?
Solved

AIX 5.3 - Enabled services

Posted on 2009-07-08
2
Medium Priority
?
793 Views
Last Modified: 2013-11-17
I have used a script to determine the services running on a specific AIX server. So the script have two sections that I'm not sure about.

1)

br_1
INETCONF="/etc/inetd.conf"
echo "# Checking for $INETCONF has services running that should be disabled - FAILS CHECK"
echo `egrep  "^time|^daytime|^echo|^chargen|^telnet|^finger|^talk|^comsat|^shell|^login|^uucp|^tftp|^name|^printer|^shell|^login" $INETCONF`
enbr_1

This produces this results:

BEGINRECORD
416
# Checking for /etc/inetd.conf has services running that should be disabled - FAILS CHECK

ENDRECORD

So how should I interpret the result?

2)

br_1
echo "# Checking ChatList=name exec comsat talk uucp smtp tftp finger systat netstat rquotad rusersd sprayd walld rexd shell login exec comsat time echo discard daytime chargen 100087 rwalld rstatd 100068 100083 100221 fs ufsd 100232 100235 printer 536870916"
 for SERVC in $ChatList
  do
    grep "^${SERVC}" ${INET} >/dev/null 2>&-

    if [ $? -eq 0 ]; then
    echo "#  $SERVC Open - FAILS CHECK"
    else
    echo "# $SERVC Closed - PASSES CHECK"
    fi
 done
 enbr_1

And the result is:

BEGINRECORD
418
# Checking ChatList=name exec comsat talk uucp smtp tftp finger systat netstat rquotad rusersd sprayd walld rexd shell login exec comsat time echo discard daytime chargen 100087 rwalld rstatd 100068 100083 100221 fs ufsd 100232 100235 printer 536870916
# name Closed - PASSES CHECK
# exec Closed - PASSES CHECK
# comsat Closed - PASSES CHECK
# talk Closed - PASSES CHECK
...
ENDRECORD

So it seems that the result for this one differs from the result of the first script.

To sum up, can I say that the services are disabled or not?

Is there a better way to check for enabled services?

Thanks for the help!
0
Comment
Question by:ralmada
2 Comments
 
LVL 68

Accepted Solution

by:
woolmilkporc earned 1000 total points
ID: 24805231
Hi,
it looks a bit strange, but let's see -
The first script checks for several services (portnames) in inetd.conf.
portname must start in the first nonblank position of its line in inetd.conf, and that's what the script checks (^ means start of line). A nonblank character in front of a portname in inetd.conf would make the entry invalid (or commented out in case of '#'), thus the service would not be active.
The script gives no output - meaning none of the checked services was found active. The heading "... FAILS CHECK" is always displayed, regardless of the result - for what reasons ever.
The second script uses the opposite approach - if a service name is found in the correct position (grep "^${SERVC}" ${INET} results in RC 0) a "FAILS CHECK" message is displayed. No such message is diplayed, meaning "check OK", like in the first script.
To sum up - both scripts basically give the same result  (in a different format, the heading of the first one being misleading), that none of the checked services is active.
A better way? Yes, it's AIX!
Simply issue
lssrc -ls inetd
and you will see all your active services at a glance.
HTH
wmp
 
0
 
LVL 41

Author Closing Comment

by:ralmada
ID: 31601161
Thanks!!
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This tech tip describes how to install the Solaris Operating System from a tape backup that was created using the Solaris flash archive utility. I have used this procedure on the Solaris 8 and 9 OS, and it shoudl also work well on the Solaris 10 rel…
Introduction Regular patching is part of a system administrator's tasks. However, many patches require that the system be in single-user mode before they can be installed. A cluster patch in particular can take quite a while to apply if the machine…
Learn several ways to interact with files and get file information from the bash shell. ls lists the contents of a directory: Using the -a flag displays hidden files: Using the -l flag formats the output in a long list: The file command gives us mor…
Learn how to get help with Linux/Unix bash shell commands. Use help to read help documents for built in bash shell commands.: Use man to interface with the online reference manuals for shell commands.: Use man to search man pages for unknown command…
Suggested Courses
Course of the Month7 days, 10 hours left to enroll

607 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question