T.R | Title | User | Personal Name | Date | Lines |
---|
1444.1 | | CSC32::R_SOMBERG | | Thu Sep 14 1989 18:52 | 5 |
| opsss.. forgot:
With test #2 after the first securiy alarm message ,we not getting any
other message doesn't matter what we are typing on the password prompt
as with test #1.
|
1444.2 | Break-in evasion? | BOMBE::MOORE | BaN CaSe_sEnSiTiVe iDeNtIfIeRs! | Thu Sep 14 1989 19:10 | 3 |
| Sounds like break-in evasion. Check for intrusion records against
WSAn: devices.
|
1444.3 | Try checking GBLPAGES | KRIS10::COX | Kristen Cox - Dallas ACT Sys Mgr | Fri Sep 15 1989 14:03 | 5 |
| This happened to me as well. I did not have enough GBLPAGES. I set MIN_GBLPAGES
to 45K and it corrected the problem on all of my nodes that had it.
KLC
|
1444.4 | same results with 45,000 | CSC32::R_SOMBERG | | Fri Sep 15 1989 15:01 | 2 |
| Tried changing GBLPAGES to 45,000 - same results.
|
1444.5 | Another shot in the dark? | KRIS10::COX | Kristen Cox - Dallas ACT Sys Mgr | Fri Sep 15 1989 16:39 | 11 |
| I'm a new DECwindows user myself, but seem to have had my share of problems.
Two other things that have caused me similar problems are:
(1) My LOGIN.COM had some things that DECwindows didn't like. In fact, I think
it was my DECW$LOGIN.COM. Anyways, if you rename both files you can easily
tell.
(2) Check any .LOG files in your directory for possible errors...
I can't think of anything else...
|
1444.6 | | CSC32::R_SOMBERG | | Fri Sep 15 1989 17:27 | 5 |
| With out tests, we renamed : sylogin.com & login.com - no
decw$login.com and the decw$sylogin.com is the default.
Reuven.
|
1444.7 | Sounds like something in SM | HYDRA::COAR | Nobody move or I'll shoot my foot! | Mon Sep 18 1989 11:55 | 9 |
| From .1, it sounds as though the session manager has vaildated the password, but
hasn't proceeded to the point where it tears down the pause window. Not getting
any further alarms sounds like the SM isn't processing the subsequent input.
From another process, what does SHOW SYSTEM, ANALYZE /SYSTEM, and SHOW PROCESS
/CONTINUOUS tell you about the session manager process?
#ken :-)}
|
1444.8 | The solution. | CSC32::R_SOMBERG | | Fri Sep 22 1989 18:58 | 20 |
| This is a short summary of what we found:
- We steped through the PAUSE code of the SM at the point where
it tries to validate the password by reading the UAF. At this point
it fails with RMS-E-RSZ.
- If failed the PAUSE code did not triggered any error message to the
user, simply returned back.
- We had only one security alarm message because it was using $GETUAI
with a special context parameter (using the privous context)
- In V5.2 there was a change in the $GETUAI system service to check if
record read from the uaf is at least 644 - if not RSZ error.
- THE USER USED SYSUAF.DAT FILE LEFT FROM V3 OF VMS - HE NEVER DID THE
CONVERT IN V4.
- We converted his uaf and it is working fine.
Reuven.
|