Re: tcpwrapped rpcbind/portmap?

From: Reg Quinton (reggers@ist.uwaterloo.ca)
Date: 08/21/01


Message-ID: <02fd01c12a46$36b56760$9d6c6181@uwaterloo.ca>
From: "Reg Quinton" <reggers@ist.uwaterloo.ca>
To: <focus-sun@securityfocus.com>
Subject: Re: tcpwrapped rpcbind/portmap?
Date: Tue, 21 Aug 2001 09:35:59 -0400


> Absolutely. The lack of ACL enforcement within the stock Solaris
> rpcbind make its use problematic in a security-sensitive environment.

I'd guess you're better off to have the filtering done at a lower level
in the IP stack and not require that each service implement it's own
filtering.

Are there no tools for Solaris to do that -- filter at a lower level in
the IP stack. Would SunScreen Lite do it?

The Seattle folks offer tools for their systems, surely we have something
for Solaris.



Relevant Pages

  • Re: tcpwrapped rpcbind/portmap?
    ... Subject: tcpwrapped rpcbind/portmap? ... > I'd guess you're better off to have the filtering done at a lower level ... > the IP stack. ... > for Solaris. ...
    (Focus-SUN)
  • RE: Weird one
    ... Solaris isn't Linux and there are a lot of potential differences under the ... There are a couple of ways that you can write and control the stack, ... On a multi-core /smp Linux box, does each CPU have its own stack or does ... Meaning if Thread A from the same process is on core 1, ...
    (comp.databases.informix)
  • Re: Solaris sparc newbie exploit coding misc questions
    ... > I gather together some misc questions about designing buffer overflows ... what is the stack address? ... On solaris 10 sparc, running ... Shellcode on Solaris sparc: In some documentation, ...
    (Vuln-Dev)
  • Re: how big can automatic (stack) arrays be
    ... pre-translated and faults are still used to grow the stack. ... was that unlike Solaris on Sparc (and Linux on PC, I think), the ... less the same memory layout, with the heap growing up, and the ...
    (comp.unix.programmer)
  • Re: how big can automatic (stack) arrays be
    ... the fundamentally identical Linux and Solaris operating systems' was ... more stack space than that, it will cause a page fault to ... happen and the kernel fault handler is supposed to expand the ...
    (comp.unix.programmer)