<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security scan tools in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/security-scan-tools/m-p/2743510#M944112</link>
    <description>Hi,&lt;BR /&gt;&lt;BR /&gt;For databases, the ISS Database Scanner works very well in scanning for Oracle-level security loopholes. I am pleased with it. Too bad there isn't one for SAP R/3 level as yet.&lt;BR /&gt;&lt;BR /&gt;There are two modes, one for normal scan, the other for penetration test.&lt;BR /&gt;&lt;BR /&gt;The database scan test will scan for invalid password policies, poor passwords, poorly assigned table privileges and roles etc. It will also call the ISS Internet Scanner if it is available on the scanner system.&lt;BR /&gt;&lt;BR /&gt;The penetration test will try to compromise an Oracle account on your system and read from the hashed password tables to crack additional Oracle passwords.&lt;BR /&gt;&lt;BR /&gt;Note that you will need the Oracle Net8 (sqlnet) client to be installed on the scanner system to allow it to connect to the scanned system for performing the audits.&lt;BR /&gt;&lt;BR /&gt;Hope this helps. Regards.&lt;BR /&gt;&lt;BR /&gt;Steven Sim Kok Leong</description>
    <pubDate>Thu, 13 Jun 2002 01:30:14 GMT</pubDate>
    <dc:creator>Steven Sim Kok Leong</dc:creator>
    <dc:date>2002-06-13T01:30:14Z</dc:date>
    <item>
      <title>Security scan tools</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-scan-tools/m-p/2743508#M944110</link>
      <description>Anyone have any information on a good security scan tool that can be run from a desktop PC instead of installing on the actual server?&lt;BR /&gt;</description>
      <pubDate>Wed, 12 Jun 2002 23:19:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-scan-tools/m-p/2743508#M944110</guid>
      <dc:creator>Tony Romero</dc:creator>
      <dc:date>2002-06-12T23:19:21Z</dc:date>
    </item>
    <item>
      <title>Re: Security scan tools</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-scan-tools/m-p/2743509#M944111</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;The only one I know of (there could be more) is ESM. From what I remember of this you load a client on your HPUX server and run a 'server' session from either a PC or an NT workstation.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.enterprise-security.com/unixsecurity.htm" target="_blank"&gt;http://www.enterprise-security.com/unixsecurity.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;HTH&lt;BR /&gt;~Michael~</description>
      <pubDate>Wed, 12 Jun 2002 23:47:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-scan-tools/m-p/2743509#M944111</guid>
      <dc:creator>Michael Tully</dc:creator>
      <dc:date>2002-06-12T23:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: Security scan tools</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-scan-tools/m-p/2743510#M944112</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;For databases, the ISS Database Scanner works very well in scanning for Oracle-level security loopholes. I am pleased with it. Too bad there isn't one for SAP R/3 level as yet.&lt;BR /&gt;&lt;BR /&gt;There are two modes, one for normal scan, the other for penetration test.&lt;BR /&gt;&lt;BR /&gt;The database scan test will scan for invalid password policies, poor passwords, poorly assigned table privileges and roles etc. It will also call the ISS Internet Scanner if it is available on the scanner system.&lt;BR /&gt;&lt;BR /&gt;The penetration test will try to compromise an Oracle account on your system and read from the hashed password tables to crack additional Oracle passwords.&lt;BR /&gt;&lt;BR /&gt;Note that you will need the Oracle Net8 (sqlnet) client to be installed on the scanner system to allow it to connect to the scanned system for performing the audits.&lt;BR /&gt;&lt;BR /&gt;Hope this helps. Regards.&lt;BR /&gt;&lt;BR /&gt;Steven Sim Kok Leong</description>
      <pubDate>Thu, 13 Jun 2002 01:30:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-scan-tools/m-p/2743510#M944112</guid>
      <dc:creator>Steven Sim Kok Leong</dc:creator>
      <dc:date>2002-06-13T01:30:14Z</dc:date>
    </item>
    <item>
      <title>Re: Security scan tools</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-scan-tools/m-p/2743511#M944113</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I forgot to give you the link:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.iss.net" target="_blank"&gt;http://www.iss.net&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;You can download a trial, request for a trial license to test your test database on.&lt;BR /&gt;&lt;BR /&gt;Hope this helps. Regards.&lt;BR /&gt;&lt;BR /&gt;Steven Sim Kok Leong</description>
      <pubDate>Thu, 13 Jun 2002 01:32:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-scan-tools/m-p/2743511#M944113</guid>
      <dc:creator>Steven Sim Kok Leong</dc:creator>
      <dc:date>2002-06-13T01:32:28Z</dc:date>
    </item>
    <item>
      <title>Re: Security scan tools</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-scan-tools/m-p/2743512#M944114</link>
      <description>Check &lt;A href="http://www.cisecurity.org/" target="_blank"&gt;http://www.cisecurity.org/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I haven't yet run the HP-UX&lt;BR /&gt;tools, but the Cisco tools&lt;BR /&gt;run remotely.  A quick look&lt;BR /&gt;indicates that server access&lt;BR /&gt;may be required.&lt;BR /&gt;&lt;BR /&gt;You could also try any of the&lt;BR /&gt;satan derivitives.  I don't&lt;BR /&gt;know of any for Windows,&lt;BR /&gt;but you should be able to&lt;BR /&gt;have an old 486 up and running&lt;BR /&gt;Linux and scanning within&lt;BR /&gt;an hour or two.&lt;BR /&gt;</description>
      <pubDate>Thu, 13 Jun 2002 13:09:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-scan-tools/m-p/2743512#M944114</guid>
      <dc:creator>Bill Thorsteinson</dc:creator>
      <dc:date>2002-06-13T13:09:42Z</dc:date>
    </item>
  </channel>
</rss>

