- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - OpenVMS
- >
- Re: Security check
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-05-2007 06:43 PM
тАО02-05-2007 06:43 PM
Security check
But is there a freeware script available that will report all security holes ? Such as world writeable files & mailboxes, unprotected accounts, unprotected SSH files, etc ?
Wim
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-05-2007 09:12 PM
тАО02-05-2007 09:12 PM
Re: Security check
e.g from
http://www.pointsecure.com/
and from
http://www.ljk.com/ljk/ljk_security.html
Where they report all security holes is a matter of opinion.
I'm not aware of any freeware scripts - fee free to write one and release it :-)
Purely Personal Opinion
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-06-2007 01:46 AM
тАО02-06-2007 01:46 AM
Re: Security check
The DIGITAL-era (commercial) tool to this end (eons ago) was DECinspect.
From long experience with DECinspect, better security is not without cost. DECinspect could render a system unusable, if you blindly invoked the DECinspect-generated lockdown script. If your environment did not meet the DECinspect profile and expectations, you might find yourself running with heavy privileges enabled to get anything done. Hardly the intended result of a lockdown. (And this "fun" was arising from a local implementation and a local profile definition for DECinspect. I'd be very surprised if a generic profile would work acceptably.)
I do have various tools and DCL procedures I use, and various procedures. The process and the techniques I use do not lend themselves to DCL and to generic DCL or application automation -- some of the more obvious parts do automate, but not the key parts of the process. The key pieces of the security review are inherently site-specific.
I've a blog entry or two on this topic queued for the HL whole-site reboot and reload.
Stephen Hoffman
HoffmanLabs
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-06-2007 01:56 AM
тАО02-06-2007 01:56 AM
Re: Security check
Wim
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-06-2007 08:39 AM
тАО02-06-2007 08:39 AM
Re: Security check
Purely Personal Opinion
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-06-2007 10:19 AM
тАО02-06-2007 10:19 AM
Re: Security check
http://www.ttinet.com/products.html
Although this is obviously not freeware.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-11-2007 09:32 AM
тАО12-11-2007 09:32 AM
Re: Security check
I eventually took its ideas and home-grew something to implement the spirit but not the letter of the DISA checks. The problem was that the guy who wrote the SRR program was clearly not a speaker of VMS as a first language. But I got enough ideas that I can say it was a useful exercise.
You might find a "public" copy if you searched the web for "System Readiness Report" (which is what SRR means) to see what crops up. Unfortunately, I am not allowed to post my version because it contains some government-specific tests. No, it doesn't matter to me - but my government point of contact goes into near apoplexy if I mention "posting code" on any forum. (One of these days that SOB will tick me off enough that it will be worth it to watch him choke...)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-11-2007 11:29 AM
тАО12-11-2007 11:29 AM
Re: Security check
Stephen Hoffman
HoffmanLabs LLC
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-11-2007 11:10 PM
тАО12-11-2007 11:10 PM
Re: Security check
I'm currently correcting it and will post it over here, if I'm satisfied with the results.
But most stuff reported is very normal over here. E.g. group users have the same access as the owner of a file (thus rwed) and the script reports this as an error.
And what is the use of reporting all files with acl's ?
Wim
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-12-2007 11:07 PM
тАО12-12-2007 11:07 PM
Re: Security check
E.g. group users have the same access as the owner of a file (thus rwed) and the script reports this as an error.
[/quote]
This might be very valid - it depends on what security base the check-tool is based on. If that disallows G:RWED, it's obvious you get a "Not Ok". Same applies to ACL checking. IMHO, that should be covered as well, but again, if the standard on which the tool is based has no clue about ACL, don't expect it to be checked, or partly, and certainly not what fits your organization.
If you require a security audit, I would first determine what standard is used and what exceptions can be tolerated and why (and in what context), and have that agreed by the auditor. Then run tests with multiple tools that are based on that standard.
OpenVMS Developer & System Manager