Privileged SSH commands for probe-based discovery
Summarize
Summary of Privileged SSH commands for probe-based discovery
This document outlines the privileged SSH commands used by ServiceNow Discovery probes during horizontal discovery to gather system information. These commands require elevated privileges and are executed via SSH with a user account (commonly namedDisco). Proper configuration of sudo permissions is essential to enable these commands without requiring password prompts, especially since private key authentication does not support sudo password entry.
Show less
It is critical for ServiceNow customers to configure the sudoers file appropriately, using the NOPASSWD option for specific commands, ensuring smooth and secure probe execution.
Key Points for Implementation
- Sudo configuration: Add NOPASSWD entries in the sudoers file for each privileged command needed by the Discovery probes, e.g.,
disco ALL=(root) NOPASSWD:/usr/sbin/dmidecode. - SSH key authentication: Use SSH keys or certificates for authentication and avoid sending passwords over the connection.
- Host key validation: MID Servers do not validate SSH host keys, so limit sensitive data exchanged over SSH to reduce risk from potential man-in-the-middle attacks.
- Disco user substitution: Replace the example username Disco with your actual user configured on the target systems.
Privileged Commands by Operating System
The commands required vary by OS, and each must be enabled with sudo permissions:
- HP-UX:
adbfor CPU speed and memory info. - Linux: Includes
dmidecode(hardware info),fdisk -l(disk info), andmultipath -ll(MPIO device mappings). - Linux and Solaris:
dmsetupto examine low-level volumes. - All UNIX versions: Commands such as
lsof,netstat,ssto identify process and connection relationships;oratabfor Oracle configurations. - Solaris specific: Commands like
iscsiadm(iSCSI info),fcinfo(WWPNs),prtvtoc(disk partitions),psandpgrepfor process info, andpfilesfor socket details. Note the requirement to manually install the/usr/ucb/pscommand on Solaris 11 systems.
Practical Recommendations for ServiceNow Customers
- Ensure all required privileged commands are listed with exact paths in your sudoers file and are allowed without password prompts.
- Test SSH key-based authentication for the Disco user to confirm privileged commands run successfully during Discovery.
- Be aware that commands requiring sudo will fail if the sudoers file is not configured with NOPASSWD for those commands.
- Review non-privileged commands separately to complete your Discovery configuration.
- Refer to Service Mapping documentation for commands specific to top-down discovery if applicable.
These tables display the SSH commands run by Discovery probes during horizontal discovery. These SSH commands require elevated privileges to run.
Operating system commands requiring elevated rights
disco ALL=(root)
NOPASSWD:/usr/sbin/dmidecode,/usr/sbin/lsof,/sbin/ifconfig.For information on commands that don’t require elevated rights, see Non-privileged SSH commands during probe-based discovery.
For information on commands used by Service Mapping during the top-down discovery, see Service Mapping commands requiring a privileged user and Service Mapping commands not requiring a privileged user.
SSH key not validated
When the MID Server connects to a system, the MID Server doesn’t perform host key validation against that system and so treats it as untrusted. If an attacker performs a man-in-the-middle attack and redirects the traffic to a malicious SSH service, the attacker can intercept or modify any data sent over the connection.
Therefore, limit any sensitive information exchanged between the MID Server and the target SSH server. Only use keys or certificates for SSH authentication, and avoid sending system credentials. Configure NOPASSWD in the sudoers file for the required privileged commands.
| Command | Purpose |
|---|---|
| adb | Gathers CPU speed and memory. /etc/sudoers line example: |
| Command | Purpose |
|---|---|
| dmidecode | Gathers several pieces of information about the hardware, including the serial number embedded within the motherboard. /etc/sudoers line example: |
| fdisk | Gathers the disks and size information on the system. /etc/sudoers line example: |
| multipath | Gathers device mappings for MultiPath Input Output (MPIO). /etc/sudoers line example: |
| Command | Purpose |
|---|---|
| dmsetup | Examines a low-level volume. /etc/sudoers line example
|
| Command | Purpose |
|---|---|
| lsof | Determines the relationship between processes and the connections being made to the system. /etc/sudoers line example: |
| oratab | Grants read access to the oratab file for locating the Oracle Home and pfile. |
| netstat | Determines the relationship between processes and the connections being made to the system. /etc/sudoers line example: |
| ss | Determines the relationship between processes and the connections being made to the system. /etc/sudoers line example: |
| Command | Purpose |
|---|---|
| iscsiadm | Gets iSCSI qualified names (IQNs). /etc/sudoers line example: |
| fcinfo | Gets World Wide Port Names (WWPNs) for ports. /etc/sudoers line example: |
| prtvtoc | Reports information about disk partitions. /etc/sudoers line example: |
| /usr/bin/ps | Lists running process. As an alternative to running with root access, add a proc_owner role.sola. /etc/sudoers line example: |
| /usr/ucb/ps | Lists running process. As an alternative to running with root access, add a proc_owner role. The use of the /etc/sudoers line example: |
| pgrep | Gets list of process IDs (PIDs) with socket information. /etc/sudoers line example: |
| pfiles | For each PID, gets and processes the output for S_IFSOCK. /etc/sudoers line example: |