- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- security audit found weak passwords for sys, adm, ...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-25-2009 07:31 AM
08-25-2009 07:31 AM
security audit found weak passwords for sys, adm, hpdb, www etc
I am running HPUX 11.11.
A have strong/complex passowrd scheme on the system. I do not want to change passowrd or shell for these accounts because it may affect system or performance.
How do I address the weak password issue?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-25-2009 07:38 AM
08-25-2009 07:38 AM
Re: security audit found weak passwords for sys, adm, hpdb, www etc
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-25-2009 07:59 AM
08-25-2009 07:59 AM
Re: security audit found weak passwords for sys, adm, hpdb, www etc
You don't. Those id's can not log in.
Take a look at the shell entry in /etc/passwd
If it can't log in, its not a security threat.
These results are a typical result of automated scripts to test security and a security auditor should have checked the shell entry and deleted them from this report.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-25-2009 08:12 AM
08-25-2009 08:12 AM
Re: security audit found weak passwords for sys, adm, hpdb, www etc
> I ran a system audit and audit found weak passwords for many generic accounts like daemon, sys, bin. uucp, nuucp,hpdb,www etc.
Got to love those audits (that don't understand UNIX).
By "weak passwords" do you mean an "*" for these accounts? If so, then no one can login anyway! The accounts are there for root to use to run various subsystems.
An "*" in the '/etc/passwd' password field, or an "x" in the password field that points the account to '/etc/shadow' where an "*" exists instead of an encrypted password means that no one can login. There is nothing "weak" about this.
Regards!
...JRF...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-25-2009 08:25 AM
08-25-2009 08:25 AM
Re: security audit found weak passwords for sys, adm, hpdb, www etc
If the user can not log in, its not a threat.
Part of the security audit process is explaining simple Unix to the auditors.
Maybe there is a niche market I should be in.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com