<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forums and Security in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680335#M908910</link>
    <description>Hi Martin.&lt;BR /&gt;&lt;BR /&gt;I fully agree with you.&lt;BR /&gt;&lt;BR /&gt;When no one wants to leave all these precious information on their workpalce itslef, obviously it is dangerous to leave all thess info in the forum.&lt;BR /&gt;&lt;BR /&gt;A warning message consisting of the points mentioned in you note can be displayed whenever a new user is registering in this forum as new user.&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;K.Vijay</description>
    <pubDate>Tue, 12 Mar 2002 08:58:41 GMT</pubDate>
    <dc:creator>K.Vijayaragavan.</dc:creator>
    <dc:date>2002-03-12T08:58:41Z</dc:date>
    <item>
      <title>Forums and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680321#M908896</link>
      <description>Hello Everyone,&lt;BR /&gt;&lt;BR /&gt;Just a friendly reminder to make sure that you "scrub" any system specific information that might be considered a security risk from your posts and submissions to the forums. &lt;BR /&gt;&lt;BR /&gt;This is particularly important when posting error messages from logs, many of which contain system specific information. In almost all instances this information is not required to try and resolve your issue by the forum members.&lt;BR /&gt;&lt;BR /&gt;This includes but is not limited to IP addresses, system hostnames, HP support agreement identifiers, as well as User Identification codes (User IDs), passwords, product serial numbers, etc. All of these important information elements should be protected. &lt;BR /&gt;&lt;BR /&gt;If you have any questions review the Terms of Use under User Submissions and Customer Responsibilities sections. A weblink is located at the bottom of the Forums home page. &lt;BR /&gt;&lt;BR /&gt;As always, thanks for participating in the forums and let's all practice "safe submissions".&lt;BR /&gt;&lt;BR /&gt;Martin</description>
      <pubDate>Mon, 11 Mar 2002 16:28:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680321#M908896</guid>
      <dc:creator>Martin Burnett_2</dc:creator>
      <dc:date>2002-03-11T16:28:20Z</dc:date>
    </item>
    <item>
      <title>Re: Forums and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680322#M908897</link>
      <description>Hello Martin,&lt;BR /&gt;&lt;BR /&gt;a well-meant point, which I would completly agree with, but (istn't there always a "but" ;-) taking the growth of the forums and the recent level of questions into consideration, I am afraid many will not be able to this, as they do simply not know enough to decide which information they have to hide, and what they have to substitute with *safe* values...&lt;BR /&gt;That could be a place for the forums' team to step in - those of you, who are able to decide when to *move* postings to another forum, might be able to do the *substitution*, perhaps?&lt;BR /&gt;&lt;BR /&gt;Just my $0.02,&lt;BR /&gt;Wodisch&lt;BR /&gt;</description>
      <pubDate>Mon, 11 Mar 2002 17:58:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680322#M908897</guid>
      <dc:creator>Wodisch</dc:creator>
      <dc:date>2002-03-11T17:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: Forums and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680323#M908898</link>
      <description>Martin,&lt;BR /&gt;&lt;BR /&gt;I agree with everything except for IP's, especially when someone is talking about routing and subnet masks. Most people don't understand IP's, subnet masks, and routing. By having them "scrub" them, will lead to erroneous postings and erroneous answers.&lt;BR /&gt;&lt;BR /&gt;live free or die&lt;BR /&gt;harry</description>
      <pubDate>Mon, 11 Mar 2002 18:06:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680323#M908898</guid>
      <dc:creator>harry d brown jr</dc:creator>
      <dc:date>2002-03-11T18:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: Forums and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680324#M908899</link>
      <description>Hello Wodisch,&lt;BR /&gt;&lt;BR /&gt;Excellent point and we (I) do. In fact, this is precisely what I was doing this morning for one of our forum users and is also what prompted me to write and post this little security reminder blurb. My concern is that as hard as we try we may still miss one or two posts out there that contain sensitive information. I would hate to see anyone get "cracked" because of information they posted in our forums. This was simply intended as a gentle reminder to us all. Thanks for the feedback.&lt;BR /&gt;&lt;BR /&gt;Martin&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 11 Mar 2002 18:10:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680324#M908899</guid>
      <dc:creator>Martin Burnett_2</dc:creator>
      <dc:date>2002-03-11T18:10:36Z</dc:date>
    </item>
    <item>
      <title>Re: Forums and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680325#M908900</link>
      <description>scrubbing IP's is superfluous.  using nslookup one can aquire a list of IP's for any system with internet access, and there is the freely available whois registration information for the domain.&lt;BR /&gt;&lt;BR /&gt;obviously login ID's, passwords, serial numbers and other types of "access" information is crucial not to post.  Think of the IP address as the roadmap, which one cannot hide, and the other info as they keys to the door.&lt;BR /&gt;&lt;BR /&gt;just a thought,&lt;BR /&gt;mark&lt;BR /&gt;</description>
      <pubDate>Mon, 11 Mar 2002 18:15:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680325#M908900</guid>
      <dc:creator>Mark Greene_1</dc:creator>
      <dc:date>2002-03-11T18:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: Forums and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680326#M908901</link>
      <description>Martin,&lt;BR /&gt;I do agree to a point, I certainly have seen information in a post that I would not not have posted.  But it also would not take long for someone to gather information about a postee and put two and two together. I could do this by getting the domain of the company from the postee's profile, checking dns records for that domain, finding the ip block assigned to that domain, etc... Pretty soon I have all the info I want and more.&lt;BR /&gt;&lt;BR /&gt;Keeping your messages sanitized should always be a priority, but a smart person could easily gain all that info and more if they wanted.&lt;BR /&gt;&lt;BR /&gt;Just my thoughts,&lt;BR /&gt;Craig</description>
      <pubDate>Mon, 11 Mar 2002 18:15:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680326#M908901</guid>
      <dc:creator>Craig Rants</dc:creator>
      <dc:date>2002-03-11T18:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: Forums and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680327#M908902</link>
      <description>Martin,&lt;BR /&gt;&lt;BR /&gt;I finally beat my network boy's into submission. They were always so secretive about anyone knowing our IP numbers and host names, and my reply was this: Security based upon lack of information is security based upon ignorance.&lt;BR /&gt;&lt;BR /&gt;It's like having an encryption routine where the formula is secret, and there are no "keys", just a formula.&lt;BR /&gt;&lt;BR /&gt;live free or die&lt;BR /&gt;harry</description>
      <pubDate>Mon, 11 Mar 2002 18:18:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680327#M908902</guid>
      <dc:creator>harry d brown jr</dc:creator>
      <dc:date>2002-03-11T18:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: Forums and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680328#M908903</link>
      <description>Hello Harry,&lt;BR /&gt;&lt;BR /&gt;Also a good point, and you are correct if the issue requires it. This is why I stated in the original posting that "...almost all instances this information is not required ..." This is just intended to get people thinking about whether the information they post is necessary and relevant to the issue, does it pose a security problem, and having thought about the issue then they can make their own "informed" decision about whether or not to post this type of info. Thanks for the feedback.&lt;BR /&gt;&lt;BR /&gt;Martin</description>
      <pubDate>Mon, 11 Mar 2002 18:23:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680328#M908903</guid>
      <dc:creator>Martin Burnett_2</dc:creator>
      <dc:date>2002-03-11T18:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: Forums and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680329#M908904</link>
      <description>Harry,&lt;BR /&gt;&lt;BR /&gt;funny you should mention that.  my boss at my very first job out of college would say "security based on ignorance is not secure, just ignorant!"&lt;BR /&gt;&lt;BR /&gt;I've not thought about him in a while, thanks for the reminder.  :-)&lt;BR /&gt;&lt;BR /&gt;mark</description>
      <pubDate>Mon, 11 Mar 2002 18:23:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680329#M908904</guid>
      <dc:creator>Mark Greene_1</dc:creator>
      <dc:date>2002-03-11T18:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: Forums and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680330#M908905</link>
      <description>Martin,&lt;BR /&gt;&lt;BR /&gt;Are you a newcommer to the Forum and HP, or just the Forum? If so, welcome, and thanks for the info on the Dec2001 release!&lt;BR /&gt;&lt;BR /&gt;live free or die&lt;BR /&gt;harry</description>
      <pubDate>Mon, 11 Mar 2002 18:29:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680330#M908905</guid>
      <dc:creator>harry d brown jr</dc:creator>
      <dc:date>2002-03-11T18:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: Forums and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680331#M908906</link>
      <description>Well, just new to the forums in this capacity. Sort of an additional duty due to the rapid growth in the ITRC we are experiencing thanks to all you guys and gals (experts) out there and your active participation. &lt;BR /&gt;&lt;BR /&gt;I bow to all of you and your expertise in this area. I give, uncle on the IP addresses. 8-) &lt;BR /&gt;&lt;BR /&gt;But you have to admit that this got all of you thinking about the security issues and that was my whole intent.&lt;BR /&gt;&lt;BR /&gt;Martin</description>
      <pubDate>Mon, 11 Mar 2002 18:36:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680331#M908906</guid>
      <dc:creator>Martin Burnett_2</dc:creator>
      <dc:date>2002-03-11T18:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: Forums and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680332#M908907</link>
      <description>Go top...</description>
      <pubDate>Tue, 12 Mar 2002 08:46:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680332#M908907</guid>
      <dc:creator>Carlos Fernandez Riera</dc:creator>
      <dc:date>2002-03-12T08:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: Forums and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680333#M908908</link>
      <description>I've noticed that some posters don't understand that the forums are public support.. they believe that it is an official hp support site.&lt;BR /&gt;&lt;BR /&gt;There's no doubt that you'll end up with &lt;BR /&gt;&lt;BR /&gt;telnet myserver &lt;BR /&gt;root password root&lt;BR /&gt;&lt;BR /&gt;one of these days!&lt;BR /&gt;&lt;BR /&gt;It is important to keep this tread alive somehow..&lt;BR /&gt;&lt;BR /&gt;Later,&lt;BR /&gt;Bill&lt;BR /&gt;</description>
      <pubDate>Tue, 12 Mar 2002 08:54:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680333#M908908</guid>
      <dc:creator>Bill McNAMARA_1</dc:creator>
      <dc:date>2002-03-12T08:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: Forums and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680334#M908909</link>
      <description>Hi Martin,&lt;BR /&gt;&lt;BR /&gt;Absolutely agree what you said. I always hide the information and post as much information as possible to the forum so that the experts here can solve my problem. &lt;BR /&gt;&lt;BR /&gt;If I expose any company's information here, I will be fired by my boss.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Kenny.</description>
      <pubDate>Tue, 12 Mar 2002 08:58:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680334#M908909</guid>
      <dc:creator>Kenny Chau</dc:creator>
      <dc:date>2002-03-12T08:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: Forums and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680335#M908910</link>
      <description>Hi Martin.&lt;BR /&gt;&lt;BR /&gt;I fully agree with you.&lt;BR /&gt;&lt;BR /&gt;When no one wants to leave all these precious information on their workpalce itslef, obviously it is dangerous to leave all thess info in the forum.&lt;BR /&gt;&lt;BR /&gt;A warning message consisting of the points mentioned in you note can be displayed whenever a new user is registering in this forum as new user.&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;K.Vijay</description>
      <pubDate>Tue, 12 Mar 2002 08:58:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680335#M908910</guid>
      <dc:creator>K.Vijayaragavan.</dc:creator>
      <dc:date>2002-03-12T08:58:41Z</dc:date>
    </item>
    <item>
      <title>Re: Forums and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680336#M908911</link>
      <description>Hello Martin,&lt;BR /&gt;&lt;BR /&gt;Yes this is very important information for all the forum members and it's needed for the new users as well.&lt;BR /&gt;&lt;BR /&gt;Perhaps it's a good practice that this thread or similar appears all the months and if somebody had an attack because the information showed in the forum can explain to everybody. Something like the forums issues thread for the month.&lt;BR /&gt;&lt;BR /&gt;Regards and thanks for the advertising,&lt;BR /&gt;&lt;BR /&gt;Justo.</description>
      <pubDate>Tue, 12 Mar 2002 09:49:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680336#M908911</guid>
      <dc:creator>Justo Exposito</dc:creator>
      <dc:date>2002-03-12T09:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: Forums and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680337#M908912</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I agree with you indeed.&lt;BR /&gt;&lt;BR /&gt;On occasions, I have seen posters who cut and paste their unshadowed /etc/passwd files straight onto their posting. Someone could potentially run crack on these password files.&lt;BR /&gt;&lt;BR /&gt;Such postings need to be sanitized.&lt;BR /&gt;&lt;BR /&gt;Steven Sim Kok Leong</description>
      <pubDate>Tue, 12 Mar 2002 09:57:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680337#M908912</guid>
      <dc:creator>Steven Sim Kok Leong</dc:creator>
      <dc:date>2002-03-12T09:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: Forums and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680338#M908913</link>
      <description>&lt;BR /&gt;Good point.  I dont think it is too difficult to mask information before posting it.&lt;BR /&gt;Put the output in a editor and do a find/replace all.  Ofcourse, even with all care, i have occasionally had slips.&lt;BR /&gt;&lt;BR /&gt;The reason for masking has less to do with it being misused, but more to do with company guidelines etc etc..&lt;BR /&gt;Afterall, what is anybody going to do with IPs or hostnames etc; as for people who post password file, well they shouldnt be admins in the first place ;-)&lt;BR /&gt;&lt;BR /&gt;cheers&lt;BR /&gt;-raj</description>
      <pubDate>Tue, 12 Mar 2002 13:30:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680338#M908913</guid>
      <dc:creator>Roger Baptiste</dc:creator>
      <dc:date>2002-03-12T13:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: Forums and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680339#M908914</link>
      <description>Help is help, but security must take first priority.&lt;BR /&gt;&lt;BR /&gt;Posting password files or any other sensitive information like this is a real bad thing, but then a lot of our systems are behind firewalls or not even connected to the internet and even if I gave you root passwords, you would not know which machine they go to, and could not get to them if you tried.&lt;BR /&gt;&lt;BR /&gt;More information is better than less information, but as you said, you can go too far.  Most folks don't know what information to give to solve problems and we have to ask for more anyway.&lt;BR /&gt;&lt;BR /&gt;We get all the time at work, "My computer is broke", well they don't really have a computer, they have an X-terminal, which is a computer but in a very limited way.&lt;BR /&gt;&lt;BR /&gt;The other problem is "My terminal is slow today".  That is a very hard one to solve.&lt;BR /&gt;&lt;BR /&gt;My 2 cents.</description>
      <pubDate>Tue, 12 Mar 2002 13:34:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680339#M908914</guid>
      <dc:creator>John Bolene</dc:creator>
      <dc:date>2002-03-12T13:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: Forums and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680340#M908915</link>
      <description>back to top.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Justo.</description>
      <pubDate>Tue, 12 Mar 2002 16:55:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/forums-and-security/m-p/2680340#M908915</guid>
      <dc:creator>Justo Exposito</dc:creator>
      <dc:date>2002-03-12T16:55:33Z</dc:date>
    </item>
  </channel>
</rss>

