HP Unix 11.0, 64 bit servers, doesn't appear to log failed `su` tries, making it possible to use a brute force program to hack into the root account by trying every possible combination of password.
Credit:
HP's web site can be found here: www.hp.com.
You can determine whether you are using an affected system by running `uname -a' the result should be `B.11.00' followed by a character. If the character is A then this is a 32 bit version of the UNIX system, if the character is B then this is the 64 bit version of the UNIX system, and you are probably affected by the bug.