<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: inetd services in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/inetd-services/m-p/3411428#M747760</link>
    <description>Out of curiousity, if ports that are vulnerable, why HP did not closed or disable them?&lt;BR /&gt;&lt;BR /&gt;My IT security personnel has done a scan to a newly installed HP-UX server and detected the following ports (excluding ports required for applications) are opened:&lt;BR /&gt;&lt;BR /&gt;Port       State       Service&lt;BR /&gt;7/udp      open      echo                    &lt;BR /&gt;9/udp      open      discard                 &lt;BR /&gt;13/udp     open      daytime                 &lt;BR /&gt;19/udp     open      chargen                 &lt;BR /&gt;67/udp     open      bootps                  &lt;BR /&gt;68/udp     open      bootpc                  &lt;BR /&gt;69/udp     open      tftp                    &lt;BR /&gt;111/udp    open      sunrpc                  &lt;BR /&gt;135/udp    open      loc-srv                 &lt;BR /&gt;161/udp    open      snmp                    &lt;BR /&gt;177/udp    open      xdmcp                   &lt;BR /&gt;514/udp    open      syslog                  &lt;BR /&gt;518/udp    open      ntalk                   &lt;BR /&gt;948/udp    open      unknown                 &lt;BR /&gt;958/udp    open      unknown                 &lt;BR /&gt;1023/udp   open      unknown                 &lt;BR /&gt;1067/udp   open      instl_boots             &lt;BR /&gt;1068/udp   open      instl_bootc             &lt;BR /&gt;1434/udp   open      ms-sql-m                &lt;BR /&gt;2049/udp   open      nfs                     &lt;BR /&gt;2121/udp   open      unknown                 &lt;BR /&gt;2148/udp   open      unknown                 &lt;BR /&gt;3068/udp   open      unknown                 &lt;BR /&gt;3069/udp   open      unknown                 &lt;BR /&gt;4045/udp   open      lockd                   &lt;BR /&gt;5300/udp   open      hacl-hb                 &lt;BR /&gt;5301/udp   open      hacl-gs                 &lt;BR /&gt;49158/udp  open      unknown                 &lt;BR /&gt;49159/udp  open      unknown                 &lt;BR /&gt;49160/udp  open      unknown                 &lt;BR /&gt;49161/udp  open      unknown                 &lt;BR /&gt;49162/udp  open      unknown                 &lt;BR /&gt;49164/udp  open      unknown                 &lt;BR /&gt;49165/udp  open      unknown                 &lt;BR /&gt;49177/udp  open      unknown                 &lt;BR /&gt;49194/udp  open      unknown                 &lt;BR /&gt;49197/udp  open      unknown                 &lt;BR /&gt;49209/udp  open      unknown                 &lt;BR /&gt;49340/udp  open      unknown                 &lt;BR /&gt;49343/udp  open       unknown       &lt;BR /&gt; &lt;BR /&gt;Port       State       Service&lt;BR /&gt;7/tcp      open      echo                    &lt;BR /&gt;9/tcp      open      discard                 &lt;BR /&gt;13/tcp     open      daytime                 &lt;BR /&gt;19/tcp     open      chargen                 &lt;BR /&gt;21/tcp     open      ftp                     &lt;BR /&gt;23/tcp     open      telnet                  &lt;BR /&gt;25/tcp     open      smtp                    &lt;BR /&gt;37/tcp     open      time                    &lt;BR /&gt;80/tcp     open      http                    &lt;BR /&gt;111/tcp    open      sunrpc                  &lt;BR /&gt;113/tcp    open      auth                    &lt;BR /&gt;135/tcp    open      loc-srv                 &lt;BR /&gt;382/tcp    open      hp-managed-node         &lt;BR /&gt;512/tcp    open      exec                    &lt;BR /&gt;513/tcp    open      login                   &lt;BR /&gt;514/tcp    open      shell                   &lt;BR /&gt;515/tcp    open      printer                 &lt;BR /&gt;543/tcp    open      klogin                  &lt;BR /&gt;544/tcp    open      kshell                  &lt;BR /&gt;644/tcp    open      unknown                 &lt;BR /&gt;901/tcp    open      samba-swat              &lt;BR /&gt;1508/tcp   open      diagmond                &lt;BR /&gt;1712/tcp   open      unknown                 &lt;BR /&gt;2049/tcp   filtered  nfs                     &lt;BR /&gt;2121/tcp   open      unknown                 &lt;BR /&gt;2148/tcp   open      unknown                 &lt;BR /&gt;4045/tcp   open      lockd                   &lt;BR /&gt;4987/tcp   open      unknown                 &lt;BR /&gt;5300/tcp   open      hacl-hb                 &lt;BR /&gt;5301/tcp   open      hacl-gs                 &lt;BR /&gt;5302/tcp   open      hacl-cfg                &lt;BR /&gt;5303/tcp   open      hacl-probe              &lt;BR /&gt;5989/tcp   open      unknown                 &lt;BR /&gt;6112/tcp   open      dtspc                   &lt;BR /&gt;7161/tcp   open      unknown                 &lt;BR /&gt;7815/tcp   open      unknown                 &lt;BR /&gt;9610/tcp   open      unknown                 &lt;BR /&gt;49152/tcp  open      unknown                 &lt;BR /&gt;49153/tcp  open      unknown                 &lt;BR /&gt;49154/tcp  open      unknown                 &lt;BR /&gt;49155/tcp  open      unknown                 &lt;BR /&gt;49156/tcp  open      unknown                 &lt;BR /&gt;49157/tcp  open      unknown                 &lt;BR /&gt;49172/tcp  open      unknown                 &lt;BR /&gt;49192/tcp  open      unknown                 &lt;BR /&gt;49208/tcp  open      unknown                 &lt;BR /&gt;49243/tcp  open      unknown                 &lt;BR /&gt;49392/tcp  open      unknown                 &lt;BR /&gt;49396/tcp  open      unknown                 &lt;BR /&gt;49397/tcp  open      unknown                 &lt;BR /&gt;49450/tcp  open      unknown                 &lt;BR /&gt;49510/tcp  open      unknown                 &lt;BR /&gt;49511/tcp  open      unknown                 &lt;BR /&gt;51298/tcp  open      unknown                 &lt;BR /&gt;51300/tcp  open      unknown                 &lt;BR /&gt; &lt;BR /&gt;&lt;BR /&gt;How does one know whether the ports opened are required by OS especially those unknown ports?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Tue, 02 Nov 2004 21:37:19 GMT</pubDate>
    <dc:creator>yc_2</dc:creator>
    <dc:date>2004-11-02T21:37:19Z</dc:date>
    <item>
      <title>inetd services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/inetd-services/m-p/3411424#M747756</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Need advice the following:&lt;BR /&gt;&lt;BR /&gt;What application uses echo, time, sunrpc etc in HP-UX?&lt;BR /&gt;&lt;BR /&gt;What is the difference between echo, time, exec etc services in inetd and command echo, time, exec ?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks in advance,&lt;BR /&gt;YC</description>
      <pubDate>Sun, 31 Oct 2004 19:56:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/inetd-services/m-p/3411424#M747756</guid>
      <dc:creator>yc_2</dc:creator>
      <dc:date>2004-10-31T19:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: inetd services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/inetd-services/m-p/3411425#M747757</link>
      <description>The 'inetd' man page should answer most of your questions.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=697436" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=697436&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;'exec' means running exectuable commands from a remote system as root.&lt;BR /&gt;e.g.&lt;BR /&gt;rexec server ls&lt;BR /&gt;Password (server:root):&lt;BR /&gt;If the password is correct, the answer will be ls from the / directory of the remote system. This is of course if the 'exec' is not commented out.</description>
      <pubDate>Sun, 31 Oct 2004 20:47:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/inetd-services/m-p/3411425#M747757</guid>
      <dc:creator>Michael Tully</dc:creator>
      <dc:date>2004-10-31T20:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: inetd services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/inetd-services/m-p/3411426#M747758</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;1. There are hardly any applications that use echo, time etc.,. &lt;BR /&gt;&lt;BR /&gt;2. The difference is that one set is commands and the other set is services. Services are associated with daemons. Inetd brokers the ports for these daemons. Whenever there is a connection attempted to the ports, inetd will invoke the service by spawing the corresponding daemon. For ex., 'telnet' is a service and 'telnetd' is the daemon. Inetd listens at port 23 for the service telnet. When a client  connect to port 23 (like using a normal telnet command), inetd will spawn a telnetd session. &lt;BR /&gt;&lt;BR /&gt;-Sri&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sun, 31 Oct 2004 20:58:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/inetd-services/m-p/3411426#M747758</guid>
      <dc:creator>Sridhar Bhaskarla</dc:creator>
      <dc:date>2004-10-31T20:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: inetd services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/inetd-services/m-p/3411427#M747759</link>
      <description>Taken from HP-UX Bastille questions at:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://cvs.sourceforge.net/viewcvs.py/bastille-linux/dev/working_tree/Bastille/Questions/SecureInetd.txt?rev=1.1&amp;amp;only_with_tag=HEAD&amp;amp;view=markup" target="_blank"&gt;http://cvs.sourceforge.net/viewcvs.py/bastille-linux/dev/working_tree/Bastille/Questions/SecureInetd.txt?rev=1.1&amp;amp;only_with_tag=HEAD&amp;amp;view=markup&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;"The inetd's built-in services include chargen, daytime, discard,&lt;BR /&gt;and echo.  These services are rarely used and when they are it is generally&lt;BR /&gt;for testing.  The UDP versions of these services can be used in a Denial of&lt;BR /&gt;Service attack and therefore we recommend disabling these services.  A brief&lt;BR /&gt;definition of each service is as follows:&lt;BR /&gt;&lt;BR /&gt;daytime: Sends the current date and time as a human readable character string&lt;BR /&gt;(RFC 867)&lt;BR /&gt;&lt;BR /&gt;discard:  Throws away anything that is sent to it, similar to&lt;BR /&gt;/dev/null.(RFC 863)&lt;BR /&gt;&lt;BR /&gt;chargen:  Character Generator sends you a stream of some&lt;BR /&gt;undefined data, preferably data in some recognizable pattern (RFC 862)&lt;BR /&gt;&lt;BR /&gt;echo:  Simply returns the packets sent to it. (RFC 862)"&lt;BR /&gt;&lt;BR /&gt;sunrpc can mean several different things; here's info on the tool-talk database server which is sunrpc based:&lt;BR /&gt;&lt;BR /&gt;"The dtspcd, ttdbserver, and cmsd services are used by CDE.  Each service&lt;BR /&gt;has relative merits but they are all rarely used and for the most part deprecated.&lt;BR /&gt;Definitions for each service are as follows:&lt;BR /&gt;&lt;BR /&gt;dtspcd: &lt;BR /&gt;Desktop Subprocess Control service is used to invoke a processes on other&lt;BR /&gt;systems.  It uses an IP based authentication that is relatively easy to beat.&lt;BR /&gt;&lt;BR /&gt;cmsd: &lt;BR /&gt;This is used to run Sun's Calendar Manager software database over the network.&lt;BR /&gt;If you don't use Sun's Calendar Manager software you will not be affected by&lt;BR /&gt;disabling this service. Sun's Calendar Manager will not work properly with&lt;BR /&gt;cmsd disabled.&lt;BR /&gt;&lt;BR /&gt;ttdbserver: &lt;BR /&gt;Sun's ToolTalk Database Server allows OpenWindows programs to intercommunicate. &lt;BR /&gt;Disabling this service may affect some of the advanced mail features of dtmail. &lt;BR /&gt;For instance, you will be unable to use the network aware mail locking feature&lt;BR /&gt;of dtmail.  Some third party applications may use this service as well."&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Hope that helps.&lt;BR /&gt;&lt;BR /&gt;-Keith</description>
      <pubDate>Tue, 02 Nov 2004 16:33:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/inetd-services/m-p/3411427#M747759</guid>
      <dc:creator>Keith Buck</dc:creator>
      <dc:date>2004-11-02T16:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: inetd services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/inetd-services/m-p/3411428#M747760</link>
      <description>Out of curiousity, if ports that are vulnerable, why HP did not closed or disable them?&lt;BR /&gt;&lt;BR /&gt;My IT security personnel has done a scan to a newly installed HP-UX server and detected the following ports (excluding ports required for applications) are opened:&lt;BR /&gt;&lt;BR /&gt;Port       State       Service&lt;BR /&gt;7/udp      open      echo                    &lt;BR /&gt;9/udp      open      discard                 &lt;BR /&gt;13/udp     open      daytime                 &lt;BR /&gt;19/udp     open      chargen                 &lt;BR /&gt;67/udp     open      bootps                  &lt;BR /&gt;68/udp     open      bootpc                  &lt;BR /&gt;69/udp     open      tftp                    &lt;BR /&gt;111/udp    open      sunrpc                  &lt;BR /&gt;135/udp    open      loc-srv                 &lt;BR /&gt;161/udp    open      snmp                    &lt;BR /&gt;177/udp    open      xdmcp                   &lt;BR /&gt;514/udp    open      syslog                  &lt;BR /&gt;518/udp    open      ntalk                   &lt;BR /&gt;948/udp    open      unknown                 &lt;BR /&gt;958/udp    open      unknown                 &lt;BR /&gt;1023/udp   open      unknown                 &lt;BR /&gt;1067/udp   open      instl_boots             &lt;BR /&gt;1068/udp   open      instl_bootc             &lt;BR /&gt;1434/udp   open      ms-sql-m                &lt;BR /&gt;2049/udp   open      nfs                     &lt;BR /&gt;2121/udp   open      unknown                 &lt;BR /&gt;2148/udp   open      unknown                 &lt;BR /&gt;3068/udp   open      unknown                 &lt;BR /&gt;3069/udp   open      unknown                 &lt;BR /&gt;4045/udp   open      lockd                   &lt;BR /&gt;5300/udp   open      hacl-hb                 &lt;BR /&gt;5301/udp   open      hacl-gs                 &lt;BR /&gt;49158/udp  open      unknown                 &lt;BR /&gt;49159/udp  open      unknown                 &lt;BR /&gt;49160/udp  open      unknown                 &lt;BR /&gt;49161/udp  open      unknown                 &lt;BR /&gt;49162/udp  open      unknown                 &lt;BR /&gt;49164/udp  open      unknown                 &lt;BR /&gt;49165/udp  open      unknown                 &lt;BR /&gt;49177/udp  open      unknown                 &lt;BR /&gt;49194/udp  open      unknown                 &lt;BR /&gt;49197/udp  open      unknown                 &lt;BR /&gt;49209/udp  open      unknown                 &lt;BR /&gt;49340/udp  open      unknown                 &lt;BR /&gt;49343/udp  open       unknown       &lt;BR /&gt; &lt;BR /&gt;Port       State       Service&lt;BR /&gt;7/tcp      open      echo                    &lt;BR /&gt;9/tcp      open      discard                 &lt;BR /&gt;13/tcp     open      daytime                 &lt;BR /&gt;19/tcp     open      chargen                 &lt;BR /&gt;21/tcp     open      ftp                     &lt;BR /&gt;23/tcp     open      telnet                  &lt;BR /&gt;25/tcp     open      smtp                    &lt;BR /&gt;37/tcp     open      time                    &lt;BR /&gt;80/tcp     open      http                    &lt;BR /&gt;111/tcp    open      sunrpc                  &lt;BR /&gt;113/tcp    open      auth                    &lt;BR /&gt;135/tcp    open      loc-srv                 &lt;BR /&gt;382/tcp    open      hp-managed-node         &lt;BR /&gt;512/tcp    open      exec                    &lt;BR /&gt;513/tcp    open      login                   &lt;BR /&gt;514/tcp    open      shell                   &lt;BR /&gt;515/tcp    open      printer                 &lt;BR /&gt;543/tcp    open      klogin                  &lt;BR /&gt;544/tcp    open      kshell                  &lt;BR /&gt;644/tcp    open      unknown                 &lt;BR /&gt;901/tcp    open      samba-swat              &lt;BR /&gt;1508/tcp   open      diagmond                &lt;BR /&gt;1712/tcp   open      unknown                 &lt;BR /&gt;2049/tcp   filtered  nfs                     &lt;BR /&gt;2121/tcp   open      unknown                 &lt;BR /&gt;2148/tcp   open      unknown                 &lt;BR /&gt;4045/tcp   open      lockd                   &lt;BR /&gt;4987/tcp   open      unknown                 &lt;BR /&gt;5300/tcp   open      hacl-hb                 &lt;BR /&gt;5301/tcp   open      hacl-gs                 &lt;BR /&gt;5302/tcp   open      hacl-cfg                &lt;BR /&gt;5303/tcp   open      hacl-probe              &lt;BR /&gt;5989/tcp   open      unknown                 &lt;BR /&gt;6112/tcp   open      dtspc                   &lt;BR /&gt;7161/tcp   open      unknown                 &lt;BR /&gt;7815/tcp   open      unknown                 &lt;BR /&gt;9610/tcp   open      unknown                 &lt;BR /&gt;49152/tcp  open      unknown                 &lt;BR /&gt;49153/tcp  open      unknown                 &lt;BR /&gt;49154/tcp  open      unknown                 &lt;BR /&gt;49155/tcp  open      unknown                 &lt;BR /&gt;49156/tcp  open      unknown                 &lt;BR /&gt;49157/tcp  open      unknown                 &lt;BR /&gt;49172/tcp  open      unknown                 &lt;BR /&gt;49192/tcp  open      unknown                 &lt;BR /&gt;49208/tcp  open      unknown                 &lt;BR /&gt;49243/tcp  open      unknown                 &lt;BR /&gt;49392/tcp  open      unknown                 &lt;BR /&gt;49396/tcp  open      unknown                 &lt;BR /&gt;49397/tcp  open      unknown                 &lt;BR /&gt;49450/tcp  open      unknown                 &lt;BR /&gt;49510/tcp  open      unknown                 &lt;BR /&gt;49511/tcp  open      unknown                 &lt;BR /&gt;51298/tcp  open      unknown                 &lt;BR /&gt;51300/tcp  open      unknown                 &lt;BR /&gt; &lt;BR /&gt;&lt;BR /&gt;How does one know whether the ports opened are required by OS especially those unknown ports?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 02 Nov 2004 21:37:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/inetd-services/m-p/3411428#M747760</guid>
      <dc:creator>yc_2</dc:creator>
      <dc:date>2004-11-02T21:37:19Z</dc:date>
    </item>
  </channel>
</rss>

