184#M759592</guid>
      <dc:creator>Victor BERRIDGE</dc:creator>
      <dc:date>2000-08-21T16:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: rlogin security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rlogin-security/m-p/2438185#M759593</link>
      <description>/etc/hosts.equiv has nothing to do with root.&lt;BR /&gt;In host-b, first, check what is the root home directory.&lt;BR /&gt;more /etc/passwd | grep root&lt;BR /&gt;and see the very right field.&lt;BR /&gt;cd to that directory.&lt;BR /&gt;ls -al |more&lt;BR /&gt;If .rhosts exists, check for host-a, or for + sign.&lt;BR /&gt;You can have something as: +   root, that allowed root from all hosts to login. &lt;BR /&gt;As a note, if you'll like to implement high security here, disable rlogin, create /etc/securetty and so on...&lt;BR /&gt;See as well&lt;BR /&gt;s700_800 11.00 r-commands cumulative mega-patch(PHNE_17028) &lt;BR /&gt; s700_800 11.00 R6.11.00 SNAplus2 services, TN3270 patch(PHNE_19613) &lt;BR /&gt; s700_800 11.00 Cumulative STREAMS Patch(PHNE_20008) &lt;BR /&gt; s700_800 11.00 cumulative ARPA Transport patch(PHNE_21767) &lt;BR /&gt; s700_800 11.00 HP DCE/9000 1.7 Integrated Login cum. patch(PHSS_17811) &lt;BR /&gt;</description>
      <pubDate>Mon, 21 Aug 2000 16:24:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rlogin-security/m-p/2438185#M759593</guid>
      <dc:creator>Antoanetta Naghiu</dc:creator>
      <dc:date>2000-08-21T16:24:51Z</dc:date>
    </item>
    <item>
      <title>Re: rlogin security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rlogin-security/m-p/2438186#M759594</link>
      <description>else your machine-b is not secured and root has no passwd...</description>
      <pubDate>Mon, 21 Aug 2000 16:26:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rlogin-security/m-p/2438186#M759594</guid>
      <dc:creator>Victor BERRIDGE</dc:creator>
      <dc:date>2000-08-21T16:26:07Z</dc:date>
    </item>
    <item>
      <title>Re: rlogin security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rlogin-security/m-p/2438187#M759595</link>
      <description>Victor and Antoanetta:&lt;BR /&gt;&lt;BR /&gt;Thank you both.  Obvious I'm still too new to this and I missed the obvious.  I assumed that root's home directory was /home/root.  It wasn't.  Someone had put a .rhosts file in root's true home directory with the offending entries in it.  I removed them.&lt;BR /&gt;</description>
      <pubDate>Mon, 21 Aug 2000 16:34:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rlogin-security/m-p/2438187#M759595</guid>
      <dc:creator>Kurt Henning</dc:creator>
      <dc:date>2000-08-21T16:34:20Z</dc:date>
    </item>
  </channel>
</rss>

