- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- nddconf ownership question
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-06-2007 04:44 AM
06-06-2007 04:44 AM
nddconf ownership question
We recently had a PCI Audit and the auditors gave us this document from the Center for Internet Security HP-UX Benchmark document and wanted us to implement them as much as we could.
I've question on the nddconf ownership, all the files under /etc/rc.config.d/* are owned by bin:bin, but this document says that the ownership should be root:sys and permissions read for everybody, I don't really see a difference, but would like to know why it should be root:sys?
Any thoughts?
Thanks,
Shabu
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-06-2007 04:50 AM
06-06-2007 04:50 AM
Re: nddconf ownership question
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-06-2007 05:37 AM
06-06-2007 05:37 AM
Re: nddconf ownership question
I'm surprised at this document.
bin and root are essentially synonymous.
It makes no difference to security unless an unprivileged user gains write access to a file.
sEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-06-2007 05:50 AM
06-06-2007 05:50 AM
Re: nddconf ownership question
bin:bin <-> root:sys; 6 of one. They're protected system accounts which is all that's important.
I am actually a little surprised to a security audit suggest world read capability. That's one area a black hat could research to find out what's configured to run by default and if there are any unprotected scripts that could be hacked.
Remember, everything in /etc/rc.config.d is sourced several times in a boot sequence; if someone could either edit those files or any files they call, they could very easily crack root.
Doug
------
Senior UNIX Admin
O'Leary Computers Inc
linkedin: http://www.linkedin.com/dkoleary
Resume: http://www.olearycomputers.com/resume.html
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-06-2007 06:13 AM
06-06-2007 06:13 AM
Re: nddconf ownership question
Thanks Folks.
I am surprised at some of the things that are in the document as well.
Anyways, so basically there is no difference since both are protected but for consistency sake just go with bin:bin?
Thanks,
Shabu
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-06-2007 06:25 AM
06-06-2007 06:25 AM
Re: nddconf ownership question
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-06-2007 07:03 AM
06-06-2007 07:03 AM
Re: nddconf ownership question
Thanks folks, I appreciate your inputs.
Closing this thread out ...
Thanks,
Shabu
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-06-2007 07:04 AM
06-06-2007 07:04 AM