mirror of
https://github.com/freebsd/freebsd-src
synced 2024-11-05 18:22:52 +00:00
In the brave new world, that that does not make us strong, kills us.
Turn OFF the "small servers" by default. FreeBSD systems should only serve actively used programs. Jewels like chargen and echo are too useful in attack scenarios.
This commit is contained in:
parent
14b7c0f2f9
commit
9080596148
Notes:
svn2git
2020-12-20 02:59:44 +00:00
svn path=/head/; revision=18639
1 changed files with 37 additions and 27 deletions
|
@ -7,45 +7,55 @@ ftp stream tcp nowait root /usr/libexec/ftpd ftpd -l
|
|||
telnet stream tcp nowait root /usr/libexec/telnetd telnetd
|
||||
shell stream tcp nowait root /usr/libexec/rshd rshd
|
||||
login stream tcp nowait root /usr/libexec/rlogind rlogind
|
||||
#exec stream tcp nowait root /usr/libexec/rexecd rexecd
|
||||
uucpd stream tcp nowait root /usr/libexec/uucpd uucpd
|
||||
#nntp stream tcp nowait usenet /usr/libexec/nntpd nntpd
|
||||
finger stream tcp nowait nobody /usr/libexec/fingerd fingerd -s
|
||||
#tftp dgram udp wait nobody /usr/libexec/tftpd tftpd /tftpboot
|
||||
#exec stream tcp nowait root /usr/libexec/rexecd rexecd
|
||||
#uucpd stream tcp nowait root /usr/libexec/uucpd uucpd
|
||||
#nntp stream tcp nowait usenet /usr/libexec/nntpd nntpd
|
||||
comsat dgram udp wait root /usr/libexec/comsat comsat
|
||||
#talk dgram udp wait root /usr/old/talkd talkd
|
||||
ntalk dgram udp wait root /usr/libexec/ntalkd ntalkd
|
||||
#ident stream tcp wait root /usr/local/sbin/identd identd -w -t120
|
||||
echo stream tcp nowait root internal
|
||||
discard stream tcp nowait root internal
|
||||
#bootps dgram udp wait root /usr/libexec/bootpd bootpd /etc/bootptab
|
||||
chargen stream tcp nowait root internal
|
||||
daytime stream tcp nowait root internal
|
||||
time stream tcp nowait root internal
|
||||
#tftp dgram udp wait nobody /usr/libexec/tftpd tftpd /tftpboot
|
||||
#bootps dgram udp wait root /usr/libexec/bootpd bootpd
|
||||
#
|
||||
# "Small servers" -- used to be standard on, but we're more conservative
|
||||
# about things due to Internet security concerns. Only turn on what you
|
||||
# need.
|
||||
#
|
||||
#daytime stream tcp nowait root internal
|
||||
#daytime dgram udp wait root internal
|
||||
#time stream tcp nowait root internal
|
||||
#time dgram udp wait root internal
|
||||
#echo stream tcp nowait root internal
|
||||
#echo dgram udp wait root internal
|
||||
discard dgram udp wait root internal
|
||||
#chargen dgram udp wait root internal
|
||||
#daytime dgram udp wait root internal
|
||||
#time dgram udp wait root internal
|
||||
#discard stream tcp nowait root internal
|
||||
#discard dgram udp wait root internal
|
||||
#chargen stream tcp nowait root internal
|
||||
#chargen dgram udp wait root internal
|
||||
#
|
||||
# Kerberos authenticated services
|
||||
#
|
||||
klogin stream tcp nowait root /usr/libexec/rlogind rlogind -k
|
||||
eklogin stream tcp nowait root /usr/libexec/rlogind rlogind -k -x
|
||||
kshell stream tcp nowait root /usr/libexec/rshd rshd -k
|
||||
rkinit stream tcp nowait root /usr/libexec/rkinitd rkinitd
|
||||
#
|
||||
# Services run ONLY on the Kerberos server
|
||||
# Neither of these work in FreeBSD 1.x.
|
||||
#
|
||||
#krbupdate stream tcp nowait root /usr/libexec/registerd registerd
|
||||
#kpasswd stream tcp nowait root /usr/libexec/kpasswdd kpasswdd
|
||||
#kpasswd stream tcp nowait root /usr/libexec/kpasswdd kpasswdd
|
||||
#
|
||||
# RPC based services
|
||||
# You MUST have portmapper running to use these!
|
||||
#rstatd/1-3 dgram rpc/udp wait root /usr/libexec/rpc.rstatd rpc.rstatd
|
||||
#rusersd/1-2 dgram rpc/udp wait root /usr/libexec/rpc.rusersd rpc.rusersd
|
||||
#walld/1 dgram rpc/udp wait root /usr/libexec/rpc.rwalld rpc.rwalld
|
||||
#pcnfsd/1-2 dgram rpc/udp wait root /usr/libexec/rpc.pcnfsd rpc.pcnfsd
|
||||
#rquotad/1 dgram rpc/udp wait root /usr/libexec/rpc.rquotad rpc.rquotad
|
||||
#sprayd/1 dgram rpc/udp wait root /usr/libexec/rpc.sprayd rpc.sprayd
|
||||
# RPC based services (you MUST have portmapper running to use these)
|
||||
#
|
||||
#rstatd/1-3 dgram rpc/udp wait root /usr/libexec/rpc.rstatd rpc.rstatd
|
||||
#rusersd/1-2 dgram rpc/udp wait root /usr/libexec/rpc.rusersd rpc.rusersd
|
||||
#walld/1 dgram rpc/udp wait root /usr/libexec/rpc.rwalld rpc.rwalld
|
||||
#pcnfsd/1-2 dgram rpc/udp wait root /usr/libexec/rpc.pcnfsd rpc.pcnfsd
|
||||
#rquotad/1 dgram rpc/udp wait root /usr/libexec/rpc.rquotad rpc.rquotad
|
||||
#sprayd/1 dgram rpc/udp wait root /usr/libexec/rpc.sprayd rpc.sprayd
|
||||
#
|
||||
# example entry for the optional pop3 server
|
||||
#
|
||||
# example entry for the pop3 server
|
||||
#pop3 stream tcp nowait root /usr/local/libexec/popper popper
|
||||
#
|
||||
# example entry for the optional ident server
|
||||
#
|
||||
#ident stream tcp wait root /usr/local/sbin/identd identd -w -t120
|
||||
|
|
Loading…
Reference in a new issue