Sponsored Content
Operating Systems HP-UX Found service running during audit Post 302162309 by dan.king on Monday 28th of January 2008 04:50:53 PM
Old 01-28-2008
Found service running during audit

Hello all!

During a network audit, I came across a host running a service on a high port (34604). Not recognizing the port, I used a tool called 'amap' (THC-AMAP - fast and reliable application fingerprint mapper) to fingerprint it.

This tool also did not fingerprint it correctly, but did manage to get a response from the service.

Here is the output:
0000: 0000 0001 412e 3031 2e31 3500 6674 7000 [ ....A.01.15.ftp. ]
0010: 6365 6420 4469 736b 2041 7272 6179 2073 [ ced Disk Array s ]
0020: 6572 6961 6c20 6e75 6d62 6572 203f 3a20 [ erial number ?: ]
0030: 4561 723a 3a4c 6973 7465 6e28 2930 3030 [ Ear::Listen()000 ]
0040: 3030 3132 3042 3846 3600 0000 000d 0000 [ 00120B8F6....... ]
0050: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
0060: 00bc 0004 1000 0000 0000 0000 0000 0000 [ ................ ]
0070: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
0080: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
0090: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
00a0: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
00b0: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
00c0: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
00d0: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
00e0: 0000 0000 0000 0000 0000 0000 0000 4003 [ ..............@. ]
00f0: 7980 0000 0000 0000 00b1 0003 0000 0000 [ y............... ]
0100: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
0110: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
0120: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
0130: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
0140: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
0150: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
0160: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
0170: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
0180: 0003 2f76 6172 2f6f 7074 2f68 7061 7272 [ ../var/opt/hparr ]
0190: 6179 2f61 646d 696e 2f30 3030 3030 3132 [ ay/admin/0000012 ]
01a0: 3042 3846 362e 0000 0000 0000 0000 0000 [ 0B8F6........... ]
01b0: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
01c0: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
01d0: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
01e0: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
01f0: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
0200: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
0210: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
0220: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
0230: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
0240: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
0250: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
0260: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
0270: 0000 0000 0000 0000 0000 0000 0000 0000 [ ................ ]
0280: 0000 0000 0000 00 [ ....... ]

I started googling around for the string "/var/opt/hparray" and I found a lot of resourced for AutoRAID controllers.

Unfortunately, i could not find any information about a remote client that could be used to connect this service. (ie. nothing with port numbers etc)

Does anyone know of such a piece of software, or am I on the complete wrong track here?

Much thanks!

-dan
 

10 More Discussions You Might Find Interesting

1. Solaris

How to be sure the dns service is running ?

Well, i changed my lan card and finally i got it up and running, i have /etc/resolv.conf with domain xxx.xxx nameserver xxx.xxx.xxx.xxx and it was working with me earlier with the old lan card, with the new one i added it ip using auto-dhcp and its received an ip from my dhcp and it can ping... (4 Replies)
Discussion started by: XP_2600
4 Replies

2. UNIX for Dummies Questions & Answers

check service is running at boot

dears am having solaris 10, and i would like to know if the NTP service is running when the OS staritng?on the other hand how can i make it start at the boot up?note the ntp is managed by the SMF in solaris 10. thanks a lot (2 Replies)
Discussion started by: thehero
2 Replies

3. Red Hat

Cannot start httpd service `GLIBC_2.4' not found (required by /lib/libgcc_s.so.1)

# service httpd start Starting httpd: Syntax error on line 6 of /etc/httpd/conf.d/php.conf: Cannot load /etc/httpd/modules/libphp4.so into server: /lib/tls/libc.so.6: version `GLIBC_2.4' not found (required by /lib/libgcc_s.so.1) I... (2 Replies)
Discussion started by: getrue
2 Replies

4. Red Hat

HP Service Guard SGLX for linux getting error as LICENSE FILE NOT FOUND

HI All, I am using RHEL 5.0 32 Bit, i was trying to install HP Service Guard Cluster in my machine where i installed RHEL5. The problem is that when i am running cmquery -n selva -C mycluster.ascii. Its output is that LICENSE FILE NOT FOUND, so exiting. So i have tried so many things. Pls... (1 Reply)
Discussion started by: skumar7466
1 Replies

5. AIX

When AIX audit start, How to set the /audit/stream.out file size ?

Dear All When I start the AIX(6100-06)audit subsystem. the log will save in /audit/stream.out (or /audit/trail), but in default when /audit/stream.out to grow up to 150MB. It will replace the original /audit/stream.out (or /audit/trail). Then the /audit/stream.out become empty and... (2 Replies)
Discussion started by: nnnnnnine
2 Replies

6. Red Hat

TSM service not found

Hello, I have some trouble checking the TSM ( Tivoli storage Mgr )service status in Linux box when i am doing service tsm status -bash: service command not found Above command is working fine in all other linux box ( Any idea how to look into this to resolve this, i am clueless from... (2 Replies)
Discussion started by: saurabh84g
2 Replies

7. Solaris

Configuring 'auditd' service to not store the audit logs in /var partition

Hello all, I've configured 'audit' service to send the audit logs to a remote log server (by using syslog plugin), which is working fine. However, there is a problem. audit service also tries to write same information (but in binary format) in /var/audit path. So, Is there anyway to stop... (2 Replies)
Discussion started by: Anti_Evil
2 Replies

8. Red Hat

How a service is always running ?

Hi How ssh service at all levels always running in her file /etc/inittab? vi /etc/inittab 10::respawn:/etc/init.d/sshd I added this line & save run init q But it did not (6 Replies)
Discussion started by: mnnn
6 Replies

9. Solaris

Checking if service is running

Hi, For audit reasons, I need to stop the web server service in some Solaris servers. The port that is listening for this service is port 10000. This is the output that shows the port 10000 is open in the server : # netstat -an | grep 10000 10.70.21.144.10000 10.70.21.133.58130 49640... (6 Replies)
Discussion started by: anaigini45
6 Replies

10. Shell Programming and Scripting

Checking to see if windows service is running

Hi I have created a PowerShell script which successfully checks whether windows service pgsql-9.2 is running. I have tried to call that PowerShell script with a shell/bash script within a LINUX machine but have been unsuccessful. Is there a way of a shell/Perl script to check whether a... (5 Replies)
Discussion started by: simpsa27
5 Replies
audit(1M)                                                                                                                                audit(1M)

NAME
audit - control the behavior of the audit daemon SYNOPSIS
audit -n | -s | -t | -v [path] The audit command is the system administrator's interface to maintaining the audit trail. The audit daemon can be notified to read the con- tents of the audit_control(4) file and re-initialize the current audit directory to the first directory listed in the audit_control file or to open a new audit file in the current audit directory specified in the audit_control file, as last read by the audit daemon. Reading audit_control also causes the minfree and plugin configuration lines to be re-read and reset within auditd. The audit daemon can also be signaled to close the audit trail and disable auditing. -n Notify the audit daemon to close the current audit file and open a new audit file in the current audit directory. -s Notify the audit daemon to read the audit control file. The audit daemon stores the information internally. If the audit daemon is not running but audit has been enabled by means of bsmconv(1M), the audit daemon is started. -t Direct the audit daemon to close the current audit trail file, disable auditing, and die. Use -s to restart auditing. -v path Verify the syntax for the audit control file stored in path. The audit command displays an approval message or outputs specific error messages for each error found. The audit command will exit with 0 upon success and a positive integer upon failure. /etc/security/audit_user /etc/security/audit_control See attributes(5) for descriptions of the following attributes: +-----------------------------+-----------------------------+ | ATTRIBUTE TYPE | ATTRIBUTE VALUE | +-----------------------------+-----------------------------+ |Availability |SUNWcsu | +-----------------------------+-----------------------------+ |Stability |Evolving | +-----------------------------+-----------------------------+ bsmconv(1M), praudit(1M), audit(2), audit_control(4), audit_user(4), attributes(5) The functionality described in this man page is available only if the Basic Security Module (BSM) has been enabled. See bsmconv(1M) for more information. The audit command does not modify a process's preselection mask. It functions are limited to the following: o affects which audit directories are used for audit data storage; o specifies the minimum free space setting; o resets the parameters supplied by means of the plugin directive. For the -s option, audit validates the audit_control syntax and displays an error message if a syntax error is found. If a syntax error message is displayed, the audit daemon does not re-read audit_control. Because audit_control is processed at boot time, the -v option is provided to allow syntax checking of an edited copy of audit_control. Using -v, audit exits with 0 if the syntax is correct; otherwise, it returns a positive integer. The -v option can be used in any zone, but the -t, -s, and -n options are valid only in local zones and, then, only if the perzone audit policy is set. See auditd(1M) and auditconfig(1M) for per-zone audit configuration. 25 May 2004 audit(1M)
All times are GMT -4. The time now is 06:54 AM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy