- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Securing root access from xterm
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-17-2002 12:57 PM
09-17-2002 12:57 PM
tks
ken
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-17-2002 01:02 PM
09-17-2002 01:02 PM
Re: Securing root access from xterm
We block root users by checking it in .profile of root user.
####
if [ ${user} = "root" ]
then
if [ ${TTY} != "console" ]
then
echo "
echo "ERR ${date} - ${TTY} ${user}-root" >> ${sulog}
exit
fi
##
Thanks.
Prashant.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-17-2002 01:06 PM
09-17-2002 01:06 PM
Re: Securing root access from xterm
echo console > /etc/securetty
GL,
C
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-17-2002 01:13 PM
09-17-2002 01:13 PM
Re: Securing root access from xterm
This is what I have on this:
Both dtlogin and vuelogin do not refer to the /etc/securetty file
after checking the login information against the /etc/passwd file.
There are several ways to prevent this:
1) To keep root from using the workstation graphics console or xterminal
when vuelogin or dtlogin are running, add the following lines to the
end of either /usr/vue/config/Xstartup (in HP-UX 10.X this would be
/etc/vue/config/Xstartup) or /etc/dt/config/Xstartup (copy over from
/usr/dt/config if the file does not exist in /etc/dt/config) for CDE:
if [ $USER = root ] ; then
exit 1
fi
This will terminate the login process if the user is logging in as
root.
or for all users :
if [ "$USER" != "root" ]; then
exit 1
fi
OR follow the steps in the HP TKB Doc (KBRC00000074):
http://support1.itrc.hp.com/service/cki/docDisplay.do?docLocale=en_US&admit=-682735245+1028645265478+28353475&docId=200000045437203
HTH,
Jeff
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-17-2002 01:14 PM
09-17-2002 01:14 PM
Re: Securing root access from xterm
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-17-2002 01:14 PM
09-17-2002 01:14 PM
Re: Securing root access from xterm
will only disable telnet sessions. xterm sessions can still get through.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-17-2002 01:17 PM
09-17-2002 01:17 PM
Re: Securing root access from xterm
sh: USER: Parameter not set.
$USER is not being set in my environment.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-17-2002 01:22 PM
09-17-2002 01:22 PM
Re: Securing root access from xterm
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-17-2002 01:23 PM
09-17-2002 01:23 PM
Re: Securing root access from xterm
Ted
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-17-2002 01:27 PM
09-17-2002 01:27 PM
Re: Securing root access from xterm
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-17-2002 01:27 PM
09-17-2002 01:27 PM
Re: Securing root access from xterm
Yes, just change $USER to $LOGNAME & you should be good to go.
Jeff
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-17-2002 01:31 PM
09-17-2002 01:31 PM
Re: Securing root access from xterm
I thought your question was how to prevent direct CDE or X logins by root.
If you want to restrict su to root - then don't give anyone the root PW......
Rgds,
Jeff
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-17-2002 01:34 PM
09-17-2002 01:34 PM
Re: Securing root access from xterm
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-18-2002 04:30 AM
09-18-2002 04:30 AM
Re: Securing root access from xterm
Here is the Command that I use in Xstart to connect to the server.
/usr/bin/X11/xterm -d @D -fn heb8x13 -geometry 100x50-1+1 -fg black -bg lightgray -ls -sb -sl 1000 -title "SERVER NAME"
notice the -ls this tells xterm to execute the "login script" if I leave this option off, or by default, the .profile will not be executed at all and I gain full root access.
Jeff,
On the su issue. The problem was that I did not know weather I could identify where the user is connecting. I can do this with the $TERM and check for the unique term type of my CONSOLE display. So I believe that I can modify .profile to restrict access to the system, but it's really a mute point if the any user has access to the system via xterm. Let me explain further. We have more than one administrator, and I want to force them to connect via the console if connecting as root directly. I guess that it's just not supported. I will probably just setup some type of logging flag in the .profile that will write each root access su or not and it's source Display and terminal type, but of course that can be bypassed by xterm without the -ls.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-18-2002 08:17 AM
09-18-2002 08:17 AM
Re: Securing root access from xterm
In my script above, I used
user=`logname`
Thanks.
Prashant.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-18-2002 09:32 AM
09-18-2002 09:32 AM
Re: Securing root access from xterm
Cool, I needed that command, but it still does not solve the problem of the default operation of xterm being to NOT execute the .profile. Now, xterm is called using rexec, is there something I can do with rexec to make sure it does not allow root access? One thought that I did have was replacing xterm itself with a script that would call a renamed and protected version of the binary, but that seems some how risky to me. :)
tks,
ken
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-18-2002 10:21 AM
09-18-2002 10:21 AM
Solutionif you use X-Windows, then your system is NOT secure at all!
Maybe you can tunnel X-Widnows through OpenSSH (works with Reflection/X, should work with Exceed, too).
"xterm" itself is a security-risk, as it can be remote-controlled and be spied-out! USe "hpterm" or "dtterm" at least, these cannot be remote-controlled that easily...
If you use "ssh" then you can configure that to NOT let "root" log in through it!
You will have to stop "XDMCP" access, too...
And I do recommend installing "IPFilter/9000" and block everything you do not need/want on that system (BOTH directions, in and out).
Just my $0.02,
Wodisch
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-18-2002 10:24 AM
09-18-2002 10:24 AM
Re: Securing root access from xterm
That is the 2 cents that I'm looking for, I suspected as much, xterm itself is a security risk and should not be used, you went beyond that and gave me alternatives. Thanks for you help, I'm still very new at this stuff.
:)
ken.