<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sudden system reboot issue in Integrity Servers</title>
    <link>https://community.hpe.com/t5/integrity-servers/sudden-system-reboot-issue/m-p/7078496#M14232</link>
    <description>&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;I am not sure what version of HP-UX is being used on this server "&lt;SPAN&gt;sdbmblv2" but you are absolutely right in saying that the user "oracle" rebooted the server twice (per shutdownlog).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;An excerpt from the man page of reboot (1M)&lt;/P&gt;&lt;P&gt;At shutdown time a message is written in the file&lt;/P&gt;&lt;P&gt;/etc/shutdownlog&lt;/P&gt;&lt;P&gt;(if it exists), containing the time of shutdown, who ran reboot, and&lt;BR /&gt;the reason.&lt;/P&gt;&lt;P&gt;Only users with appropriate privileges can run the reboot command.&lt;/P&gt;&lt;P&gt;Please take note of the last time. Also, per man page of&amp;nbsp;privileges (5), under "Privileges for System Calls"&lt;/P&gt;&lt;P&gt;reboot() PRIV_REBOOT&lt;/P&gt;&lt;P&gt;So, the user definitely seem to have the privileges.&amp;nbsp;&lt;/P&gt;&lt;P&gt;There was a potential security vulnerablity identified on HP-UX 11.11 and older versions in which local user could increase privileges. The fix was available in -&amp;nbsp;&lt;SPAN&gt;PHCO_30402&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I don't think there is any such vulnerability on later versions though.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may want to login as this user "&lt;SPAN&gt;oracle" and check it.&amp;nbsp; Also, check if this user is part of any privileged group.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Jun 2021 07:20:07 GMT</pubDate>
    <dc:creator>KishJ</dc:creator>
    <dc:date>2021-06-29T07:20:07Z</dc:date>
    <item>
      <title>Sudden system reboot issue</title>
      <link>https://community.hpe.com/t5/integrity-servers/sudden-system-reboot-issue/m-p/7078398#M14230</link>
      <description>&lt;P&gt;Dear Concern,&lt;/P&gt;&lt;P&gt;Our system is running on HP-UX 11.31 system. System rebooted last two days few time and from below log, we have found below entries.&amp;nbsp;&lt;/P&gt;&lt;P&gt;# cat /etc/shutdownlog&lt;/P&gt;&lt;P&gt;12:35 Thu Feb 6, 2020. Reboot: (by sdbmblv2!oracle)&lt;BR /&gt;12:08 Fri Feb 7, 2020. Reboot: (by sdbmblv2!oracle)&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As per my understanding, these entries mean "oracle" user reboot the system twice. My query is can "oracle" user reboot the system as it is only a normal user not superuser priviledge?&lt;/P&gt;&lt;P&gt;With Best Regards,&lt;/P&gt;&lt;P&gt;Kauser&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Feb 2020 05:02:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/integrity-servers/sudden-system-reboot-issue/m-p/7078398#M14230</guid>
      <dc:creator>Kauser</dc:creator>
      <dc:date>2020-02-08T05:02:59Z</dc:date>
    </item>
    <item>
      <title>Re: Sudden system reboot issue</title>
      <link>https://community.hpe.com/t5/integrity-servers/sudden-system-reboot-issue/m-p/7078403#M14231</link>
      <description>&lt;P&gt;Dear Concern,&lt;/P&gt;&lt;P&gt;In addition to above post, we've found no entries in /etc/shutdown.allow file.&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Kauser&lt;/P&gt;</description>
      <pubDate>Sat, 08 Feb 2020 05:53:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/integrity-servers/sudden-system-reboot-issue/m-p/7078403#M14231</guid>
      <dc:creator>Kauser</dc:creator>
      <dc:date>2020-02-08T05:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: Sudden system reboot issue</title>
      <link>https://community.hpe.com/t5/integrity-servers/sudden-system-reboot-issue/m-p/7078496#M14232</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;I am not sure what version of HP-UX is being used on this server "&lt;SPAN&gt;sdbmblv2" but you are absolutely right in saying that the user "oracle" rebooted the server twice (per shutdownlog).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;An excerpt from the man page of reboot (1M)&lt;/P&gt;&lt;P&gt;At shutdown time a message is written in the file&lt;/P&gt;&lt;P&gt;/etc/shutdownlog&lt;/P&gt;&lt;P&gt;(if it exists), containing the time of shutdown, who ran reboot, and&lt;BR /&gt;the reason.&lt;/P&gt;&lt;P&gt;Only users with appropriate privileges can run the reboot command.&lt;/P&gt;&lt;P&gt;Please take note of the last time. Also, per man page of&amp;nbsp;privileges (5), under "Privileges for System Calls"&lt;/P&gt;&lt;P&gt;reboot() PRIV_REBOOT&lt;/P&gt;&lt;P&gt;So, the user definitely seem to have the privileges.&amp;nbsp;&lt;/P&gt;&lt;P&gt;There was a potential security vulnerablity identified on HP-UX 11.11 and older versions in which local user could increase privileges. The fix was available in -&amp;nbsp;&lt;SPAN&gt;PHCO_30402&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I don't think there is any such vulnerability on later versions though.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may want to login as this user "&lt;SPAN&gt;oracle" and check it.&amp;nbsp; Also, check if this user is part of any privileged group.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 07:20:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/integrity-servers/sudden-system-reboot-issue/m-p/7078496#M14232</guid>
      <dc:creator>KishJ</dc:creator>
      <dc:date>2021-06-29T07:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: Sudden system reboot issue</title>
      <link>https://community.hpe.com/t5/integrity-servers/sudden-system-reboot-issue/m-p/7078499#M14233</link>
      <description>&lt;P&gt;Hello again,&lt;/P&gt;&lt;P&gt;You may also want to check through the documentation :HP-UX System Administrator's Guide:Security Management HP-UX 11i Version 3" -&amp;nbsp;&lt;A href="https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;amp;docId=c01944073" target="_blank"&gt;https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;amp;docId=c01944073&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 09:29:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/integrity-servers/sudden-system-reboot-issue/m-p/7078499#M14233</guid>
      <dc:creator>KishJ</dc:creator>
      <dc:date>2020-02-10T09:29:49Z</dc:date>
    </item>
  </channel>
</rss>

