<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: lockdown /etc/services in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701625#M58052</link>
    <description>Hi if you want to deactivate the telnet and ftp services for certain users or machines, then you need to update the file /var/adm/inetd.sec&lt;BR /&gt;&lt;BR /&gt;There you can specify the service name and to whom you wna to block the access (machine).....&lt;BR /&gt;Hope this helps.&lt;BR /&gt;Simply by making /etc/services readable will not do anything. That is an irrelavent thing here. &lt;BR /&gt;&lt;BR /&gt;-pap</description>
    <pubDate>Thu, 11 Apr 2002 14:47:05 GMT</pubDate>
    <dc:creator>pap</dc:creator>
    <dc:date>2002-04-11T14:47:05Z</dc:date>
    <item>
      <title>lockdown /etc/services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701622#M58049</link>
      <description>I've been asked to make the /etc/services file readable by root only; however, users still need to be able to telnet &amp;amp; ftp.  I thought about using Symark Powerbroker to give users ftp &amp;amp; telnet access, but applications such as Oracle &amp;amp; Valencia also need to work without problems.  Have anyone had to do this or have any suggestions?</description>
      <pubDate>Thu, 11 Apr 2002 14:27:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701622#M58049</guid>
      <dc:creator>Vernell Woods_1</dc:creator>
      <dc:date>2002-04-11T14:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: lockdown /etc/services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701623#M58050</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;it should be read only be default , so change it.&lt;BR /&gt;&lt;BR /&gt;cheers&lt;BR /&gt;John.</description>
      <pubDate>Thu, 11 Apr 2002 14:31:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701623#M58050</guid>
      <dc:creator>John Carr_2</dc:creator>
      <dc:date>2002-04-11T14:31:19Z</dc:date>
    </item>
    <item>
      <title>Re: lockdown /etc/services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701624#M58051</link>
      <description>ignore my last comment I misread the post</description>
      <pubDate>Thu, 11 Apr 2002 14:32:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701624#M58051</guid>
      <dc:creator>John Carr_2</dc:creator>
      <dc:date>2002-04-11T14:32:37Z</dc:date>
    </item>
    <item>
      <title>Re: lockdown /etc/services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701625#M58052</link>
      <description>Hi if you want to deactivate the telnet and ftp services for certain users or machines, then you need to update the file /var/adm/inetd.sec&lt;BR /&gt;&lt;BR /&gt;There you can specify the service name and to whom you wna to block the access (machine).....&lt;BR /&gt;Hope this helps.&lt;BR /&gt;Simply by making /etc/services readable will not do anything. That is an irrelavent thing here. &lt;BR /&gt;&lt;BR /&gt;-pap</description>
      <pubDate>Thu, 11 Apr 2002 14:47:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701625#M58052</guid>
      <dc:creator>pap</dc:creator>
      <dc:date>2002-04-11T14:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: lockdown /etc/services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701626#M58053</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;any reason for this request ?&lt;BR /&gt;I mean "services" is a lookup database for the systemcall "getservbyname".&lt;BR /&gt;&lt;BR /&gt;So whatever is in there does not mean the service is available. Just to take read away looks to me like a try to "hide by disguise" a service. &lt;BR /&gt;&lt;BR /&gt;This is pretty much like using a non-standard tcpip-port for a standard application which is opposed to common thinking no security feature. A real hacker will use a portscan-tool and find your Oracle-Listener even if it runs on Port 12345.&lt;BR /&gt;So the only non-benefit is you have more trouble with your administration.&lt;BR /&gt;&lt;BR /&gt;If you need protection, go for a firewall and a good concept.&lt;BR /&gt;&lt;BR /&gt;Just my 0.02 ???&lt;BR /&gt;Volker</description>
      <pubDate>Thu, 11 Apr 2002 14:50:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701626#M58053</guid>
      <dc:creator>Volker Borowski</dc:creator>
      <dc:date>2002-04-11T14:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: lockdown /etc/services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701627#M58054</link>
      <description>Let me explain a little further:   Our auditors said that it was an exception to have /etc/services readable by all users.  We want to make it readable by root "ONLY".  In doing so, users won't be able to ftp or telnet...but we want them to be able to.  I need to make /etc/services readable by root only and still have users able to ftp &amp;amp; telnet.  At the same time, I need applications that make calls to other servers to function correctly.  I don't understand why /etc/services need to be locked down or how it's an exception, but I have to do it.    PLEASE HELP!!!</description>
      <pubDate>Thu, 11 Apr 2002 14:51:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701627#M58054</guid>
      <dc:creator>Vernell Woods_1</dc:creator>
      <dc:date>2002-04-11T14:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: lockdown /etc/services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701628#M58055</link>
      <description>Hi:&lt;BR /&gt;&lt;BR /&gt;Volker's comments say it all!.  Don't be badgered by the auditors.  '/etc/services' should be readable by all, and need not be marked writeable, since as 'root' you can edit (write) it regardless.  Having controlled that, only you (root) can add or remove services.  Auditors often go on witch-hunts to show management that they earned their keep!&lt;BR /&gt;&lt;BR /&gt;Regards!&lt;BR /&gt;&lt;BR /&gt;...JRF...</description>
      <pubDate>Thu, 11 Apr 2002 14:59:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701628#M58055</guid>
      <dc:creator>James R. Ferguson</dc:creator>
      <dc:date>2002-04-11T14:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: lockdown /etc/services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701629#M58056</link>
      <description>WELL SAID, JRF!&lt;BR /&gt;&lt;BR /&gt;Rgds,&lt;BR /&gt;JEFF&lt;BR /&gt;&lt;BR /&gt;P.S.&lt;BR /&gt;inetd.sec &amp;amp; inetd.conf is where the REAL, internal security is &amp;amp; SHOULD be set! And NOTHING beats a well configured FW for external security!</description>
      <pubDate>Thu, 11 Apr 2002 15:05:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701629#M58056</guid>
      <dc:creator>Jeff Schussele</dc:creator>
      <dc:date>2002-04-11T15:05:21Z</dc:date>
    </item>
    <item>
      <title>Re: lockdown /etc/services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701630#M58057</link>
      <description>Vee,&lt;BR /&gt;&lt;BR /&gt;/etc/services much like /etc/rpc is a lookup table for Berkely and Arpa sevices for the Unix OS.&lt;BR /&gt;&lt;BR /&gt;These have to be available for the OS (and users) to have basic functionality with the outside world.&lt;BR /&gt;&lt;BR /&gt;As was suggested earlier, different options exist for locking down the server securely and effectively.&lt;BR /&gt;&lt;BR /&gt;The auditors should provide supporting doc (reasons) for such request.&lt;BR /&gt;&lt;BR /&gt;TCPwrappers (HP's IPSec900), SSL, and HP's patch PHNE_23949 which helps control ftp'users' access may help in controlling access to this server.&lt;BR /&gt;&lt;BR /&gt;Finally you may want to search/browse the security forum for past postings.</description>
      <pubDate>Thu, 11 Apr 2002 15:05:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701630#M58057</guid>
      <dc:creator>Frank Quinteros</dc:creator>
      <dc:date>2002-04-11T15:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: lockdown /etc/services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701631#M58058</link>
      <description>What the heck is their basis for such a demand?  Do they know anything about UNIX?  Of course /etc/services has to be world readable.&lt;BR /&gt;&lt;BR /&gt;I hope they're not making any other similarly stupid demands.  If so, you need to raise the red flag with management.&lt;BR /&gt;&lt;BR /&gt;Darrell</description>
      <pubDate>Thu, 11 Apr 2002 15:12:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701631#M58058</guid>
      <dc:creator>Darrell Allen</dc:creator>
      <dc:date>2002-04-11T15:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: lockdown /etc/services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701632#M58059</link>
      <description>Thanks Guys for your responses.  I'll go back and ask exactly what the issue is.  Maybe with a more in-depth explanation, I can come up with a better plan.&lt;BR /&gt;&lt;BR /&gt;Thanks again.</description>
      <pubDate>Thu, 11 Apr 2002 15:15:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/lockdown-etc-services/m-p/2701632#M58059</guid>
      <dc:creator>Vernell Woods_1</dc:creator>
      <dc:date>2002-04-11T15:15:11Z</dc:date>
    </item>
  </channel>
</rss>

