Re: security in sun solaris

From: Christian (christian_at_dnet.net.id)
Date: 08/29/03

  • Next message: netethix_at_iprimus.com.au: "RE: Security+ Advice"
    Date: Fri, 29 Aug 2003 08:34:36 +0700
    To: security-basics@securityfocus.com
    
    

    many thanks to
    martin.campbell@ed.ac.uk
    Frank.Branch@GD-NS.Com
    svawter@zonelabs.com
    salgak@speakeasy.net
    lukas76cz@seznam.cz

    actually, i have worked on inetd before on reducing unneccesary
    services, but the problem was in the services that was not in inetd, but
    anyway, thanks to the many people above, now i can secure my solaris box.
    a very good link that was pointed to me : (and it's really helpfull)
    http://security.vt.edu/lockitdown/
    http://sabernet.home.comcast.net/papers/Solaris.html
    http://www.serverworldmagazine.com/sunserver/2000/11/attack.shtml

    btw, i have problem installing lsof 4.68 on my sun solaris box, the
    install command was (after make install):
    install -m 2755 -g kmem lsof /usr/local/lsof/
    and it ends up with message saying
    "install: lsof was not found anywhere!"
    i have read the faqs and search the web but no uck so far, maybe someone
    could enlighten me?

    regards,
    christian

    >
    >
    > hi, i'm new at solaris, and i want to secure my solaris boxes, i
    > recently run nmap on one of my solaris box runing named service under
    > SunOS 5.6
    > Port State Service
    > 23/tcp open telnet
    > 25/tcp open smtp
    > 53/tcp open domain
    > 111/tcp open sunrpc
    > 256/tcp open rap
    > 257/tcp filtered set
    > 258/tcp open yak-chat
    > 264/tcp open bgmp
    > 265/tcp open unknown
    > 540/tcp open uucp
    > 4045/tcp open lockd
    > 6112/tcp open dtspc
    > 32771/tcp open sometimes-rpc5
    > 32773/tcp open sometimes-rpc9
    > 32774/tcp open sometimes-rpc11
    > 32775/tcp open sometimes-rpc13
    > 32776/tcp open sometimes-rpc15
    >
    > anyone know what this services for? and how turned these off? well,
    > except for telnet,smtp and domain of course, and how what program runs
    > what service in Solaris? like netstat -a -p in linux...
    > thanks for the help!
    >
    > regards,
    > chris
    >
    >
    >
    ---------------------------------------------------------------------------
    > Attend Black Hat Briefings & Training Federal, September 29-30
    (Training),
    > October 1-2 (Briefings) in Tysons Corner, VA; the world's premier
    > technical IT security event. Modeled after the famous Black Hat
    event in
    > Las Vegas! 6 tracks, 12 training sessions, top speakers and sponsors.
    > Symantec is the Diamond sponsor. Early-bird registration ends September
    > 6.Visit us: www.blackhat.com
    >
    ----------------------------------------------------------------------------
    >
    >

    ---------------------------------------------------------------------------
    Attend Black Hat Briefings & Training Federal, September 29-30 (Training),
    October 1-2 (Briefings) in Tysons Corner, VA; the world's premier
    technical IT security event. Modeled after the famous Black Hat event in
    Las Vegas! 6 tracks, 12 training sessions, top speakers and sponsors.
    Symantec is the Diamond sponsor. Early-bird registration ends September 6.Visit us: www.blackhat.com
    ----------------------------------------------------------------------------


  • Next message: netethix_at_iprimus.com.au: "RE: Security+ Advice"

    Relevant Pages

    • NDD Issue
      ... SUN E450 Machine not booting ... Solaris inetd not honoring the "-t" flag ...
      (SunManagers)
    • Solaris 8 to Linux dump compatibility question (Nick Pettefar)
      ... Solaris 8 to Linux dump compatibility question ... FOLLOWUP: Netra X1: How to break the LOM prompt in order to ... patches not available to customers w/o sunsolve accounts... ... After this you will need to write a finish script that will install the same ...
      (SunManagers)
    • Need Soalris 10 Certificaion documentaion
      ... One of our clients have an older aplication that only runs in Solaris ... Operating Environment Installation CD February 2000, which is SUN ... Solaris inetd not honoring the "-t" flag ...
      (SunManagers)
    • Solaris x86 FAQ 1/2
      ... Where can I obtain Solaris 2/x86 maintenance updates? ... What information should I have before an install? ... a 60GB disk shows up as only 28GB. ... Can I create a partition for Solaris within my extended partition? ...
      (comp.unix.solaris)
    • Re: trojaned SSHD ?
      ... I'd recommend moving to OpenSSH, which supports both ssh1 and ssh2 ... platforms, including Solaris. ... Information relevant to the installation of SSH on NCMIR systems. ... * Install Zlib 1.1.2 libraries, compiling from source, on Solaris and IRIX ...
      (Focus-SUN)

  • Quantcast