<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Review Script in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/security-review-script/m-p/4065792#M86236</link>
    <description>There are any number of these DCL procedures around, and there are (were) tools that specifically sought various insecurities, attacks or known issues.  Here's one starting point, with info on the VMS SRR mentioned earlier:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://64.223.189.234/node/43" target="_blank"&gt;http://64.223.189.234/node/43&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;And it's perfectly fine to have an entry without an identifier.&lt;BR /&gt;&lt;BR /&gt;If you want to work on your password security, start here:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://64.223.189.234/node/229" target="_blank"&gt;http://64.223.189.234/node/229&lt;/A&gt;&lt;BR /&gt;</description>
    <pubDate>Fri, 07 Sep 2007 16:48:55 GMT</pubDate>
    <dc:creator>Hoff</dc:creator>
    <dc:date>2007-09-07T16:48:55Z</dc:date>
    <item>
      <title>Security Review Script</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/security-review-script/m-p/4065789#M86233</link>
      <description>Years ago I had seen a DCL script which would review a VMS config for some obvious security issues (eg AUTHORIZE entries w/o Identifiers, DECnet accounts with default pwds, etc).&lt;BR /&gt;&lt;BR /&gt;I don't recall if this was an HP script or a third party script.  I've scoured the web without success.&lt;BR /&gt;&lt;BR /&gt;If anyone remembers this, can they point me to a copy?  TIA</description>
      <pubDate>Wed, 05 Sep 2007 14:58:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/security-review-script/m-p/4065789#M86233</guid>
      <dc:creator>Jack Trachtman</dc:creator>
      <dc:date>2007-09-05T14:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: Security Review Script</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/security-review-script/m-p/4065790#M86234</link>
      <description>Can't post it, darn thing is too big.&lt;BR /&gt;&lt;BR /&gt;If you have access to a DISA site, or friends in the U.S. Government who have such access, you could look for OPENVMS-SRR-V2R2.COM - but beware that it is terribly buggy.  Not to mention that it is a resource hog and takes literally hours to run on a big system.&lt;BR /&gt;&lt;BR /&gt;I had a copy, ran it, barfed (I barfed just after it did...), and rewrote the bugger to fit our site's configuration a little better.&lt;BR /&gt;&lt;BR /&gt;There are at LEAST 6 faulty loops and more than a couple of bad variable references, but it IS a starting point.&lt;BR /&gt;&lt;BR /&gt;Larry Kilgallen might have something more directed, updated, and immediately useful - for a price.&lt;BR /&gt;</description>
      <pubDate>Thu, 06 Sep 2007 11:42:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/security-review-script/m-p/4065790#M86234</guid>
      <dc:creator>Richard W Hunt</dc:creator>
      <dc:date>2007-09-06T11:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: Security Review Script</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/security-review-script/m-p/4065791#M86235</link>
      <description>Back in the good old days  ( |d|i|g|i|t|a|l|, Easynet, Valbonne ) we used, or were told to use 'inspect'.&lt;BR /&gt;I believe my dear, late, friend Dave Monahan worked on that for a while.&lt;BR /&gt;&lt;BR /&gt;Did that become the "Polycenter Security Compliance Manager (PSCM)"&lt;BR /&gt;Avaiable through Touch Technologies, Inc?&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.ttinet.com/products.html" target="_blank"&gt;http://www.ttinet.com/products.html&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://www.ttinet.com/doc/pscm/user_guide_003.html" target="_blank"&gt;http://www.ttinet.com/doc/pscm/user_guide_003.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Hope this helps some,&lt;BR /&gt;Hein van den Heuvel (at gmail dot com)&lt;BR /&gt;HvdH Performance Consulting&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 06 Sep 2007 17:38:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/security-review-script/m-p/4065791#M86235</guid>
      <dc:creator>Hein van den Heuvel</dc:creator>
      <dc:date>2007-09-06T17:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: Security Review Script</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/security-review-script/m-p/4065792#M86236</link>
      <description>There are any number of these DCL procedures around, and there are (were) tools that specifically sought various insecurities, attacks or known issues.  Here's one starting point, with info on the VMS SRR mentioned earlier:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://64.223.189.234/node/43" target="_blank"&gt;http://64.223.189.234/node/43&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;And it's perfectly fine to have an entry without an identifier.&lt;BR /&gt;&lt;BR /&gt;If you want to work on your password security, start here:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://64.223.189.234/node/229" target="_blank"&gt;http://64.223.189.234/node/229&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 07 Sep 2007 16:48:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/security-review-script/m-p/4065792#M86236</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2007-09-07T16:48:55Z</dc:date>
    </item>
  </channel>
</rss>

