- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: second telnetd?
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-29-2001 02:11 PM
11-29-2001 02:11 PM
second telnetd?
I tried in vain to stop my company from opening telnet to our HP 11.0 server from the internet for a single application.
After telneting in, the users login script starts the app, and logs out. I feel confident in the security of the log in scripts, but i only want the user accounts that start the application to be able to telnet from the internet.
Any ideas? I was looking at running a second telnet daemon on a different port, but how do you force an automatic logon (not letting them choose a username to log in as)?
I was looking at the telnetd on linux, and was curious about the -L option, providing a different program than "/bin/login" for authentication. Is this option available on HP-UX?
Thanks,
Ben
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-29-2001 02:18 PM
11-29-2001 02:18 PM
Re: second telnetd?
second telnetd on other port /etc/inetd.conf copy telnet line and alter the port reload (inetd -c) but think about the next option:
I think you should take a look at sshd, if you want your system available from the internet.
take a look at this url:
http://forums.itrc.hp.com/cm/QuestionAnswer/1,11866,0xd4cecf38d6bdd5118ff10090279cd0f9,00.html
Hope this will help.
Gideon
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-29-2001 02:26 PM
11-29-2001 02:26 PM
Re: second telnetd?
the real problem i have if trying to force the username and password that is used when connecting to the second "internet" telnetd. once that is done, i have pretty tight logins scripts to take care of the rest.
Thanks,
Ben
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-29-2001 02:34 PM
11-29-2001 02:34 PM
Re: second telnetd?
Ok. How are you planning to alter the tcp/port these applications are using to set up theire telnet connections?
telnet machine_name:32
A login procedure can be automated with a .rhosts file and remsh, but over the internet?!?!?
Is it possible to create a ssh tunnel and let those applications connect throug the tunnel?
Gideon
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-29-2001 02:40 PM
11-29-2001 02:40 PM
Re: second telnetd?
Instead of /bin/sh in the password file for the user they get /usr/local/script.sh
When they sign in they get the TUI and no shell, they may change their tune after that.
Good Luck,
Keep fighting the good fight,
C
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-29-2001 02:56 PM
11-29-2001 02:56 PM
Re: second telnetd?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-30-2001 07:25 AM
11-30-2001 07:25 AM
Re: second telnetd?
my plan was to run a second telnet daemon on a different port, say 1023, then when a telnet is made to the internet ip on port 23, the firewall would forward it to port 1023 on the internal ip.
then that telnet daemon would auto-login as a user that excutes the app in the .login, then the next line is "logout".
maybe i should forget telnet and write a perl script to listen on the port then run the app?
ideas appreciated,
ben