Scanning Unix-based assets

Technology

Computers based on macOS, Linux, FreeBSD, and ESX/ESXi operating systems are scanned using agents. An agent is an executable that is uploaded to a remote computer via SSH and SCP/SFTP and gathers information about its hardware and software using operating system utilities.

The program supports scanning of 64-bit macOS systems.

The SSH protocol enables exchanging data between two hosts using a secure channel. There are currently two versions of this protocol: SSH-1 and SSH-2. TNI uses SSH-2 for scanning. Most modern UNIX systems support this protocol.

SCP and SFTP are used to transfer files securely between two hosts. Both are supported by many modern SSH servers. TNI supports both of these protocols.

Scanning of the ESX/ESXi systems can also be performed via the HTTP protocol (by accessing their web interface). To use this scanning method, you need to specify the credentials in the VMware column on the Scanner tab.

Attention!

To scan macOS and Unix-like systems that are joined to a domain, you need to specify the domain account you previously used to log in to the target computer.
Alternatively, you can use a local account with administrator privileges to perform the scan.

Remote scanning via the SSH protocol

How it works:

  1. TNI connects to the remote computer via the SSH protocol.
  2. A temporary folder is created in the remote user’s home directory. The agent is then uploaded to this folder via SFTP or SCP.
  3. The agent is launched and creates a file containing the collected information when the scan is complete.
  4. The resulting file is then transferred back to TNI via SFTP or SCP and imported into the currently open Storage.
  5. The temporary folder containing the agent and the resulting file is deleted.

Before starting a scan, make sure that:

  • the remote computer runs an SSH-2 server that supports SFTP or SCP and is accessible through the firewall on TCP port 22, or on the Custom port specified in Options;
  • the remote user is permitted to connect to the SSH server (the AllowUsers option). If scanning is performed as root, the PermitRootLogin option must be set to yes;
  • the remote user must have administrative privileges. On Linux, the user must belong to the sudoers list unless the account is root).

The operating system must provide the agent with certain utilities to collect all the required data from the computer. The list of utilities depends on the operating system configuration. If a required utility is not installed on the target computer, a message will appear in the corresponding category in the Common reports view.

The operating system must also provide the standard C++ library libstdc++.so.6.

The following is an approximate list of utilities required to collect data from a Linux-based computer: arch, cd-info, df, dmidecode, dpkg-query / emerge / pacman / pkgtool / rpm, get-edid, hdparm, head, ifconfig, iptables, iptables-save, ls, lspci (pciconf for FreeBSD), lsusb, ps, pvdisplay, pvscan, route, rpm, swapon, uname.

Manual scanning

How it works:

  1. The appropriate agent executable is manually copied to the target computer and launched. When the scan is complete, the agent creates a file containing the collected information.
  2. The resulting file must be moved to the TNI Storage.
  3. See the Manual scan section for details.
Contents