home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!munnari.oz.au!bunyip.cc.uq.oz.au!news.qut.edu.au!qut.edu.au!chan
- From: chan@qut.edu.au
- Newsgroups: comp.sys.hp
- Subject: Bug in hp-ux8? for Hacker???
- Message-ID: <1992Jul23.140959.51693@qut.edu.au>
- Date: 23 Jul 92 14:09:59 EST
- Organization: Queensland University of Technology
- Lines: 16
-
- We have a HP cluster with 635 as server and 300s as diskless workstations
- running yellow pages. Recently, we have some problem of remote logging into
- the system from unauthorised machines.
- 1) There are some root login recorded in last (wtmp) but we have set
- /etc/securetty to only one line of "console". I dont understand how they can
- bypass the kernel checking. Is there a bug in the OS that will allow this
- type of log in ???
- 2) In the password file, a user has his passwd file set as "*" and
- the shell field as "/bin/sync". But this user still appears on the wtmp
- log as had log in to the system and through the system to telnet to other
- machines. Is there another bug in the OS that will allow this to happen??
-
- Is ther any body out there that has the same experience who can answer
- my question???
-
- Please e-mail me on schan@ice.fit.qut.edu.au
-