<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question on intrusions in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/question-on-intrusions/m-p/5013012#M29772</link>
    <description>Hi Kalle,&lt;BR /&gt;&lt;BR /&gt;Here's the output earlier when I was doing my daily checks. I already have removed the intrusion as it was affecting some of our production users.&lt;BR /&gt;&lt;BR /&gt;Thanks, Roose.</description>
    <pubDate>Thu, 09 Nov 2006 04:20:46 GMT</pubDate>
    <dc:creator>roose</dc:creator>
    <dc:date>2006-11-09T04:20:46Z</dc:date>
    <item>
      <title>Question on intrusions</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/question-on-intrusions/m-p/5013008#M29768</link>
      <description>Hi folks, just wanted to verify: when can a source be designated as suspect or as an intruder? I have just seen on our system 21 counts for a specific IP address but flagged as suspect and 6 counts for another IP address but already flagged as intruder.&lt;BR /&gt;&lt;BR /&gt;We are running OpenVMS 7.3-1 and TCP/IP v5.3 ECO4.</description>
      <pubDate>Wed, 08 Nov 2006 21:12:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/question-on-intrusions/m-p/5013008#M29768</guid>
      <dc:creator>roose</dc:creator>
      <dc:date>2006-11-08T21:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: Question on intrusions</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/question-on-intrusions/m-p/5013009#M29769</link>
      <description>Bruce Claremont did a nice writeup, of the LGI parameter which control this behaviour.&lt;BR /&gt;See here:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.migrationspecialties.com/pdf/SYSGEN%20Login%20Parameters.pdf" target="_blank"&gt;http://www.migrationspecialties.com/pdf/SYSGEN%20Login%20Parameters.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;regards Kalle</description>
      <pubDate>Thu, 09 Nov 2006 00:42:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/question-on-intrusions/m-p/5013009#M29769</guid>
      <dc:creator>Karl Rohwedder</dc:creator>
      <dc:date>2006-11-09T00:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: Question on intrusions</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/question-on-intrusions/m-p/5013010#M29770</link>
      <description>Hi Kalle,&lt;BR /&gt;&lt;BR /&gt;Thanks for the link.&lt;BR /&gt;&lt;BR /&gt;The information from Bruce's write-up does provide the explanation for the LGI parameters, but I still don't see how a source is flagged as suspect or intruder? I can see that it must have to do with the LGI_BRK_LIM and LGI_HID_TIM parameters, but the description on these parameters only says about "evasive action". Again, I'm hoping to look for an explanation why a count of 21 can only be flagged as suspect, but a 6 is already an intruder.&lt;BR /&gt;&lt;BR /&gt;I'm attaching our system's LGI parameters for reference.</description>
      <pubDate>Thu, 09 Nov 2006 01:49:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/question-on-intrusions/m-p/5013010#M29770</guid>
      <dc:creator>roose</dc:creator>
      <dc:date>2006-11-09T01:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: Question on intrusions</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/question-on-intrusions/m-p/5013011#M29771</link>
      <description>I noticed you set LGI_BTK_TERM to 1 (default), so that the terminal port is used to check for intrusions. I prefer to set it to 0.&lt;BR /&gt;Can you post a SHOW INTRUSION ?&lt;BR /&gt;&lt;BR /&gt;regard Kalle</description>
      <pubDate>Thu, 09 Nov 2006 04:17:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/question-on-intrusions/m-p/5013011#M29771</guid>
      <dc:creator>Karl Rohwedder</dc:creator>
      <dc:date>2006-11-09T04:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: Question on intrusions</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/question-on-intrusions/m-p/5013012#M29772</link>
      <description>Hi Kalle,&lt;BR /&gt;&lt;BR /&gt;Here's the output earlier when I was doing my daily checks. I already have removed the intrusion as it was affecting some of our production users.&lt;BR /&gt;&lt;BR /&gt;Thanks, Roose.</description>
      <pubDate>Thu, 09 Nov 2006 04:20:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/question-on-intrusions/m-p/5013012#M29772</guid>
      <dc:creator>roose</dc:creator>
      <dc:date>2006-11-09T04:20:46Z</dc:date>
    </item>
    <item>
      <title>Re: Question on intrusions</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/question-on-intrusions/m-p/5013013#M29773</link>
      <description>&lt;BR /&gt;The relevant parameters for your question are LGI_BRK_TMO (set at 300 secs.), LGI_BRK_LIM (set at 5 tries), and LGI_HID_TIM (set at 600 secs.)&lt;BR /&gt;&lt;BR /&gt;Every time a user has a login failure, his (or her) expiration time is incremented by LGI_BRK_TMO. If he exceeds LGI_BRK_LIM attempts within the expiration period he is declared an intruder and evasion is in effect.  Evasion means he won't be able to successfully login even if he provides the correct username and password.  In your case this does not apply because you DISUSER the account anyway (LGI_NRK_DISUSER).&lt;BR /&gt;&lt;BR /&gt;So the reason why you see an INTRUDER after 6 counts is because he exceeded the limit of 5 within his expiration period.  The most likely reason you see a "suspect" with 21 counts is because he was declared an intruder previously and your hide time is low (10 minutes) and after 10 minutes he drops down from intruder to suspect and the count is not reset.  I would say he's been rising to intruder and dropping to suspect a number of times for some period of time.&lt;BR /&gt;&lt;BR /&gt;Hope that helps.&lt;BR /&gt;</description>
      <pubDate>Thu, 09 Nov 2006 09:04:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/question-on-intrusions/m-p/5013013#M29773</guid>
      <dc:creator>EdgarZamora</dc:creator>
      <dc:date>2006-11-09T09:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: Question on intrusions</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/question-on-intrusions/m-p/5013014#M29774</link>
      <description>&lt;BR /&gt;Oops just noticed a typo, LGI_NRK_DISUSER should be LGI_BRK_DISUSER.&lt;BR /&gt;&lt;BR /&gt;Also forgot to mention the more likely possibility that the user was very tenacious in trying to login, after he was declared an intruder he kept trying to login thereby inflating his count to 21.  After he stopped trying and time elapsed he dropped down to suspect and that's probably around the time you did a SHOW INTRUSION.&lt;BR /&gt;&lt;BR /&gt;You should reconsider your use of DISUSER and/or your low HIDE time depending on your security requirements.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 09 Nov 2006 09:14:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/question-on-intrusions/m-p/5013014#M29774</guid>
      <dc:creator>EdgarZamora</dc:creator>
      <dc:date>2006-11-09T09:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: Question on intrusions</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/question-on-intrusions/m-p/5013015#M29775</link>
      <description>Hi Edgar,&lt;BR /&gt;&lt;BR /&gt;I believe the information you gave me is the one I am looking for. &lt;BR /&gt;&lt;BR /&gt;Thanks as well to Kalle for his information.&lt;BR /&gt;&lt;BR /&gt;I am closing this case now.</description>
      <pubDate>Thu, 09 Nov 2006 20:20:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/question-on-intrusions/m-p/5013015#M29775</guid>
      <dc:creator>roose</dc:creator>
      <dc:date>2006-11-09T20:20:35Z</dc:date>
    </item>
  </channel>
</rss>

