<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VMS intruder from telnet session in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/vms-intruder-from-telnet-session/m-p/4871085#M20309</link>
    <description>You may wish to look at setting system parameter LGI_BRK_TERM to 0. From the HELP on VMS V7.1&lt;BR /&gt;Parameters&lt;BR /&gt;&lt;BR /&gt;  LGI_BRK_TERM&lt;BR /&gt;&lt;BR /&gt;       LGI_BRK_TERM causes the terminal name to be part of the&lt;BR /&gt;       association string for the terminal mode of break-in detection.&lt;BR /&gt;       When off (0),  association is done on user name only. LGI_BRK_&lt;BR /&gt;       TERM is set by default (1).  It should be cleared if physical&lt;BR /&gt;       terminal names are created dynamically (that is, if LAT is&lt;BR /&gt;       installed) and effective break-in detection is desired.&lt;BR /&gt;&lt;BR /&gt;       LGI_BRK_TERM is a DYNAMIC parameter.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Wed, 17 Nov 2004 13:17:48 GMT</pubDate>
    <dc:creator>Ian Miller.</dc:creator>
    <dc:date>2004-11-17T13:17:48Z</dc:date>
    <item>
      <title>VMS intruder from telnet session</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-intruder-from-telnet-session/m-p/4871082#M20306</link>
      <description>VMS V7.3-x recognize a telnet session with remote TCP/IP adress, and the login is not allowed after LGI_BRK_LIM.&lt;BR /&gt;&lt;BR /&gt;Sourcee &amp;gt;  Node::TELNET_AC103B05&lt;BR /&gt;----------------------------------&lt;BR /&gt;VMS V7.1 the port number change after login failure, and the intrusion mechanism don't detect an intruder from an incoming telnet session.&lt;BR /&gt;&lt;BR /&gt;Host: 172.16.10.10 Port: 1440:USER&lt;BR /&gt;-----------------------------------&lt;BR /&gt;We can't upgrade VMS......&lt;BR /&gt;Is a way to use the intrusion mechanism with VMS 7.1 ?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;</description>
      <pubDate>Wed, 17 Nov 2004 11:46:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-intruder-from-telnet-session/m-p/4871082#M20306</guid>
      <dc:creator>dvanwingen</dc:creator>
      <dc:date>2004-11-17T11:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: VMS intruder from telnet session</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-intruder-from-telnet-session/m-p/4871083#M20307</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Welcome to the VMS forum.&lt;BR /&gt;&lt;BR /&gt;This is an TCPIP issue. Can you tell us the version of TCPIP? Symply do:&lt;BR /&gt;$ UCX SHOW VERSION&lt;BR /&gt;&lt;BR /&gt;Bojan</description>
      <pubDate>Wed, 17 Nov 2004 12:52:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-intruder-from-telnet-session/m-p/4871083#M20307</guid>
      <dc:creator>Bojan Nemec</dc:creator>
      <dc:date>2004-11-17T12:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: VMS intruder from telnet session</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-intruder-from-telnet-session/m-p/4871084#M20308</link>
      <description>If you run TCP/IP Services for OpenVMS V5.0A, there is a patch for this. Please see the description in: &lt;A href="http://ftp.support.compaq.com.au/pub/ecoinfo/ecoinfo/387.htm" target="_blank"&gt;http://ftp.support.compaq.com.au/pub/ecoinfo/ecoinfo/387.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Bojan</description>
      <pubDate>Wed, 17 Nov 2004 13:16:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-intruder-from-telnet-session/m-p/4871084#M20308</guid>
      <dc:creator>Bojan Nemec</dc:creator>
      <dc:date>2004-11-17T13:16:03Z</dc:date>
    </item>
    <item>
      <title>Re: VMS intruder from telnet session</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-intruder-from-telnet-session/m-p/4871085#M20309</link>
      <description>You may wish to look at setting system parameter LGI_BRK_TERM to 0. From the HELP on VMS V7.1&lt;BR /&gt;Parameters&lt;BR /&gt;&lt;BR /&gt;  LGI_BRK_TERM&lt;BR /&gt;&lt;BR /&gt;       LGI_BRK_TERM causes the terminal name to be part of the&lt;BR /&gt;       association string for the terminal mode of break-in detection.&lt;BR /&gt;       When off (0),  association is done on user name only. LGI_BRK_&lt;BR /&gt;       TERM is set by default (1).  It should be cleared if physical&lt;BR /&gt;       terminal names are created dynamically (that is, if LAT is&lt;BR /&gt;       installed) and effective break-in detection is desired.&lt;BR /&gt;&lt;BR /&gt;       LGI_BRK_TERM is a DYNAMIC parameter.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 17 Nov 2004 13:17:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-intruder-from-telnet-session/m-p/4871085#M20309</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2004-11-17T13:17:48Z</dc:date>
    </item>
    <item>
      <title>Re: VMS intruder from telnet session</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-intruder-from-telnet-session/m-p/4871086#M20310</link>
      <description>You're correct, the changing port number means intrusions from the same real source aren't always recognised as such.&lt;BR /&gt;&lt;BR /&gt;Although you can change the behaviour by clearing LGI_BRK_TERM, the source is then listed as you've shown "Node::TELNET_AC103B05". The hex string is an encoded IP address. Unfortunately TELNET protocol does not include the source username, so the intrusion looks the same for all attempts from the same NODE, regardless of the source user. &lt;BR /&gt;&lt;BR /&gt;This means a single user can drive the node into INTRUDER status, and block connections from ALL users coming from that node. This might not be a problem, for example, if all your incoming telnet sessions are from PCs. But it WILL be a problem in some environments.&lt;BR /&gt;&lt;BR /&gt;If you're going to clear LGI_BRK_TERM, it may be worth thinking about increasing LGI_BRK_LIM (ie: the threshold for a suspect becoming an intruder). Setting it up from the default of 5 to (say) 25, will reduce the chances of a single user with a bad memory blocking access from the whole node (5 retries is "reasonable", but I'd question the sanity of anyone who retries a password 25 times!). Sure this slightly reduces your protection against brute force attacks on your system, but then with half decent password policies, there's not much different between a dictionary attack of 5 and one with 25.</description>
      <pubDate>Wed, 17 Nov 2004 15:50:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-intruder-from-telnet-session/m-p/4871086#M20310</guid>
      <dc:creator>John Gillings</dc:creator>
      <dc:date>2004-11-17T15:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: VMS intruder from telnet session</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-intruder-from-telnet-session/m-p/4871087#M20311</link>
      <description>When the source is composed with the IP address and you use DHCP, there is also one more (small) reduction.&lt;BR /&gt;An intruder can reboot (or simply restart the TCPIP services). So his IP address changes. Doing so he obtain more retries and he can drive many IP addresses into intruder status.&lt;BR /&gt;&lt;BR /&gt;Bojan</description>
      <pubDate>Thu, 18 Nov 2004 05:53:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-intruder-from-telnet-session/m-p/4871087#M20311</guid>
      <dc:creator>Bojan Nemec</dc:creator>
      <dc:date>2004-11-18T05:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: VMS intruder from telnet session</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-intruder-from-telnet-session/m-p/4871088#M20312</link>
      <description>Thanks for help&lt;BR /&gt;&lt;BR /&gt;With LGI_BRK_TERM to 0 we have a response to our need.</description>
      <pubDate>Mon, 22 Nov 2004 10:59:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-intruder-from-telnet-session/m-p/4871088#M20312</guid>
      <dc:creator>dvanwingen</dc:creator>
      <dc:date>2004-11-22T10:59:49Z</dc:date>
    </item>
    <item>
      <title>Re: VMS intruder from telnet session</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-intruder-from-telnet-session/m-p/4871089#M20313</link>
      <description>Thanks for help&lt;BR /&gt;&lt;BR /&gt;With LGI_BRK_TERM to 0 we have a response to our need</description>
      <pubDate>Mon, 22 Nov 2004 11:09:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-intruder-from-telnet-session/m-p/4871089#M20313</guid>
      <dc:creator>dvanwingen</dc:creator>
      <dc:date>2004-11-22T11:09:28Z</dc:date>
    </item>
  </channel>
</rss>

