- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Removing services from inetd.conf
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-20-2003 01:00 PM
03-20-2003 01:00 PM
time stream tcp nowait root internal
dtspc stream tcp nowait root /usr/dt/bin/dtspcd /usr/dt/bin/dtspcd
rpc dgram udp wait root /usr/dt/bin/rpc.cmsd 100068 2-5 rpc.cmsd (Calendar?)
recserv stream tcp nowait root /usr/lbin/recserv recserv -display :0
registrar stream tcp nowait root /etc/opt/resmon/lbin/registrar /etc/opt/resmon/
lbin/registrar
It seems to be a given that I can safely remove these:
chargen
ntalk
bootps
daytime
echo
discard
ident
Less is more? (secure that is)
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-20-2003 01:08 PM
03-20-2003 01:08 PM
Re: Removing services from inetd.conf
Most shops need ftp and telnet, but you are better off with secure shell, which is not run out of inetd.conf
I'd stay away from anything that starts with an r because most of those are insecure berkley protocols which can be functionally replaced by secure shell.
Here is a link for the free secure shell software from HP, replacing telnet, ftp rcp.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-20-2003 01:08 PM
03-20-2003 01:08 PM
Re: Removing services from inetd.conf
Most shops need ftp and telnet, but you are better off with secure shell, which is not run out of inetd.conf
I'd stay away from anything that starts with an r because most of those are insecure berkley protocols which can be functionally replaced by secure shell.
Here is a link for the free secure shell software from HP, replacing telnet, ftp rcp.
http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=T1471AA
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-20-2003 01:09 PM
03-20-2003 01:09 PM
Re: Removing services from inetd.conf
dtspc is to do with CDE
Some 'rpc' are to do with NFS services
'resmon' is to with the EMS monitoring
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-20-2003 01:14 PM
03-20-2003 01:14 PM
SolutionYes. One good rule is to disable everything and enable only what you need. For the services you enabled, you may want to configured /var/adm/inetd.sec for further restrictions.
time - returns the time on the system. For ex.,
telnet localhost 37
dtspcd, rpc.cmsd are CDE services.
registrar is used by EMS. If you are monitoring the resources using EMS, then you want to leave it enabled.
-Sri
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-20-2003 01:16 PM
03-20-2003 01:16 PM
Re: Removing services from inetd.conf
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-20-2003 01:21 PM
03-20-2003 01:21 PM
Re: Removing services from inetd.conf
But a more favorable way is to put them protected by tcp-wrapper.
From there, you may specify who can or cannot access your individual services.
For sshd service, if you are lazy as me, I suggest not to use it since too frequent ssl and ssh patches and lots of attacked against ssh.
Hope this helps.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-20-2003 01:33 PM
03-20-2003 01:33 PM
Re: Removing services from inetd.conf
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-20-2003 02:09 PM
03-20-2003 02:09 PM
Re: Removing services from inetd.conf
20030319 Watch Vulnerability in Remote Procedure Call libraries
20030318 Watch Samba Buffer Overflow
20030317 Warning Windows 2000 - Microsoft IIS 5.0 (Only) Unchecked Buffer Overflow
20030305 Watch Snort Vulnerability
20030228 Watch Remote Root Vulnerability In Sendmail
20030126 Warning Microsoft SQL Slammer Worm
20021008 Warning W32/Bugbear@MM Worm
20020916 Warning Apache/mod_ssl Worm
20020719 Watch Web Server Reconnaissance
20020805-2 Watch SSL Vulnerability
20020805-1 Watch OpenSSH Trojan
20020716 Warning Multiple Systems Compromised
20020521 Warning New MS SQL Worm
20020221 Warning Vulnerability in CDE
20020219 Warning WU-FTPD name globbing vulnerability
20011204 Warning W32/Goner@MM Worm Activity
20011130 Warning Continued Threats Made Against U.S. Government Systems
20011120 Warning SSHD Vulnerability
20011025 Warning UPDATE: Threats Made Against U.S. Government Systems
20011019 Warning Threats Made Against U.S. Government Systems
20010918 Warning W32/Nimda@MM Worm
20010910 Warning W32/Magistr.b@MM Virus
20010831 Watch Vulnerability in Printer Service
20010807 Warning (Upgrade in Status) Vulnerability in Telnet Service
20010725 Watch Vulnerability in Telnet Service
20010723 Warning W32/SirCam@MM (SirCam) Malicious Code
20010719 Warning Code Red Worm Threat
20010213 Warning VBS/SST (Anna Kournikova) Malicious Code
20010130 Warning Multiple Vulnerabilities in BIND
20000817 Warning Attack Alert
20000810 Watch Vulnerabilities In Netscape Communicator
20000717 Watch Multiple NOAA Web Server Home Page Defacements
20000712 Watch Washington University FTP server (wu-ftpd) vulnerabilities
20000620 Watch Virus - IRC/Stages.worm
20000601 Watch Cybernet Macro Virus
20000518 Watch I Love You Virus
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-20-2003 02:34 PM
03-20-2003 02:34 PM
Re: Removing services from inetd.conf
I am not sure if it is going to affect Omniback. But sure not Bastille. I would suggest a conservative approach by disabling them one by one and then make sure you don't get any complaints from the users. cmsd is calender manager and users may be using it.
recserv is used by SharedX service. You may not need it either.
Regarding ssh, I prefer to use it against the standard tools. Vulnerabilities are common even on the vendor supported softwares. But we cannot take it as an excuse to send the data in cleartext. Particularly sending passwords in clear-text is always vulnerable. You can use HP's secure shell if you want support.
-Sri