- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - OpenVMS
- >
- What's this mean with "<login>" a/c in break-in re...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-27-2005 08:41 PM
10-27-2005 08:41 PM
i analyze the breakin record and find that many records' username are marked as "
i have no idea about this information, who knows it?
thanks
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-27-2005 08:58 PM
10-27-2005 08:58 PM
Re: What's this mean with "<login>" a/c in break-in record?
You establish a connection and get "Username". You do not enter username, timeout period expires and connection is disconnected.
Usually this means that no username was entered when connection was estableshed.
You can also have this kind of record when someone scan your VMS system with some kind of port scaner.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-27-2005 10:28 PM
10-27-2005 10:28 PM
Re: What's this mean with "<login>" a/c in break-in record?
Some years ago, I had a similar problem, a lot of breaking marked as login. The problem was induced by a serial device - TX type - who sended request to a VAX box and produced a failure on multiplexor box.
You can check intrusion (SHO INTRUSION) command and discover if break records are produced by a particular device.
Saludos.
Daniel.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-27-2005 11:36 PM
10-27-2005 11:36 PM
Re: What's this mean with "<login>" a/c in break-in record?
but... after my test.
if you try to manually break in the system, you can still get the "
further more, i found that not all the login failure record can be analysed from event log...
anybody know this problem? (maybe called bug?)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-28-2005 01:19 AM
10-28-2005 01:19 AM
Re: What's this mean with "<login>" a/c in break-in record?
Purely Personal Opinion
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-28-2005 02:17 AM
10-28-2005 02:17 AM
Re: What's this mean with "<login>" a/c in break-in record?
do you mean this record from audit file?
Auditable event: Local interactive login failure
Event time: 27-OCT-2005 19:07:43.67
PID: 2D17558A
Process name: _VTA1661:
Username:
Process owner: [SYSTEM]
Terminal name: _VTA1661, Host: 10.155.155.155 Port: 2039
Image name: $1$DGA2500:[SYS0.SYSCOMMON.][SYSEXE]LOGINOUT.EXE
Posix UID: -2
Posix GID: -2 (%XFFFFFFFE)
Status: %LOGIN-F-CMDINPUT, error reading command input
If it is so, then you can achieve it this way
(Don't write any username)
MYHOST> set host 0
Unauthorised Access is PROHIBITED
Username:
Error reading command input
Timeout period expired
%REM-S-END, control returned to node MYHOST::
Mike
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-28-2005 02:23 AM
10-28-2005 02:23 AM
Re: What's this mean with "<login>" a/c in break-in record?
You can still see the source host or device, from which the login was attempted.
Usually its caused just by no action by user.
Sometimes it's caused by unsteady network traffic (corrupted frames) or faulty or wrongly configured terminal device.
Or it can by some type of network scanning.
Mike
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-28-2005 02:52 AM
10-28-2005 02:52 AM
Re: What's this mean with "<login>" a/c in break-in record?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-28-2005 03:33 AM
10-28-2005 03:33 AM
Re: What's this mean with "<login>" a/c in break-in record?
that's the audit log, you are right
but i have not tested what you suggest :)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-30-2005 08:39 PM
10-30-2005 08:39 PM
Re: What's this mean with "<login>" a/c in break-in record?
If it from the same terminal line, that line is suspect to be bad in this respect.
You can also check the accounting file for login failures; also check opator.log on the event - the system may have been set up to use accounting and operator for siganllin login events.
Willem
OpenVMS Developer & System Manager
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-30-2005 08:45 PM
10-30-2005 08:45 PM
Re: What's this mean with "<login>" a/c in break-in record?
but as a matter of fact.from my test, i input wrong username/password for 9 times continuously. and get the analysis report from event log. it shows 8:1 (8 times have the right username, but 1 time is sdisplayed "
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-30-2005 10:02 PM
10-30-2005 10:02 PM
Solution1. Accounting.
Timeout on username :
Timeout on password :
Invalid username :
Correct username + incorrect password : the correct username
I got only 1 accounting record for each set host command (even if 3 times a username was entered). Only the last action is written (e.g. timeout after invalid username is timeout).
SSH based login may react differently.
2. Audit.
The username and password as entered was shown in the breakin records. What I think is bad. No password should be revealed to the system manager (if you see "secrey" you may guess that the password is "secret").
In the login failure records,
Wim
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-30-2005 10:11 PM
10-30-2005 10:11 PM
Re: What's this mean with "<login>" a/c in break-in record?
the last sentence "
but my result is if the username was invalid, it still showed in the audit log, with the error:"%status ... no such user"
in summary, i think there are many uncertain factors in VMS. hope my found is wrong...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-30-2005 10:22 PM
10-30-2005 10:22 PM
Re: What's this mean with "<login>" a/c in break-in record?
Was your record marked "login failure" on the first line of the audit report ?
If it is "breakin" your findings are as expected (always shows the info).
Wim
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-30-2005 11:08 PM
10-30-2005 11:08 PM
Re: What's this mean with "<login>" a/c in break-in record?
Remote interactive login failure
or
Remote interactive breakin detection
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-31-2005 02:21 AM
10-31-2005 02:21 AM
Re: What's this mean with "<login>" a/c in break-in record?
Purely Personal Opinion
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-31-2005 11:53 AM
10-31-2005 11:53 AM
Re: What's this mean with "<login>" a/c in break-in record?
you mean that it should be reasonable due to system designation?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-04-2005 07:18 AM
11-04-2005 07:18 AM
Re: What's this mean with "<login>" a/c in break-in record?
from your Forum Profile:
I have assigned points to 85 of 108 responses to my questions.
It looks like you mostly have some older streams unassigned.
Maybe you can find some time to do some assigning?
http://forums1.itrc.hp.com/service/forums/helptips.do?#33
Mind, I do NOT say you necessarily need to give lots of points. It is fully up to _YOU_ to decide how many. If you consider an answer is not deserving any points, you can also assign 0 ( = zero ) points, and then that answer will no longer be counted as unassigned.
Consider, that every poster took at least the trouble of posting for you!
To easily find your streams with unassigned points, click your own name somewhere.
This will bring up your profile.
Near the bottom of that page, under the caption â My Question(s)â you will find â questions or topics with unassigned points â Clicking that will give all, and only, your questions that still have unassigned postings.
Thanks on behalf of your Forum colleagues.
PS. â nothing personal in this. I try to post it to everyone with this kind of assignment ratio in this forum. If you have received a posting like this before â please do not take offence â none is intended!
Proost.
Have one on me.
jpe
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-05-2005 09:01 AM
11-05-2005 09:01 AM
Re: What's this mean with "<login>" a/c in break-in record?
you said "you mean that it should be reasonable due to system designation?"
Can you rephrase this question because I don't understand what you are asking.
Purely Personal Opinion
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-08-2005 01:52 PM
11-08-2005 01:52 PM
Re: What's this mean with "<login>" a/c in break-in record?
thanks!