[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: portmapper



On Mon, Sep 13, 1999 at 01:40:57PM -0700, Jim McCloskey wrote:

> The security consultant here would like me not to run the RPC
> portmapper. I suppose this is a known security issue, and I'm not
> actually using the services that depend on it.

> It seems to be started in /etc/initd/netbase, but looking at that
> script, it's not obvious to me what the base way to disable it would
> be. 

Comment out the line which starts the portmap program.  In potato
portmap has been moved into a seperate init script, so you could just
remove it from the relevant runlevels.

It would probably also be good karma to disable or deinstall anything 
else which uses portmap - "rpcinfo -p <host>" should give you a clue 
as to what that involves.

-- 
Mark Brown  mailto:broonie@tardis.ed.ac.uk   (Trying to avoid grumpiness)
            http://www.tardis.ed.ac.uk/~broonie/
EUFS        http://www.eusa.ed.ac.uk/societies/filmsoc/

Attachment: pgpXwG_UJ05Ps.pgp
Description: PGP signature


Reply to: