HP Security Bulletin - A potential security vulnerability has been identified with HP OpenVMS VAX version 7.x and 6.x and OpenVMS Alpha Version 7.x or 6.x that may allow a local authorized user to gain unauthorized privileged access to data and system resources.
e66e3ed9d1547351b44ccc372e680af3This DCL script abuses the old psi_mail trick on VAX/VMS systems to remotely find valid users.
9890000f54a0213e136a51bd7d083523The VAX/VMS SYSUAF.DAT file
645ca1923619a7d35137c53bf198ed7cUser's Guide to VAX/VMS
3bc692962e43864b89f200b1fbd24650Modernz #11. VMS / VAX
1653d9c2e032b4a6a7c5da561c26589cCERT Advisory - VAX/VMS Breakins
f798fa874650c78970881fbc6c58393aDECnet, UNIX UUCP files, VAX - Tekno DCS help,
64290bece59995a12630c2f8a1b1e49aPretty complete file on hacking VAX/VMS machines
8cb93208f4cb82eb5b2415a1f17292e1Default passwords for VAX/VMS, DEC-10, TOPS 10,
31158b573473039878fbc3439eee27e2A VAX decoy script to grab some accunts.
0e9b48477a5ef9a5ac73fc3e20601e5aHow to hack VAX's.
e86524de1ff10dd3dd2a7c6b7de9fbf3VAX/VMS hacking FAQ
26dabc9ffa59eb982e9680f9ae865517Network Associates COVERT Labs Security Advisory - The L-Soft LISTSERV web archive (wa,wa.exe) component contains an unchecked buffer allowing remote execution of arbitrary code with the privileges of the LISTSERV daemon. Vulnerable systems include L-Soft LISTSERV Web Archives 1.8d (confirmed) and 1.8c (inferred) for Windows 9x, Windows NT 3.5x, Windows NT 4.0, Windows 2000, UNIX (all vendors), and OpenVMS VAX.
58af72d4575b8af155ed349ceb0f7589bt systemx switch administration and overview of bt telcom operations and maintanance centers, written for f41th magazine. the system is based on a vax/vms platform with multi-level oracle databases, a look into the man-machine interface of uk switching, and remote switch/node interfaces.
0f9e81592d3b2509db6673ddff785b37Subject VAX/VMS failure to disable user accounts Date 13-Feb-93
4010fd66e26708916beb1dcc1140c9efNetBSD uses the ptrace(2) system call to trace and debug other processes. The debugging process can also modify the internal registers, including the status (PSL) register, for the process being debugged. Besides the normal user-accessible flags, the VAX hardware also stores information about privilege levels and used stacks in the PSL. Those flags are only altered via the instruction REI (return from interrupt) or LDPCTX (load process context) and cannot be modified while running in "user" mode. NetBSD security page here.
d202015e49826330e6cff56fe5dd9e41A potential vulnerability with LOGINOUT for OpenVMS (VAX & ALPHA) V7.1 software has been discovered.
78d220bad7256c6b4c2850a4f09bf587