SpyderByte.com: OpenVMS.org dba.OpenVMS.org dcl.OpenVMS.org de.OpenVMS.org fr.OpenVMS.org it.OpenVMS.org
   
Home Contribute News, Jobs, Press Releases, etc. Advertise on OpenVMS.org About/Contact Search News Archives
More Links
  • US-CERT Carnegie Mellon University database
  • Read here!
  • Printer friendly version
    Share this story

    Navigation
    VMS Audio Network (VAN)
    Featured Articles
    Vendors
    Training
    Golden Eggs
    Golden Eggs x86
    Help for VMS Beginners
    Documentation
    Developer Resources
    Books
    Commercial Software
    Open Source & Freeware
    OpenSource ported to VMS
    Resources
    FAQs/How-to
    Lists/Newsgroups/Forums
    Security Advisories & Info
    OpenVMS Patches

    Forums
     HP ITRC OpenVMS forum
     OpenVMS Hobbyist forums
     Usenet: comp.os.vms

    Mailing Lists
    OpenVMS.org Newsletter
    OpenVMS.org Alerts
    Rdb Managers

    Roadmaps
    OpenVMS Roadmap (2009)
    Itanium Roadmap
    HP Roadmaps (2002)
    BCS Roadmap FAQ (2002)
    Storage Roadmap FAQ (2002)


    OpenVMS.org Info
    OpenVMS.org Admin Staff:
    Ken Farmer, Ian Miller
    About
    Search OpenVMS.org
    News Archives
    Mobile Edition
    Submit News
    Advertising Information

    OpenVMS.org Websites

    Databases running on OpenVMS


    Digital Command Languauge


    French



    German


    Italian



    Latest News

    Is OpenVMS vulnerable ?
    Posted by Antonio Vigliotti on Tuesday October 25 2005 @ 05:17AM EDT
    From: Antonio Vigliotti, it.OpenVMS.org

    OpenVMS supporters considered this OS the best you can find as far as security. But, is this really true ?

    To answer this question, we have looked at the US-CERT Carnegie Mellon University database, one of the most authoritative sources for vulnerability certification. Our query was OpenVMS vulnerabilities in October 2005 and the database returned 16 (yes, sixteen) pages of instances. Surprised? Shocked, maybe? Wait before you throw your Alpha server out of the window: there is an explanation for all this.

    The latest instance was related to CA-Unicenter, a third party software. Nothing to worry about, then.

    - Potential DoS for BIND V9 service: does not affect OpenVMS.
    - Execution of unauthorized PHP code on server: does not affect OpenVMS.
    - DHCP buffer overflow: does not affect OpenVMS.
    - Possible remote execution of code with CVS software: does not affect OpenVMS.
    - FTP buffer overflow: does not affect OpenVMS.
    - Warning issues related to SIP Session Initialization Protocol -- guess: does not affect OpenVMS.

    The most relevant instance has to do with OpenSSH, the encrypted protocol created for web access. Two vulnerabilities have been noted, both allow the remote execution of unauthorized code. MultiNet, TCPware and SSH for OpenVMS are immune to those problems.

    You may find the vulnerability report here, http://search.cert.org/query.html

    Have some spare time to kill? Try to do the same for other popular operating systems and have fun!

    Understand Italian? Read here!


    < OpenVMS Roadmap updated | VMS82I_FIBRE_SCSI-V0100, ECO Kit Release >



    ADVERTISEMENT:
    Sponsors







    The OpenVMS Consultant
    OpenVMS Consulting


    The Minimum You Need to Know book series
    Books by Roland Hughes


    Alpha and VAX Replacement
    StanQ.com



    Interested in Advertising? Click here...

    Friends of VMS
    Connect (HP User Community):
    Connect Home
    Connect Chapters
    Connect Special Interest Groups

    United Kingdom
    Canada
    Encompasserve/DECUServe
    OpenVMS Hobbyist
    More usergroups...
    Other Sites:
    Aaron's OpenVMS blog
    Alexey Chupahin
    Arne Vajhoej
    DECUS Library Compendium
    DJE Systems
    Dr OpenVMS blog
    Francesco Gennai
    Eight-Cubed blog
    Free OpenVMS Software
    Galen Tackett
    HoffmanLabs
    Hunter Goatley
    Ian Miller
    Itanium Solutions Alliance
    Jeff Cameron
    John Fisher
    Syltrem VMS Page (French)
    Kednos PL/I
    Keith Parris
    Migration Specialties
    Noetic Systems, Inc
    OpenOffice Port to VMS
    OpenVMSPlanet.org
    OpenVMS Rocks
    Preatorian.net
    Retrobeep
    Steven M. Schweda
    SYSMGR Blog
    TMESIS Software
    Trends That Matter
    VAMP (VMS, Apache, MySQL, PHP)
    VIM
    Vaxination
    Visio Cafe (HP Templates)
    VMSresource.org.uk
    XDelta
    Free VMS Accounts:
    Deathrow Public OpenVMS Cluster
    Encompasserve/DECUServe/EISNER
    Polarhome
    Fafner
    Poetry Hacklab
    Marway.Org
    In Memory:
    John Wisniewski Memorial Site
    Terry Shannon Memorial Site


    OpenVMS Rings

    OpenVMS Webring

    Prev

    Random

    Next

    Prev5

    List

    Next5

    OpenVMS Gurus

    Prev

    Random

    Next

    Prev5

    List

    Next5




    Home About & Contact Search Archive Mobile Submit News Sponsorship & Advertising
         Copyright © 2001-2007 SCORSE, LLC
    OpenVMS® is a trademark of HP
    All other trademarks are those of their owners.
        
      SpyderByte.com ;Technical Portals