- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: Nessus Security Scan disabling root on trusted...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-12-2005 09:55 AM
тАО01-12-2005 09:55 AM
We have just recently converted to trusted systems on 11.0 and 11i HPUX servers. We have included root to be disabled after 3 failed log in attempts. My problem is our Security Team uses Nessus, and during the scans it attempts to access root(ssh/rexec etc)at least 3 times, and the account is disabled.
Our Security Staff believes this leaves us vulnerable... I do not have access to Nessus as it is run and supported by their group. Clearly there must be a way to modify Nessus so that it can still scan but not disable root, How do you keep the systems trusted and still utilize Nessus? Thank you for your time.
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-12-2005 10:06 AM
тАО01-12-2005 10:06 AM
Re: Nessus Security Scan disabling root on trusted system
Even if the root accounts get disabled, you can still login using the root account on the console.
Hope this helps.
Regds
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-12-2005 10:11 AM
тАО01-12-2005 10:11 AM
Re: Nessus Security Scan disabling root on trusted system
If you choose to directly edit the tcb files make sure that you are logged in as root in at least two session so that you can get yourself out of trouble as fast as you got yourself in.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-12-2005 10:12 AM
тАО01-12-2005 10:12 AM
Re: Nessus Security Scan disabling root on trusted system
Once you are logged into the console user "modprpw -k root" to reactivate the root account.
Hope this helps.
regds
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-12-2005 10:30 AM
тАО01-12-2005 10:30 AM
Re: Nessus Security Scan disabling root on trusted system
Janet
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-12-2005 02:01 PM
тАО01-12-2005 02:01 PM
SolutionWhether you change nessus or change the number of failed attemps that HP-UX allows root, you're vulnerable to a denial-of-service attack.
One question, I don't know the answer off the top of my head and don't have a test environment -- if you set sshd to disallow root logins, does the daemon head off the attempt without the operating system flagging it as a failed attempt?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-12-2005 11:27 PM
тАО01-12-2005 11:27 PM
Re: Nessus Security Scan disabling root on trusted system
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-13-2005 12:36 AM
тАО01-13-2005 12:36 AM
Re: Nessus Security Scan disabling root on trusted system
Janet
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-13-2005 07:09 AM
тАО01-13-2005 07:09 AM
Re: Nessus Security Scan disabling root on trusted system
but in any way the ssh check could be taken out of the test run, OTOH raising the bad login limit a bit should be ok.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-13-2005 07:44 AM
тАО01-13-2005 07:44 AM
Re: Nessus Security Scan disabling root on trusted system
Did you use the gui or a script to do the nessus scan? If scripted, please share.
You made sure with testing that your root login will lock after three invalid attempts. Knowing this vastly limits the number of possibilities any hacker, internal or external has to make trouble.
A console login automatically re-enables the root login.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com