[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference csc32::consolemanager

Title:POLYCENTER Console Manager
Notice:Kits, Scans, Docs on CSC32:: as PCM$KITS:,PCM$DOCS:, PCM$SCANS:
Moderator:CSC32::BUTTERWORTH
Created:Thu Aug 06 1992
Last Modified:Fri Jun 06 1997
Last Successful Update:Fri Jun 06 1997
Number of topics:1541
Total number of notes:6564

1409.0. "Big Security problem !!!!" by SWTHOM::LEROYER (Cul qui gratte , main qui pue) Mon Oct 14 1996 12:34

	Hello , 

A customer had different problems like "Transmission break", "Console CONNECT
crashes" , Console RECONFIGURE hangs" and ... He was in version V1.6-110 
OK , i take a look in "consoleeco2016_unix.release_notes" and i found all
solutions for problems.
I said to this customer : -upgrade to DCROSF162 with setld
		     and  -patch with PATCH308.TAR  ( why not??)

Oh surprise with this version V1.6-308 , all non-PCM users can used a CONSOLE
CONNECT throught the C3.


I have tried on my own system.The source was DCROSF162 (like V1.6-201) ALL OK.
I patch with PATCH307 or PATCH307A or PATCH308 with the recommendation
	# chmod 4555 /usr/opt/DCR160/bin/OSF/console
	# chmod 544 /sbin/console_startup
and i have the same problem: A non-PCM user can connect the console throught C3.

	For this customer and for me , it 's a serious security problem.

	Does anybody have this problem ?
	Is there a workaround ?
	....

Thanks in advance.

T.RTitleUserPersonal
Name
DateLines