Operating System - HP-UX
1758612 Members
2426 Online
108874 Solutions
New Discussion юеВ

What are AudFilter rules and how can I tell if they are enabled

 
SOLVED
Go to solution
PamelaJThrasher
Regular Advisor

What are AudFilter rules and how can I tell if they are enabled

Hello-
Today I recieved an email about an critical alert impacting HP-UX 11.31 (HPSBUX02514 SSRT100010 rev.1)

It states:
A potential security vulnerability have been identified with HP-UX with AudFilter rules enabled. The vulnerability could be exploited locally to create a Denial of Service (DoS).

What are AudFilter rules and how can I tell if they are enabled?

TIA
Pam
2 REPLIES 2
Ron Freund
Occasional Advisor
Solution

Re: What are AudFilter rules and how can I tell if they are enabled

See http://docs.hp.com/en/5992-3373/ch08s03.html for more info on the Auditing system.

"HP-UX Auditing System Extensions is a _*Software Pack*_ product and is delivered as an optional product on all Operating Environments."

Check in /var/.audit/ if empty you're not using it...

See man 5 audit too.

HTH
Ron
Ron Freund
Occasional Advisor

Re: What are AudFilter rules and how can I tell if they are enabled

From the product Release notes:
# swlist -d @ /tmp/.depot
If the HP-UX Auditing System Extensions depot is on your system, you'll see this:
AuditExt B.11.31.03 HP-UX Auditing System Extensions.

They are here: http://docs.hp.com/en/5900-0338/5900-0338.pdf
R