never stop questioning

b-17.ciac-unicos-security

b-17.ciac-unicos-security
Posted Sep 23, 1999

b-17.ciac-unicos-security

MD5 | 6981920915356eb9da4a7349bcfd3234

b-17.ciac-unicos-security

Change Mirror Download

FOR OFFICIAL DEPARTMENT OF ENERGY USE ONLY
_____________________________________________________
The Computer Incident Advisory Capability
___ __ __ _ ___
/ | / \ /
\___ __|__ /___\ \___
_____________________________________________________
Information Bulletin

Increasing Security on Your UNICOS System

March 5, 1100 PST Number B-17

Critical UNICOS Information
________________________________________________________________________
PROBLEM: Some UNICOS systems have not installed all patches that may
have security implications
PLATFORM: Many versions of the Cray UNICOS operating system
DAMAGE: Possibility that some UNICOS systems are not operating as
securely as possible
SOLUTIONS: Install UNICOS patches that apply to your version of UNICOS
_______________________________________________________________________


CIAC has been working with Cray Research Corporation as well as Cray
users in the DOE community to determine which basic set of UNICOS
patches provides a baseline level of security in UNICOS systems. The
patches described below have been identified as important in assuring
that this baseline level has been met. Some of these patches have been
the subject of Cray alert bulletins (Cray Field Alerts), each of which
(if applicable) will be referenced as each patch is identified. You
may contact Cray for additional information in obtaining, installing,
and assuring that these patches have been installed on your UNICOS
system.

The mods listed below are Cray binary files available to correct each
described problem. These mods are available on the crayamid system.
Each UNICOS mod has a unique identification. For example, Cray mod
d15567cmda) and is appropriate to specific versions of the UNICOS
operating system. Unless otherwise stated, the mod will apply to the
entire family of Cray hardware, including Cray-1, X-MP, Y-MP, and
Cray-2.

1. Cray mod d15567cmda, UNICOS version 5.0/5.1

Modifies the command /bin/du . Alternatively, removing the SETUID bit
from the /bin/du command by executing the following command as root
will effectively replace the need for the above mod:

chmod 0755 /bin/du

2. Cray mod d18028, UNICOS version 5.0/5.1

Modifies the command /etc/nu. This mod has been integrated in the
baseline operating system for Cray-1/XMP/YMP at version 5.1.8d and
Version 5.1.8 for Cray-2. For more details, see Cray Field Alert #93.

3. Cray mod e13159utsa, UNICOS version 4.0, 4.EA, 5.0

This patch was the subject of Cray Field Alert #72. The patch modifies
the read/write and reada/writea system calls. A copy of the mod may be
found on the crayamid system under
/u/mods/unicos_x/5.0/uts/e13159utsa.

4. Limited buffer space in the kernel for some entries.

This problem has been corrected with the following mods. CIAC
recommends that you install any mods that apply to your system.

UNICOS 5.1: XMP d19646utsa
Cray-2 d19647inca
XMP, Cray-2 d19648tcpa
UNICOS 6.0 XMP 60uts07182a
XMP 60uts07187a
XMP, Cray-2 60uts07186a
Cray-2 60uts07184a
UNICOS 6.1 XMP 61uts07182a
XMP 61uts07187a
XMP,Cray-2 61uts07186a
Cray-2 61uts07184a

CIAC recommends that you install any mods (listed above) appropriate to
your UNICOS system. In addition, you should upgrade your version of
UNICOS to the most recent available, since many improvements to the
security of your system have been integrated into the most recent base
operating system.

For additional information or assistance, please contact CIAC:

Tom Longstaff
(415) 423-4416 or (FTS) 543-4416, or

Eugene Schultz
(415) 422-7781 or (FTS) 532-7781

Call CIAC at (415) 422-8193 or (FTS) 532-8193 or send
e-mail to ciac@cheetah.llnl.gov

Send FAX messages to: (415) 423-0913 or (FTS) 543-0913

Karis Forster and Chuck Athey provided information contained in this
bulletin. Neither the United States Government nor the University of
California nor any of their employees, makes any warranty, expressed
or implied, or assumes any legal liability or responsibility for the
accuracy, completeness, or usefulness of any information, product, or
process disclosed, or represents that its use would not infringe
privately owned rights. Reference herein to any specific commercial
products, process, or service by trade name, trademark manufacturer,
or otherwise, does not necessarily constitute or imply its
endorsement, recommendation, or favoring by the United States
Government or the University of California. The views and opinions of
authors expressed herein do not necessarily state or reflect those of
the United States Government nor the University of California, and
shall not be used for advertising or product endorsement purposes.

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close