The following table lists the more common system services within AIX®. Use this table to recognize a starting point for securing your system.
Before you secure your system, back up all your original configuration files, especially the following:
Service |
Daemon |
Started by |
Function |
Comments |
inetd/bootps |
inetd |
/etc/inetd.conf |
bootp services to diskless clients |
|
inetd/chargen |
inetd |
/etc/inetd.conf |
character generator (testing only) |
|
inetd/cmsd |
inetd |
/etc/inetd.conf |
calendar service (as used by CDE) |
|
inetd/comsat |
inetd |
/etc/inetd.conf |
Notifies incoming electronic mail |
|
inetd/daytime |
inetd |
/etc/inetd.conf |
obsolete time service (testing only) |
|
inetd/discard |
inetd |
/etc/inetd.conf |
/dev/null service (testing only) |
|
inetd/dtspc |
inetd |
/etc/inetd.conf |
CDE Subprocess Control |
|
inetd/echo |
inetd |
etc/inetd.conf |
echo service (testing only) |
|
inetd/exec |
inetd |
/etc/inetd.conf |
remote execution service |
|
inetd/finger |
inetd |
/etc/inetd.conf |
finger peeking at users |
|
inetd/ftp |
inetd |
/etc/inetd.conf |
file transfer protocol |
|
inetd/imap2 |
inetd |
/etc/inetd.conf |
Internet Mail Access Protocol |
|
inetd/klogin |
inetd |
/etc/inetd.conf |
Kerberos login |
|
inetd/kshell |
inetd |
/etc/inetd.conf |
Kerberos shell |
|
inetd/login |
inetd |
/etc/inetd.conf |
rlogin service |
|
inetd/netstat |
inetd |
/etc/inetd.conf |
reporting of current network status |
|
inetd/ntalk |
inetd |
/etc/inetd.conf |
Allows users to talk with each other |
|
inetd/pcnfsd |
inetd |
/etc/inetd.conf |
PC NFS file services |
|
inetd/pop3 |
inetd |
/etc/linetd.conf |
Post Office Protocol |
|
inetd/rexd |
inetd |
/etc/inetd.conf |
remote execution |
|
inetd/quotad |
inetd |
/etc/inetd.conf |
reports of file quotas (for NFS clients) |
|
inetd/rstatd |
inetd |
/etc/inetd.conf |
Kernel Statistics Server |
|
inetd/rusersd |
inetd |
/etc/inetd.conf |
info about user logged in |
|
inetd/rwalld |
inetd |
/etc/inetd.conf |
write to all users |
|
inetd/shell |
inetd |
/etc/inetd.conf |
rsh service |
|
inetd/sprayd |
inetd |
/etc/inetd.conf |
RPC spray tests |
|
inetd/systat |
inetd |
/etc/inted.conf |
"ps -ef" status report |
|
inetd/talk |
inetd |
/etc/inetd.conf |
establish split screen between 2 users on the net |
|
inetd/ntalk |
inetd |
/etc/inetd.conf |
"new talk" establish split screen between 2 users on the net |
|
inetd/telnet |
inetd |
/etc/inetd.conf |
telnet service |
|
inetd/tftp |
inetd |
/etc/inetd.conf |
trivial file transfer |
|
inetd/time |
inetd |
/etc/inetd.conf |
obsolete time service |
|
inetd/ttdbserver |
inetd |
/etc/inetd.conf |
tool-talk database server (for CDE) |
|
inetd/uucp |
inetd |
/etc/inetd.conf |
UUCP network |
|
inittab/dt |
init |
/etc/rc.dt script in the /etc/inittab |
desktop login to CDE environment |
|
inittab/dt_nogb |
init |
/etc/inittab |
desktop login to CDE environment (NO graphic boot) |
|
inittab/httpdlite |
init |
/etc/inittab |
web server for the docsearch command |
|
inittab/i4ls |
init |
/etc/inittab |
license manager servers |
|
inittab/imqss |
init |
/etc/inittab |
search engine for "docsearch" |
|
inittab/lpd |
init |
/etc/inittab |
BSD line printer interface |
|
inittab/nfs |
init |
/etc/inittab |
Network File System/Net Information Services |
|
inittab/piobe |
init |
/etc/inittab |
printer IO Back End (for printing) |
|
inittab/qdaemon |
init |
/etc/inittab |
queue daemon (for printing |
|
inittab/uprintfd |
init |
/etc/inittab |
kernel messages |
|
inittab/writesrv |
init |
/etc/inittab |
writing notes to ttys |
|
inittab/xdm |
init |
/etc/inittab |
traditional X11 Display Management |
|
rc.nfs/automountd |
|
/etc/rc.nfs |
automatic file systems |
|
rc.nfs/biod |
|
/etc/rc.nfs |
Block IO Daemon (required for NFS server) |
|
rc.nfs/keyserv |
|
/etc/rc.nfs |
Secure RPC Key server |
|
rc.nfs/nfsd |
|
/etc/rc.nfs |
NFS Services (required for NFS Server) |
|
rc.nfs/rpc.lockd |
|
/etc/rc.nfs |
NFS file locks |
|
rc.nfs/rpc.mountd |
|
/etc/rc.nfs |
NFS file mounts (required for NFS Server) |
|
rc.nfs/rpc.statd |
|
/etc/rc.nfs |
NFS file locks (to recover them) |
|
rc.nfs/rpc.yppasswdd |
|
/etc/rc.nfs |
NIS password daemon (for NIS master) |
|
rc.nfs/ypupdated |
|
/etc/rc.nfs |
NIS Update daemon (for NIS slave) |
|
rc.tcpip/autoconf6 |
|
/etc/rc.tcpip |
IPv6 interfaces |
|
rc.tcpip/dhcpcd |
|
/etc/rc.tcpip |
Dynamic Host Configure Protocol (client ) |
|
rc.tcpip/dhcprd |
|
/etc/rc.tcpip |
Dynamic Host Configure Protocol (relay |
|
rc.tcpip/dhcpsd |
|
/etc/rc.tcpip |
Dynamic Host Configure Protocol (server |
|
rc.tcpip/dpid2 |
|
/etc/rc.tcpip |
outdated SNMP service |
|
rc.tcpip/gated |
|
/etc.rc.tcpip |
gated routing between interfaces |
|
rc.tcpip/inetd |
|
/etc/rc.tcpip |
inetd services |
|
rc.tcpip/mrouted |
|
/etc/rc.tcpip |
multi-cast routing |
|
rc.tcpip/names |
|
/etc/rc.tcpip |
DNS name server |
|
rc.tcpip/ndp-host |
|
/etc/rc.tcpip |
IPv6 host |
|
rc.tcpip/ndp-router |
|
/etc/rc.tcpip |
IPv6 routing |
|
rc.tcpip/portmap |
|
/etc/rc.tcpip |
RPC services |
|
rc.tcpip/routed |
|
/etc/rc.tcpip |
RIP routing between interfaces |
|
rc.tcpip/rwhod |
|
/etc/rc.tcpip |
Remote "who" daemon |
|
rc.tcpip/sendmail |
|
/etc/rc.tcpip |
mail services |
|
rc.tcpip/snmpd |
|
/etc/rc.tcpip |
Simple Network Management Protocol |
|
rc.tcpip/syslogd |
|
/etc/rc.tcpip |
system log of events |
|
rc.tcpip/timed |
|
/etc/rc.tcpip |
Old Time Daemon |
|
rc.tcpip/xntpd |
|
/etc/rc.tcpip |
New Time Daemon |
|
dt login |
|
/usr/dt/config/Xaccess |
unrestricted CDE |
|
anonymous FTP service |
|
user rmuser -p |
anonymous ftp |
|
anonymous FTP writes |
|
|
anonymous ftp uploads |
|
ftp.restrict |
|
|
ftp to system accounts |
|
root.access |
|
/etc/security/user |
rlogin/telnet to root account |
|
snmpd.readWrite |
|
/etc/snmpd.conf |
SNMP readWrite communities |
|
syslog.conf |
|
|
configure syslogd |
|
Parent topic:
Security