<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IT security forbidden processes in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/it-security-forbidden-processes/m-p/5885793#M729205</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Indeed depends on the application used on that system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;auth&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; used by MC/SG, sendmail, but may be configuration may avoid that use&lt;BR /&gt;bootps&amp;nbsp; -&amp;gt; if the no other system boot getting config from that system, no need (&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; so if your system is not an ignite server should not be useful&lt;BR /&gt;chargen&amp;nbsp; -&amp;gt; depends on applications , system itself doesn't need it&lt;BR /&gt;discard&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; depends on applications, system itself doesn't need it, but often useful for test purpose&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MC/SG packages could use it&lt;BR /&gt;dtspc&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; needed if you use DCE&lt;BR /&gt;echo&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt;&amp;nbsp; depends on application, but usually very useful for test purpose&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MC/SG packages could use it&lt;BR /&gt;exec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; no rexec possible, doens't look like to be mandatory&lt;/P&gt;&lt;P&gt;login&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; no rlogin possible, it is a choice, need to check application don't use it&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ntalk&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; ntalk, doesn't looks like to be that useful&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;printer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; remote print ,&lt;BR /&gt;shell&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; -&amp;gt; remsh, may be avoided, but may need to check scripts which need to&amp;nbsp; use it ignite? MC/SG?&lt;BR /&gt;tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; used with bootp to get the kernel from the server, so if not an ignite server should be ok.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now all this is just a first quick look, a real assesment should be made.&lt;/P&gt;</description>
    <pubDate>Fri, 30 Nov 2012 12:53:44 GMT</pubDate>
    <dc:creator>Laurent Menase</dc:creator>
    <dc:date>2012-11-30T12:53:44Z</dc:date>
    <item>
      <title>IT security forbidden processes</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/it-security-forbidden-processes/m-p/5885725#M729204</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a list of processes provided by IT Security that are forbidden to be run on HPUX servers. I want to have a close look at it and check if they really needs to be stopped from running OR there are some process that are mandatory from application view point or OS view point.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below are the processes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;auth&lt;BR /&gt;bootps&lt;BR /&gt;chargen&lt;BR /&gt;discard&lt;BR /&gt;dtspc&lt;BR /&gt;echo&lt;BR /&gt;exec&lt;/P&gt;&lt;P&gt;login&lt;/P&gt;&lt;P&gt;ntalk&lt;BR /&gt;printer&lt;BR /&gt;shell&lt;BR /&gt;tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Nov 2012 12:28:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/it-security-forbidden-processes/m-p/5885725#M729204</guid>
      <dc:creator>vijay alur alur</dc:creator>
      <dc:date>2012-11-30T12:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: IT security forbidden processes</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/it-security-forbidden-processes/m-p/5885793#M729205</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Indeed depends on the application used on that system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;auth&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; used by MC/SG, sendmail, but may be configuration may avoid that use&lt;BR /&gt;bootps&amp;nbsp; -&amp;gt; if the no other system boot getting config from that system, no need (&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; so if your system is not an ignite server should not be useful&lt;BR /&gt;chargen&amp;nbsp; -&amp;gt; depends on applications , system itself doesn't need it&lt;BR /&gt;discard&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; depends on applications, system itself doesn't need it, but often useful for test purpose&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MC/SG packages could use it&lt;BR /&gt;dtspc&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; needed if you use DCE&lt;BR /&gt;echo&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt;&amp;nbsp; depends on application, but usually very useful for test purpose&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MC/SG packages could use it&lt;BR /&gt;exec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; no rexec possible, doens't look like to be mandatory&lt;/P&gt;&lt;P&gt;login&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; no rlogin possible, it is a choice, need to check application don't use it&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ntalk&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; ntalk, doesn't looks like to be that useful&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;printer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; remote print ,&lt;BR /&gt;shell&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; -&amp;gt; remsh, may be avoided, but may need to check scripts which need to&amp;nbsp; use it ignite? MC/SG?&lt;BR /&gt;tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; used with bootp to get the kernel from the server, so if not an ignite server should be ok.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now all this is just a first quick look, a real assesment should be made.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Nov 2012 12:53:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/it-security-forbidden-processes/m-p/5885793#M729205</guid>
      <dc:creator>Laurent Menase</dc:creator>
      <dc:date>2012-11-30T12:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: IT security forbidden processes</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/it-security-forbidden-processes/m-p/5886047#M729206</link>
      <description />
      <pubDate>Fri, 30 Nov 2012 15:04:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/it-security-forbidden-processes/m-p/5886047#M729206</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2012-11-30T15:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: IT security forbidden processes</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/it-security-forbidden-processes/m-p/6028723#M729207</link>
      <description>&lt;P&gt;Thanks for replying!!&lt;/P&gt;</description>
      <pubDate>Sat, 13 Apr 2013 20:58:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/it-security-forbidden-processes/m-p/6028723#M729207</guid>
      <dc:creator>vijay alur alur</dc:creator>
      <dc:date>2013-04-13T20:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: IT security forbidden processes</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/it-security-forbidden-processes/m-p/6071819#M729208</link>
      <description>all of these are started by inetd&lt;BR /&gt;&lt;BR /&gt;comment out the services in /etc/inetd.cond and execute&lt;BR /&gt;&lt;BR /&gt;inetd -c. to rearead the file&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sat, 18 May 2013 21:39:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/it-security-forbidden-processes/m-p/6071819#M729208</guid>
      <dc:creator>Emil Velez_2</dc:creator>
      <dc:date>2013-05-18T21:39:59Z</dc:date>
    </item>
  </channel>
</rss>

