- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: su set to public executable
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-02-2004 12:37 PM
05-02-2004 12:37 PM
just looking through our audit report and it seems our "su" command is set to public executable, which is a audit breech.
my question is, if the attributes of su are
"-r-sr-xr-x" how can I change this so its no longer public executable.
We are running HP-UX v11.0 ?
Kind Regards,
oz
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-02-2004 01:57 PM
05-02-2004 01:57 PM
Re: su set to public executable
Steven
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-02-2004 02:23 PM
05-02-2004 02:23 PM
Re: su set to public executable
" The su command was set to public executable, with the result that account hacking by any users using this command would not be subject to intruder lockout."
I was thinking chmod 4550 may do the trick ?
Cheers,
oz
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-02-2004 02:39 PM
05-02-2004 02:39 PM
Solution- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-02-2004 02:48 PM
05-02-2004 02:48 PM
Re: su set to public executable
The safeguard in the 'su' program is that any account other than root, requires a password to continue. Changing it can render your system useless. I would rather have the 'su' command open for use with the ability to make sure that a password is entered, rather than be able to log in as root directly. Changing it to 4550 is no good either. Is your system going to get hacked internally in your own company?? If you have the system in a DMZ for example (out in internet land) there are far better ways to secure your system.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-02-2004 02:51 PM
05-02-2004 02:51 PM
Re: su set to public executable
Su command has to be world executable. There is no beating around the bush with that. Do your auditors know what they are auditing and the impact in demanding things like this. Looks like this is their first experience with this kind of auditing.
Hope this helps.
Regds
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-02-2004 02:55 PM
05-02-2004 02:55 PM
Re: su set to public executable
However, the implication that users could launch attacks without a lockout is not correct for patched versions of HP-UX. Repeated su attempts will lockout any target account, just like telnet attacks. su will not provide the attacker with any feedback that the account was disabled. su uses PAM for authentication just like login/passwd.
Bill Hassell, sysadmin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-02-2004 02:57 PM
05-02-2004 02:57 PM
Re: su set to public executable
i have sent an email to our head office admins to ask what they have their su command set at. this will give me an indication on how they have there system setup.
Awaiting reply ....