Portmap UNSET procedure requested |
---|
Risk Level: | Medium | Check or Attack Name: PmapUnset |
---|---|---|
Platforms: | RPC Portmapper | |
Description: | The RPC Portmapper implements the UNSET procedure that allows RPC programs to unregister themselves with the portmapper. This destroys the mapping between the programs RPC number and port number inside the portmapper and is usually called as the service shuts down. |
|
Remedy: | The Remote Procedure Call (RPC) is an inherently unsafe protocol and should be blocked at all border gateways and firewalls to prevent attackers from abroad exploiting these weaknesses. |
|
References: |
Know Your Risks |