<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MUP VMS831H1I_SYS_MUP-V1100 - how critical is this? in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246640#M99556</link>
    <description>My understanding is that this is a deliberate change in policy.</description>
    <pubDate>Mon, 12 Jul 2010 12:35:07 GMT</pubDate>
    <dc:creator>Ian Miller.</dc:creator>
    <dc:date>2010-07-12T12:35:07Z</dc:date>
    <item>
      <title>MUP VMS831H1I_SYS_MUP-V1100 - how critical is this?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246632#M99548</link>
      <description>Our customers generally run in a very closed environment, and the limited users generally have accounts with most privileges enabled.&lt;BR /&gt;&lt;BR /&gt;The brief description of this OpenVMS MUP states that when using the &lt;BR /&gt;SHOW PROCESS/CONTINUOUS command, there can be "local disclosure of information". &lt;BR /&gt;&lt;BR /&gt;Does this MUP correct unintended display of system information only? Is there a nastier reason that would warrant installing this MUP?&lt;BR /&gt;Thanks!</description>
      <pubDate>Tue, 06 Jul 2010 22:30:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246632#M99548</guid>
      <dc:creator>Scot Newton</dc:creator>
      <dc:date>2010-07-06T22:30:25Z</dc:date>
    </item>
    <item>
      <title>Re: MUP VMS831H1I_SYS_MUP-V1100 - how critical is this?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246633#M99549</link>
      <description>Hi Scot,&lt;BR /&gt;&lt;BR /&gt;You can find the details of the patch at the following location -&lt;BR /&gt;* patch details: VMS831H1I_SYS_MUP-V1100&lt;BR /&gt;&lt;A href="http://www11.itrc.hp.com/service/patch/patchDetail.do?patchid=VMS831H1I_SYS_MUP-V1100&amp;amp;sel={openvms:i64:8.3-1h1,}&amp;amp;BC=main" target="_blank"&gt;http://www11.itrc.hp.com/service/patch/patchDetail.do?patchid=VMS831H1I_SYS_MUP-V1100&amp;amp;sel={openvms:i64:8.3-1h1,}&amp;amp;BC=main&lt;/A&gt;|search|&lt;BR /&gt;&lt;BR /&gt;As per the patch details -&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt;5.2.1  A potential security vulnerability has been fixed with HP OpenVMS&lt;BR /&gt;&amp;gt;&amp;gt; Auditing&lt;BR /&gt;&amp;gt;&amp;gt; The vulnerability could result in a local disclosure of information.&lt;BR /&gt;This is related to OpenVMS Audit logfile information disclosure.&lt;BR /&gt;If a user logs in with a invalid password for a number of times, then he would&lt;BR /&gt;be marked as a intruder. However the break-in logs would contain invalid&lt;BR /&gt;password in the password field.&lt;BR /&gt;The fix was to replace the invalid password with the text "&lt;INVALID&gt;".&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; 5.2.3  SHOW PROCESS/CONTINUOUS Command can cause undesired&lt;BR /&gt;&amp;gt;&amp;gt; behavior on OpenVMS I64 System&lt;BR /&gt;This was related to a problem where the system would crash when the&lt;BR /&gt;DCL "$SHOW PROCESS/CONTINUOUS" command was being executed.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; Is there a nastier reason that would warrant installing this MUP?&lt;BR /&gt;Does not look like.&lt;BR /&gt;&lt;BR /&gt;Based on the above information, you need to decide whether its important for&lt;BR /&gt;this patch to be installed in your environment.&lt;BR /&gt;&lt;BR /&gt;Hope this helps.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Murali&lt;/INVALID&gt;</description>
      <pubDate>Wed, 07 Jul 2010 02:17:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246633#M99549</guid>
      <dc:creator>P Muralidhar Kini</dc:creator>
      <dc:date>2010-07-07T02:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: MUP VMS831H1I_SYS_MUP-V1100 - how critical is this?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246634#M99550</link>
      <description>Murali,&lt;BR /&gt;&lt;BR /&gt;thank you very much for the additional details of the 'local disclosure of information'. Note that this 'disclosure' most likely does exist since OpenVMS V1.0, so it was a design decision to display the passwords under these circumstances. You need privileges or access to a privileged terminal to view this data.&lt;BR /&gt;&lt;BR /&gt;This information should help the system managers to decide, whether to install this MUP patch.&lt;BR /&gt;&lt;BR /&gt;Volker.&lt;BR /&gt;</description>
      <pubDate>Wed, 07 Jul 2010 04:25:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246634#M99550</guid>
      <dc:creator>Volker Halle</dc:creator>
      <dc:date>2010-07-07T04:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: MUP VMS831H1I_SYS_MUP-V1100 - how critical is this?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246635#M99551</link>
      <description>Scot,&lt;BR /&gt;&lt;BR /&gt;Please take particular note of 5.2.3 in Murali's post.&lt;BR /&gt;&lt;BR /&gt;Potential crashes that have not yet been experienced tend to be discounted. Unfortunately, Murphy's Law applies. Additionally, there are frequently other ways of encountering the problem.&lt;BR /&gt;&lt;BR /&gt;Scheduled updates are generally easier to deal with than an unexpected encounter with the problem.&lt;BR /&gt;&lt;BR /&gt;- Bob Gezelter, &lt;A href="http://www.rlgsc.com" target="_blank"&gt;http://www.rlgsc.com&lt;/A&gt;</description>
      <pubDate>Wed, 07 Jul 2010 12:59:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246635#M99551</guid>
      <dc:creator>Robert Gezelter</dc:creator>
      <dc:date>2010-07-07T12:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: MUP VMS831H1I_SYS_MUP-V1100 - how critical is this?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246636#M99552</link>
      <description>Thanks for the information everyone. Will instruct our customers to install this MUP at next scheduled PM.</description>
      <pubDate>Wed, 07 Jul 2010 14:32:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246636#M99552</guid>
      <dc:creator>Scot Newton</dc:creator>
      <dc:date>2010-07-07T14:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: MUP VMS831H1I_SYS_MUP-V1100 - how critical is this?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246637#M99553</link>
      <description>Hi Scot,&lt;BR /&gt;&lt;BR /&gt;Please refer the following link which says how you can thank the forum -&lt;BR /&gt;&lt;A href="http://forums11.itrc.hp.com/service/forums/helptips.do?#28" target="_blank"&gt;http://forums11.itrc.hp.com/service/forums/helptips.do?#28&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Murali</description>
      <pubDate>Wed, 07 Jul 2010 14:37:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246637#M99553</guid>
      <dc:creator>P Muralidhar Kini</dc:creator>
      <dc:date>2010-07-07T14:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: MUP VMS831H1I_SYS_MUP-V1100 - how critical is this?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246638#M99554</link>
      <description>re: Murali &lt;BR /&gt;&lt;BR /&gt;  So here's what you get when you eliminate much of the history/memory of your engineering team! &lt;BR /&gt;&lt;BR /&gt;  My recollection is that what appears to have been changed was a deliberate feature of intrusion detection and evasion. &lt;BR /&gt;&lt;BR /&gt;*Suspect* usernames and passwords were obscured in audit alarms and journal, on the assumption that a common error for a geniune login error for an authorized user would be for the username and/or password to contain sufficient information to guess the real password.&lt;BR /&gt;&lt;BR /&gt; However, once there were sufficient attempts to become an intruder, it's unlikely to be a real error, so both usernames and passwords were logged in clear text. Since the audit journal requires privileged access, it's not such a big deal that a password might be revealed, as anyone who can read it can reset passwords anyway. Second, it allows the system manager to analyze intrusion attempts to determine the nature of the attack (which I've used a few times). &lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sun, 11 Jul 2010 22:00:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246638#M99554</guid>
      <dc:creator>John Gillings</dc:creator>
      <dc:date>2010-07-11T22:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: MUP VMS831H1I_SYS_MUP-V1100 - how critical is this?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246639#M99555</link>
      <description>John's recollection is correct.  &lt;BR /&gt;&lt;BR /&gt;This is (was) documented and intentional behavior within OpenVMS security mechanisms, and was designed to allow any particular password selections or break-in techniques being utilized by the intruder to be identified.   Specifically, if this was a dictionary attack or something targeted to the user or the group or the server or the organization.&lt;BR /&gt;&lt;BR /&gt;Here's a quick reference:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://h71000.www7.hp.com/doc/84final/6048/6048pro_008.html" target="_blank"&gt;http://h71000.www7.hp.com/doc/84final/6048/6048pro_008.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Additionally (and with rather more clarity) "Passwords used in break-in attempts are not displayed on security operator terminals, but they are logged to the security audit log file and can be displayed with the Audit Analysis utility." from page 325 here:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://h71000.www7.hp.com/doc/732final/aa-q2hlg-te/aa-q2hlg-te.pdf" target="_blank"&gt;http://h71000.www7.hp.com/doc/732final/aa-q2hlg-te/aa-q2hlg-te.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;The decision to send these break-in passwords (just) to the auditing database and not to alarms (where viewing was not controlled) was also deliberate, as was the decision to send along cleartext passwords for an intruder and not for suspects.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sun, 11 Jul 2010 22:48:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246639#M99555</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2010-07-11T22:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: MUP VMS831H1I_SYS_MUP-V1100 - how critical is this?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246640#M99556</link>
      <description>My understanding is that this is a deliberate change in policy.</description>
      <pubDate>Mon, 12 Jul 2010 12:35:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246640#M99556</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2010-07-12T12:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: MUP VMS831H1I_SYS_MUP-V1100 - how critical is this?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246641#M99557</link>
      <description>&amp;gt;My understanding is that this &lt;BR /&gt;&amp;gt;is a deliberate change in policy.&lt;BR /&gt;&lt;BR /&gt;Ian - Really?  Was the change in policy before or after the code change?&lt;BR /&gt;&lt;BR /&gt;If this really was a change in policy, why was the change in policy not documented as such?  Why was this presented as a "Problem corrected" and then a MUP issued?&lt;BR /&gt;&lt;BR /&gt;If the intent was to change a well known behavior it should have been clearly documented as a change in behavior. &lt;BR /&gt;&lt;BR /&gt;Brad McCusker&lt;BR /&gt;&lt;BR /&gt;Software Concepts International&lt;BR /&gt;&lt;A href="http://www.sciinc.com" target="_blank"&gt;www.sciinc.com&lt;/A&gt;&lt;BR /&gt;  &lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 12 Jul 2010 15:19:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246641#M99557</guid>
      <dc:creator>Brad McCusker</dc:creator>
      <dc:date>2010-07-12T15:19:27Z</dc:date>
    </item>
    <item>
      <title>Re: MUP VMS831H1I_SYS_MUP-V1100 - how critical is this?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246642#M99558</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;The text the "OpenVMS Guide to System Security" is changed in the "HP OpenVMS Guide to System Security OpenVMS Version 8.4"&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://h71000.www7.hp.com/doc/84final/ba554_90015/ba554_90015.pdf" target="_blank"&gt;http://h71000.www7.hp.com/doc/84final/ba554_90015/ba554_90015.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;"Passwords used in break-in attempts are not displayed on security operator terminals and also not logged to the security audit log file."&lt;BR /&gt;&lt;BR /&gt;Thanks and warm regards,&lt;BR /&gt;Prasad&lt;BR /&gt;</description>
      <pubDate>Tue, 13 Jul 2010 02:44:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246642#M99558</guid>
      <dc:creator>sgprasad</dc:creator>
      <dc:date>2010-07-13T02:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: MUP VMS831H1I_SYS_MUP-V1100 - how critical is this?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246643#M99559</link>
      <description>I was concerned by this too, and logged case 4616845931 on July 8 ...  (I figure we have had a support contract for 25+ years, might as well ask a question or two):&lt;BR /&gt;&lt;BR /&gt;and was given this response and the case was closed (no one told me it was secret)  (may wrap poorly):&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;We understand that customer is asking for an option to display the wrong password from the break in&lt;BR /&gt;records, which were disabled in the recent recent vms*_sys_mup-v* patches.&lt;BR /&gt;As already highlighted in the problem description, this change was done due to a security alert.&lt;BR /&gt;Leaving an option to display the wrong password in the operating system can be abused in general.&lt;BR /&gt;It is also an industry standard to not display any information related to passwords in the logs.&lt;BR /&gt;While the wrong password display might be useful for the current customer in some cases, going&lt;BR /&gt;without this display will be a safe and recommended approach.&lt;BR /&gt;Thanks and warm regards,&lt;BR /&gt; (OpenVMS Security Engineering)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;============================================&lt;BR /&gt;=========&lt;BR /&gt;&lt;BR /&gt;I mentioned to them I have made use of (as others have said) the literal password data in the audit logs in the past ...&lt;BR /&gt;&lt;BR /&gt;I also suggested having a switchable setting ... with the default being to hide the password but allow the system manager to return to the old behavior if desired.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Verne&lt;BR /&gt;</description>
      <pubDate>Tue, 13 Jul 2010 17:30:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246643#M99559</guid>
      <dc:creator>Verne Britton</dc:creator>
      <dc:date>2010-07-13T17:30:50Z</dc:date>
    </item>
    <item>
      <title>Re: MUP VMS831H1I_SYS_MUP-V1100 - how critical is this?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246644#M99560</link>
      <description>References&lt;BR /&gt;&lt;BR /&gt;SSRT100144&lt;BR /&gt;SSRT090267&lt;BR /&gt;CVE-2010-1973 &lt;BR /&gt;</description>
      <pubDate>Wed, 14 Jul 2010 07:15:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/mup-vms831h1i-sys-mup-v1100-how-critical-is-this/m-p/5246644#M99560</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2010-07-14T07:15:24Z</dc:date>
    </item>
  </channel>
</rss>

