Re: FreeBSD Security Advisory FreeBSD-SA-06:10.nfs



FreeBSD Security Advisories wrote:
Topic: Remote denial of service in NFS server
[...]
IV. Workaround

1) Disable the NFS server: set the nfs_server_enable variable to "NO"
in /etc/rc.conf, and reboot.

Alternatively, if there are no active NFS clients (as listed by the
showmount(8) utility), simply killing the mountd and nfsd processes
should suffice.

2) Add firewall rules to block RPC traffic to the NFS server from
untrusted hosts.

There's one more workaround: Since this problem only affects RPC messages
incoming via TCP, disabling the use of TCP with NFS will correct this
while still allowing NFS to run over UDP.

To disable use of TCP for NFS, remove the "-t" flag from nfs_server_flags
in /etc/rc.conf and reboot.

Colin Percival
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: NFS mount of ODS-5 vs traditional parse type
    ... > I would like to know if someone of you found a workaround about a NFS ... data on a case-preserving case-insensitive file system? ...
    (comp.os.vms)
  • Re: bug in autofs???
    ... I do not know of a workaround using NFS. ... Kind regards, ... Jan Gerrit ...
    (linux.redhat.install)
  • SuSE 10.0 NFS vs. Firewall
    ... I am attempting to get NFS working; both client and server are running ... 3/min burst 5 LOG level warning tcp-options ip-options prefix ... 3/min burst 5 state NEW udp dpt:sunrpc LOG level warning tcp-options ... 3/min burst 5 state NEW tcp dpt:sunrpc LOG level warning tcp-options ...
    (alt.os.linux.suse)
  • Re: Firewall problems with NFS
    ... It seems to only allow use as an NFS client, since that worked fine when I tested it. ... U was surprised to see that TCP with tcp_adv_win_size=5 and rsize=8192 was as fast as UDP, ... 100005 1 udp 841 mountd ...
    (Fedora)
  • Trying to get NFS working with FreeBSD & OS X
    ... NFS client on a Mac OS X box. ... 100000 4 tcp 111 portmapper ... 100000 4 udp 111 portmapper ... 100021 0 udp 617 nlockmgr ...
    (comp.unix.bsd.freebsd.misc)