Re: Disabling rpcbind/portmapper

From: Gregory Hicks (ghicks_at_cadence.com)
Date: 11/05/03

  • Next message: Reg Quinton: "Re: Disabling rpcbind/portmapper"
    Date: Wed, 5 Nov 2003 10:28:42 -0800 (PST)
    To: focus-sun@securityfocus.com, vasco@all-2-it.com
    
    

    > Date: Wed, 05 Nov 2003 13:14:27 +0000
    > From: António Vasconcelos <vasco@all-2-it.com>
    >
    > Casper Dik wrote:
    >
    > > The risk of rpcbind is fairly minimal; though I supposed we should
    > >
    > >put in some work to make it e.g., "localhost only".
    > >
    >
    > I didn't know that such thing could be done, at least in Sol 8 or 9.
    > Is there any way to restrict any server only to one interface ? Maybe
    > with some kind of iptables or such ????
    >

    The only way *I've* seen this done is with a firewall blocking all
    machines except the one you WANT the traffic to go to...

    Regards,
    Gregory Hicks

    -------------------------------------------------------------------

    "The trouble with doing anything right the first time is that nobody
    appreciates how difficult it was."

    When a team of dedicated individuals makes a commitment to act as
    one... the sky's the limit.

    Just because "We've always done it that way" is not necessarily a good
    reason to continue to do so... Grace Hopper, Rear Admiral, United
    States Navy


  • Next message: Reg Quinton: "Re: Disabling rpcbind/portmapper"

    Relevant Pages

    • Re: no network access to or from server
      ... If your eth0 (or whatever interface are you using) interface ... You can flush your iptables chains with the following: ... >>and mail server running Debian 3.1. ... >You should first try to clear the firewall rules shorewall might have set. ...
      (Debian-User)
    • iptables is like alchemy
      ... This is really related to iptables, ... of that server actually just connects to port 22 on another machine located ... in the network on the internal interface. ...
      (Fedora)
    • iptables difference between FC3 and FC4
      ... my server currently have multiple IP running on a single interface.. ... choose to use iptables rules to have all proxies replying by theire own ... but when I try this same iptables command on a server runnign FC4 it ...
      (comp.os.linux.networking)
    • Re: Disabling rpcbind/portmapper
      ... > Is there any way to restrict any server only to one interface? ... > with some kind of iptables or such ...
      (Focus-SUN)
    • Re: Is there an obvious way to do this in python?
      ... | interface, if it is returned as 'full' draw the full interface. ... | functional because the database would restrict writes to certain ... | some kind of update server to which you can periodically send Python ...
      (comp.lang.python)