How to find out which network service are NOT linked against libwrap.s / tcpd (TCPWrapper)

last updated in Categories Howto, Linux, Security

tcpd is use as a access control facility for internet services. It can be set up to monitor incoming requests for telnet, sshd, finger, ftp, exec, rsh, rlogin, tftp, talk, comsat and other services that have a one-to-one mapping onto executable files.

These days almost all leading Linux distros network services are linked against libwrap.a in order to take advantage of the tcpwrappers access control facility.

However some time few services (especially third party apps) does not link itself against libwrap.

You can easily find out if particler installed network service is NOT linked against libwrap.s / tcpd using strings command.

strings command print the strings of printable characters in files especially binary files thus strings is mainly useful for determining the contents of non-text / binary files.

For example find out if sshd network service can use tcpd or not:
$ strings $(which sshd)| grep libwrap
Output:

libwrap.so.0
libwrap refuse returns

Above output, clearly indicate that sshd is linked against libwrap.s / tcpd (TCPWrapper) service. See how to use tcpd to restrict ssh access.

Update:
Sean pointed out ldd command:
$ ldd /usr/sbin/sshd | grep -i libwrapOR# ldd $(which sshd) | grep -i libwrap
Output:

libwrap.so.0 => /lib/libwrap.so.0 (0x40020000)

Posted by: Vivek Gite

The author is the creator of nixCraft and a seasoned sysadmin, DevOps engineer, and a trainer for the Linux operating system/Unix shell scripting. Get the latest tutorials on SysAdmin, Linux/Unix and open source topics via RSS/XML feed or weekly email newsletter.

2 comment

    Have a question? Post it on our forum!