Re: How vulnerable is RPC (port 1025) on Linux?

From: David Magda (dmagda+trace040423_at_ee.ryerson.ca)
Date: 06/23/04

  • Next message: David Magda: "Re: using secure ftp with a pipe ?"
    Date: 23 Jun 2004 11:21:34 -0400
    
    

    jdaviestx@comcast.net (Joshua Davies) writes:
    [...]
    > most port 1025 vulnerabilities are related to Microsoft's DCOM
    > protocol, which I'm obviously not using... are there any other
    > known RPC vulnerabilities? Any known worms that try to replicate
    > on port 1025?

    There are no publicly disclosed vulnerabilities at this time. (Any
    old issues (if they exist) should be fixed.)

    That being said, there is always the possibility of issues in the
    future. As a general rule: if you don't need a service, disable
    it. Your system cannot be broken into if there are no ways in.

    -- 
    David Magda <dmagda at ee.ryerson.ca>, http://www.magda.ca/
    Because the innovator has for enemies all those who have done well under
    the old conditions, and lukewarm defenders in those who may do well 
    under the new. -- Niccolo Machiavelli, _The Prince_, Chapter VI
    

  • Next message: David Magda: "Re: using secure ftp with a pipe ?"

    Relevant Pages

    • port of NetBSDs audit-packages (and an update of pkg_install)
      ... I want to port NetBSD's security/audit-packages to FreeBSD. ... The idea is that you just synchronize a file with known vulnerabilities, ... and a script in periodic/security warns you when you have a vulnurable ...
      (freebsd-hackers)
    • Re: Crashing services with NMAP and/or SuperScan ?
      ... There are POP servers on VMS that won't take a reset TCP session for ... electro-cardiogram reader controlling software that dies at the mere ... You have identified possible vulnerabilities with your scans, ... or indeed any random person with a port scanner -- would do the same ...
      (Pen-Test)
    • FreeBSD Ports Security Advisory FreeBSD-SA-01:23.icecast [REVISED]
      ... FreeBSD only: NO ... 2001-05-28 v1.1 Note vulnerabilities in versions prior to 1.3.10 ... The icecast software, versions prior to 1.3.10, contains multiple ... Upgrade your entire ports collection and rebuild the icecast port. ...
      (FreeBSD-Security)
    • Re: gaim or aim on 5.4 amd64 ?
      ... > some security issues, thus portaudit prevents You from installing it. ... Portaudit merely reports on security vulnerabilities in the ports. ... Portaudit will not prevent the install of a vulnerable port. ...
      (freebsd-questions)
    • Force install vulnerable port
      ... How can I override portaudit when trying to install a port with ... vulnerabilities like jdk? ... My temp. ...
      (freebsd-questions)