home *** CD-ROM | disk | FTP | other *** search
- From: panos@tigger.Colorado.EDU (Panos Tsirigotis)
- Newsgroups: alt.security,comp.sys.sun.admin
- Subject: Re: announcing securelib: securing network services under SunOS
- Message-ID: <1992Feb17.174806.19954@colorado.edu>
- Date: 17 Feb 92 17:48:06 GMT
- References: <1992Feb15.221236.1698@eecs.nwu.edu>
- Organization: University of Colorado, Boulder
-
- In article <1992Feb15.221236.1698@eecs.nwu.edu> phil@eecs.nwu.edu (William LeFebvre) writes:
- >There has been much discussion on these groups recently about how
- >vulnerable system daemons like ypserv, pwdauthd, and portmap are
- >to hostile attack from remote Internet sites. I have devised a
- >clever little package that creates an alternate shared library for
- >use with system daemons which need to be protected from unwanted
- >connections. It is called "securelib".
- >
- > .... [ description of securelib skipped]
- >
- >USING THE ALTERNATE LIBRARY:
- >
- >Now decide which servers you want to protect. I personally have
- >chosen portmap, rpc.pwdauthd, ypserv, and rpc.yppasswdd. Another
- >possibility is nfsd, but remember that each packet received by nfsd
- >must be verified by "_ok_address". This may have a noticeable impact
- >on nfs performance.
-
- No, nfsd is NOT a possibility. nfsd does not exist is user mode; it
- is in the kernel and it invokes the _kernel_ code that implements recvmsg.
-
- Panos
-
- --
- Panos Tsirigotis, CS grad
- Pmail: Computer Science Dept., U. of Colorado @ Boulder, Boulder, CO 80309-0430
- Email: panos@cs.colorado.edu
-
-