- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Security...Senior admin quit.
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-10-2000 12:43 PM
11-10-2000 12:43 PM
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-10-2000 12:46 PM
11-10-2000 12:46 PM
Re: Security...Senior admin quit.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-10-2000 12:49 PM
11-10-2000 12:49 PM
Re: Security...Senior admin quit.
With the acct disabled, there is no access. Without the root passwd, can't really go that route either. You mentioned that outside access has been closed.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-10-2000 12:57 PM
11-10-2000 12:57 PM
Re: Security...Senior admin quit.
Good Luck!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-10-2000 01:00 PM
11-10-2000 01:00 PM
Re: Security...Senior admin quit.
...but you STILL might want to keep HIS or HER phone number handy... :-))
...JRF...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-10-2000 01:03 PM
11-10-2000 01:03 PM
Solution1. backup all your data; make sure that you have older backups available
2. perform a checksum of all executables and compare with a freshly installed machine. (in case a common commands such as su, netstat, ps etc. have been modified)
# sum /sbin/* /usr/sbin/* /bin/*
2b. do a full search of the servers for any scripts that may be lurking... you should know what each does.
3. obtain a copy of lsof (from the archive centre) and run it to ensure that no ports are stealthly open.
4. Check all cron jobs, at jobs to confirm that you know what they do.
5. check that you do not have strange entries in your $HOME/.rhosts and hosts.equiv
6. Keep an eye on traffic going into and out of your servers; verify that there are no MODEMs connected to any workstations/servers.
6. Worst-case scenario, do a clean install and restore your data (after validation) although I must say that most SAs I know are ethically minded and would not (no matter hoe unpleasant the circumstances are) subvert their former employers.
7. Now might be a good time to install tripwire http://www.tripwire.com/ to keep a track of what has changed on your systems.
Good luck.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-10-2000 01:08 PM
11-10-2000 01:08 PM
Re: Security...Senior admin quit.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-10-2000 01:13 PM
11-10-2000 01:13 PM
Re: Security...Senior admin quit.
Examine /etc/passwd and /etc/sudoers (if you use sudo) very carefully. Make sure not only the system passwd, but any other passwords/accounts he had access to have been changed.
Keep an eye on open network ports, make sure nothing mysterious is listening on your servers.
If you allow anonymous ftp, make sure the security around the ftp filesystem is still in place.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-10-2000 01:14 PM
11-10-2000 01:14 PM
Re: Security...Senior admin quit.
Is a good security app to help you ensure that certain critical files have not been changed. Can get a copy from the COAST security site.
As mentioned, most SAs will not mess around with previous employers. I believe this amounts to a Federal Offense.
And yes, always have good backups handy.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-10-2000 02:04 PM
11-10-2000 02:04 PM
Re: Security...Senior admin quit.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-10-2000 02:31 PM
11-10-2000 02:31 PM
Re: Security...Senior admin quit.
Have a known good copy of your operating system with all patches, etc. ready to install if necessary. Also, show your night operator where the wires connecting this machine to the LAN are and how to pull them out if given the word. (paranoid yes, but I once had a colleague fired and my boss gave him 20 seconds at the keyboard, need I detail the damage he caused?)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-10-2000 05:16 PM
11-10-2000 05:16 PM
Re: Security...Senior admin quit.
One important thing is check your cron jobs immediately for any unncessary jobs that are scheduled which can cause disaster.
...Madhu
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-10-2000 05:21 PM
11-10-2000 05:21 PM
Re: Security...Senior admin quit.
Did you guys sent him out properly with a farewell party ? :)
...Madhu
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-13-2000 07:00 AM
11-13-2000 07:00 AM
Re: Security...Senior admin quit.
As it is, I have several passwords in my head for people in our company, which I can't forget even if I wanted to.
Knowing what I know about the company's modems, firewall, unix, and software with security leaks, it would be very difficult for them to stop me if I wanted to get in.
If you fear this admin, I'd change every password in the place.