Re: rpc.statd attacks

From: Crist J. Clark (cristjc@earthlink.net)
Date: 07/22/01


Date: Sun, 22 Jul 2001 11:07:55 -0700
From: "Crist J. Clark" <cristjc@earthlink.net>
To: serkoon <serkoon@thedarkside.nl>

On Sun, Jul 22, 2001 at 12:52:08PM +0200, serkoon wrote:
> > However, since I have port 111 blocked in the firewall,
> > how in the world is even an error message being generated?
> > I have even portscanned and 111 is not open to the outside.
>
> Firewall UDP:111 or kill portmapd (if you don't need it).

1) You do not allow traffic to 111/tcp OR 111/udp, do you?

2) Just because you block port 111 doesn't mean people cannot attack
   rpc.statd. Blocking 111 just makes finding the ports that rpc.statd
   is listening on a little harder, but not difficult.

Don't "block" port 111. Pass only traffic you want and expect, block
everything else by default.

-- 
Crist J. Clark                           cjclark@alum.mit.edu
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • Another discussion of this
    ... Strictly speaking, this is not a port 25 block, as would have been ... InsightBroadband has some special settings for travelers that should help: ... PLEASE COPY & PASTE THE ERROR MESSAGE TO GET SPECIFIC ASSISTANCE. ... using the correct port settings as provided by the server. ...
    (microsoft.public.windows.vista.mail)
  • Re: port 4125
    ... The error message indeed indicates that there is some process use the port ... then please try to logon to SBS server box to test the ... This newsgroup only focuses on SBS technical issues. ... I attached a screenshot of the error message I receive. ...
    (microsoft.public.windows.server.sbs)
  • Re: COM1 not behaving...
    ... perhaps the BIOS is handing off 4 and OS is assigning 7 because it thinks 4 is used and there is the error message? ... What's weird though, is that I just noticed that COM1 now has IRQ 7, while it had IRQ 4 yesterday. ... I haven't swapped the expansion card to a different PCI slot yet, ... I seem to have a stubborn serial port. ...
    (microsoft.public.windowsxp.hardware)
  • Re: 0x800CCCA0 NNTP_RESPONSE_ERROR
    ... >encounteing the following error message when I attempt to ... >Port 119 is needed to access newsgroups and it would ... Bruce - Thanks for the reply - I am not using a firewall. ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: Error: shared library "mysqlclient.18" does not exist
    ... wheel 20 Mar 11 16:22 libmysqlclient.so@ ... At what point do you receive the error message? ... compiling security/maia port. ... that means you can go and run "make install" if you don't actually ...
    (freebsd-questions)