IRIX workstation hardening
#1
IRIX workstation hardening
Interesting document.

https://www.giac.org/paper/gsec/4374/sec...ion/107207
Shiunbird
Administrator

Trade Count: (1)
Posts: 553
Threads: 45
Joined: Mar 2021
Location: Czech Republic
Find Reply
05-04-2021, 01:31 PM
#2
RE: IRIX workstation hardening
I've seen that paper around and adapted it to our wiki as part of IRIX Setup 101.

I'm the system admin of this site. Private security technician, licensed locksmith, hack of a c developer and vintage computer enthusiast. 

https://contrib.irixnet.org/raion/ -- contributions and pieces that I'm working on currently. 

https://codeberg.org/SolusRaion -- Code repos I control

Technical problems should be sent my way.
Raion
Chief IRIX Officer

Trade Count: (9)
Posts: 4,239
Threads: 533
Joined: Nov 2017
Location: Eastern Virginia
Website Find Reply
05-04-2021, 02:49 PM
#3
RE: IRIX workstation hardening
Oh those are both pretty great, I hadn’t seen that part of the Wiki before. I wonder, with PAM, could newer security modules be ported over?

---
Octane2 Octane O2
jenna64bit
O2

Trade Count: (1)
Posts: 35
Threads: 2
Joined: Apr 2020
Location: USA
Find Reply
05-06-2021, 12:18 PM
#4
RE: IRIX workstation hardening
It's not the same as Linux PAM it appears and I don't know if it was ever documented.

I'm the system admin of this site. Private security technician, licensed locksmith, hack of a c developer and vintage computer enthusiast. 

https://contrib.irixnet.org/raion/ -- contributions and pieces that I'm working on currently. 

https://codeberg.org/SolusRaion -- Code repos I control

Technical problems should be sent my way.
Raion
Chief IRIX Officer

Trade Count: (9)
Posts: 4,239
Threads: 533
Joined: Nov 2017
Location: Eastern Virginia
Website Find Reply
05-06-2021, 01:17 PM
#5
RE: IRIX workstation hardening
Dang, I was hoping it'd be something along the lines of an Irix kernel module with the same API, as PAM is for Linux. Anyway, thanks again for the wiki pages!

---
Octane2 Octane O2
jenna64bit
O2

Trade Count: (1)
Posts: 35
Threads: 2
Joined: Apr 2020
Location: USA
Find Reply
05-07-2021, 02:11 PM
#6
RE: IRIX workstation hardening
It should be worth noting that not even all of the BSDs use PAM. I'm not saying it's impossible to Port modules over but as far as I know it's not a straightforward drop-in process.

The only place it's really standard is in GNU/Linux and FreeBSD as far as I know. Solaris might have it but I haven't looked at that recently.

A lot of my efforts are focused on documenting things and replacing userland components right now because that's where we have the most flexibility. Until the various subsystems of the system kernel are documented it's going to be very difficult to audit it much less extend it.

I'm the system admin of this site. Private security technician, licensed locksmith, hack of a c developer and vintage computer enthusiast. 

https://contrib.irixnet.org/raion/ -- contributions and pieces that I'm working on currently. 

https://codeberg.org/SolusRaion -- Code repos I control

Technical problems should be sent my way.
Raion
Chief IRIX Officer

Trade Count: (9)
Posts: 4,239
Threads: 533
Joined: Nov 2017
Location: Eastern Virginia
Website Find Reply
05-07-2021, 03:23 PM
#7
RE: IRIX workstation hardening
Some angel could one day leak IRIX's source code...
(if anyone at HP still has it)
Shiunbird
Administrator

Trade Count: (1)
Posts: 553
Threads: 45
Joined: Mar 2021
Location: Czech Republic
Find Reply
05-07-2021, 03:36 PM
#8
RE: IRIX workstation hardening
I have source code but it's on a tape in a safe deposit box. I've never looked at the code personally.

I'm the system admin of this site. Private security technician, licensed locksmith, hack of a c developer and vintage computer enthusiast. 

https://contrib.irixnet.org/raion/ -- contributions and pieces that I'm working on currently. 

https://codeberg.org/SolusRaion -- Code repos I control

Technical problems should be sent my way.
Raion
Chief IRIX Officer

Trade Count: (9)
Posts: 4,239
Threads: 533
Joined: Nov 2017
Location: Eastern Virginia
Website Find Reply
05-07-2021, 08:05 PM
#9
RE: IRIX workstation hardening
All of IRIX 5.3 is online, it's pretty easy to find it so I won't post a link. All I can say is the coders were not big believers in commenting. Only parts of IRIX 6 ever made it into the wild.

Project: Temporarily lost at sea
Plan: World domination! Or something...
vishnu
Tezro, Octane2, 2 x Onyx4

Trade Count: (0)
Posts: 1,245
Threads: 41
Joined: Dec 2017
Location: Minneapolis, Minnesota USA
Find Reply
05-08-2021, 06:38 AM
#10
RE: IRIX workstation hardening
(05-07-2021, 08:05 PM)Raion Wrote:  I have source code but it's on a tape in a safe deposit box. I've never looked at the code personally.

Please, please, please, please, PLEASE make a backup.

Octane2  R14k 600MHz, V10, 2GB RAM, 73GB disk, IRIX 6.5.22
shrek
It's not done until it's ogre.

Trade Count: (0)
Posts: 233
Threads: 19
Joined: Jan 2019
Location: United States
Find Reply
05-10-2021, 05:40 PM


Forum Jump:


Users browsing this thread: 1 Guest(s)