NIS YPBind service

Risk Level: Low risk vulnerability  Low

Check or Attack Name: ypbind

Platforms: Any
Description:

The NIS ypbind service was found. NIS (Network Information Service) contains data, such as host files, password files, and e-mail aliases for entire networks. It allows a remote user to obtain copies of the NIS password map information. An attacker who possesses the NIS domain name (often set up as a derivative of the public domain name) can steal information helpful in guessing passwords and gaining unauthorized access.

Remedy:

The NIS domain name should be hard to guess.

References:

X-Force Logo
Know Your Risks