HPUX rexecd bug on trusted system

Kevin K. Sochacki (kksocha@ERENJ.COM)
Fri, 05 Dec 1997 17:28:18 -0500

I have discovered a bug in rexecd on system running HPUX 10.20 that have
been converted to trusted systems.

On unsuccessful login attempts via rexec/rexecd the bad login counter
(u_numunsuclog) is updated as it should, however on any successful login
the bad login counter does not get cleared. So if users inadvertently
miss type their password even once between successful logins they will
eventually be locked out. Lockouts should only occur when consecutive
unsuccessful logins exceed the allowed bad logins.

For those of you how have converted to a trusted system and have not
applied patch PHNE_12161 you are vulnerable to a brut force attack of
guessing password via rexec. Patch PHNE_12161 fix a problem of not
updating the bad login counter (u_numunsuclog) circumvent the lockout
feature of unsuccessful user logins.

This problem has been report to HP and is currently being addressed.

