nv-l

RE: [nv-l] Migrating from Netview 6.0.3 to 7.1

2002-11-06 10:06:50
Subject: RE: [nv-l] Migrating from Netview 6.0.3 to 7.1
From: James Shanks <jshanks AT us.ibm DOT com>
To: nv-l AT lists.tivoli DOT com
Date: Wed, 6 Nov 2002 10:06:50 -0500
Yes, it was added to 6.0.3, but only if you applied the e-fix for APAR 
IY21527.  And you had to contact Support to obtain that.  Lots of people 
did not, so their first exposure to the escape characters will be in some 
level of 7.1.  The changes are documented in the Release Notes for 7.1, as 
is the use of netnmrc.pre to disable the fix or alter the acceptable 
characters, but hey, who reads those?  :-)

James Shanks
Level 3 Support  for Tivoli NetView for UNIX and NT
Tivoli Software / IBM Software Group




"Bursik, Scott {PBSG}" <Scott.Bursik AT pbsg DOT com>
11/06/2002 08:30 AM

 
        To:     "'nv-l AT lists.tivoli DOT com'" <nv-l AT lists.tivoli DOT 
com>, lesdickert AT att DOT net
        cc: 
        Subject:        RE: [nv-l] Migrating from Netview 6.0.3 to 7.1



Wasn't the fix adding the escape characters added in 6.0.3?

Scott Bursik
Event Systems Management
Pepsico Business Solutions Group
(972) 334-3757
scott.bursik AT pbsg DOT com

-----Original Message-----
From: netview AT toddh DOT net [mailto:netview AT toddh DOT net] 
Sent: Tuesday, November 05, 2002 5:37 PM
To: lesdickert AT att DOT net
Cc: nv-l AT lists.tivoli DOT com
Subject: Re: [nv-l] Migrating from Netview 6.0.3 to 7.1

lesdickert AT att DOT net writes:
> Or, if you want it to work just like in 6.0.3,
> create a file in /usr/OV/bin called
> 
> netnmrc.pre
> 
> with one line in it:
> 
> export AdditionalLegalTrapCharacters=disable
> 
> and bring netview down and back up and then trapd
> will quit putting those annoying \ characters into
> the varbind data.
> 
> Oops!  Was I not supposed to reveal this secret???


Well, if you're comfortable allowing any device with udp/162
visibility to your netview server capable of running arbitrary
commands in root context on your NetView server. 

I'm under the distinct impression that this would leave you wide open
to a handy root compromise per.
        http://www.cert.org/advisories/CA-2001-24.html

I for one wouldn't advocate disabling that fix. 

-- 
Todd H.
http://www.toddh.net/

---------------------------------------------------------------------
To unsubscribe, e-mail: nv-l-unsubscribe AT lists.tivoli DOT com
For additional commands, e-mail: nv-l-help AT lists.tivoli DOT com

*NOTE*
This is not an Offical Tivoli Support forum. If you need immediate
assistance from Tivoli please call the IBM Tivoli Software Group
help line at 1-800-TIVOLI8(848-6548)

---------------------------------------------------------------------
To unsubscribe, e-mail: nv-l-unsubscribe AT lists.tivoli DOT com
For additional commands, e-mail: nv-l-help AT lists.tivoli DOT com

*NOTE*
This is not an Offical Tivoli Support forum. If you need immediate
assistance from Tivoli please call the IBM Tivoli Software Group
help line at 1-800-TIVOLI8(848-6548)