- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- security issues
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-05-2004 10:53 PM
03-05-2004 10:53 PM
Is there a security patch bundle released by HP? I actually wanted to address the following issues raised by a customer.
-NFS Exported Directories Mountable by unathorized users .
-statd service may be vulnerable to a format string attack .
-rpc. mountd daemon might be vulnerable to an off-by one overflow .
-Sendmail Header Processing Buffer Overflow Vulnerability .
-Sendmail Addredd Prescan Possible Memory Corruption Vulnerability .
-Sendmail Prescan() Remote Buffer Overrun Vulnerability .
-Multiple Vendor SNMP Request And Trap Handling Vulnerabilities.
Thanks and Regards,
Omar Alvi
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-06-2004 04:03 AM
03-06-2004 04:03 AM
SolutionThe easiest way to address security patches is with the security_patch_check tool. Download and install this tool.
http://software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=B6834AA
(Note that this requires Perl which can be obtained here: )
http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=PERL
Then run it:
# /opt/sec_mgmt/spc/bin/security_patch_check -r
It will give you a list of security patches required to get your system up to date.
With that list you can then go to the ITRC Patch database
http://www1.itrc.hp.com/service/patch/mainPage.do
Search for each patch, add it to your list and then download the whole bundle. This will also resolve any patch dependencies as well.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-06-2004 12:00 PM
03-06-2004 12:00 PM
Re: security issues
Stop looking.
Security is based on the dilligence and time of the systems administrator. You have to stay on top of patches, keep your eyes on the net for new threats.
There are other tools that help though.
Security Patch Check
http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=B6834AA
TCP Wrappers
http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=TCPWRAP
IDS/9000 (Intrusion Detection Sytstem)
http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=J5083AA
Get all these products working you'll be quite secure.
Secure shell
http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=T1471AA
ipfilter
http://software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=B9901AA
Also, dump any logins or transfers based on the insecure Berkley protocols. rsh.remesh.rcp.
Permissions are key. Especially when exposed to the public Internet.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-06-2004 11:13 PM
03-06-2004 11:13 PM
Re: security issues
berlene.herren@hp.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-07-2004 10:06 AM
03-07-2004 10:06 AM
Re: security issues
http://www.software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=B6849AA