- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: Is the system really secure
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-27-2000 02:18 PM
11-27-2000 02:18 PM
Is the system really secure
We are running a trusted system. If I run netstat -n command, it will show only connection that are in ?Established? shown in ? state? column and socket (IP address.port#) is shown under the column ?Foreign Address?. If I run netstat command with options -an then I see under foreign address *.* and status is LISTEN. Are these the passive sockets and is not a security threat to the system?
Any explanation will be appreciated.
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-27-2000 02:53 PM
11-27-2000 02:53 PM
Re: Is the system really secure
The system may not necessarily be secure... when you run netstat -an you get a listing telling you what services are running (are listening) any service (look under Local Address) that has a LISTEN against it is a service running.
you can use the lsof tool to determine what process own what sockets.
ESTABLISHED only shows up when there is an actual connection to the port between the localhost and the remote host.
do a man on netstat for more details on what each of the statuses means.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-27-2000 05:36 PM
11-27-2000 05:36 PM
Re: Is the system really secure
Does the service has to be mentioned in /etc/services file and configured in /etc/inetd.conf file.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-27-2000 09:28 PM
11-27-2000 09:28 PM
Re: Is the system really secure
Yes, there is a program running that is listening on ports 49263 and 53341- it is not necessary for the port to be listed in /etc/services or listed in inetd.conf before it is used by a program.
The way to confirm what program is listening on the identified ports, download lsof from http://hpux.ee.ualberta.ca/hppd/hpux/Sysadmin/lsof-4.51/
you can use lsof to determine what files and ports are opened but what process.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-28-2000 04:03 AM
11-28-2000 04:03 AM
Re: Is the system really secure
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-28-2000 05:27 AM
11-28-2000 05:27 AM
Re: Is the system really secure
One last point to clear. if a port is open and state is LISTEN, will a connection only be established on that port for the service that is configured in /etc/inetd.conf file.
Or the said port can be used to access the system in some other way.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-28-2000 05:37 AM
11-28-2000 05:37 AM
Re: Is the system really secure
if you do a
telnet localhost port
(where port is the port number it is listening on) you should get a connection - the results might not mean anything to you if you do not know what program is running on that port... that is why if you use lsof to find out what is running on that port, you can better know what to expect.