★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/server_security_article-2490.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 
News: Server Security 2/13/2001 10:50

Securing BSD Daemons

O'Reilly
Posted By: Jen Olson
2/13/2001

Let's continue where we left off by taking a closer look at /etc/inetd.conf. Remember that inetd is the internet super-server which listens for requests on behalf of other daemons; it reads /etc/inetd.conf to determine which ports you wish it to listen on. You should always comment out the lines which represent the daemons you don't wish people to make network connections to. A good general rule is that if you don't know what a daemon does, comment it out.

On my system, inetd is listening for IPV4 connection requests for the following daemons: ftp, telnet, comsat, ntalk, and tftp. I don't intend to maintain a tftp or ftp server, and I'm not totally convinced that I need to provide comsat or ntalk services. However, I do need to telnet into my FreeBSD system on occasion. So, I'll become the superuser, open up /etc/inetd.conf using the vi editor, and add comment characters to the four lines that represent the daemons on whose behalf I don't want inetd to listen. When I'm finished, that portion of my /etc/inetd.conf file will look like


Click here to go to this article.

SafeWeb's Triangle Boy enters CIA civil service
Feb 17

Tatu Ylonen Comments on SSH Trademark
Feb 16

Jay Beale: Education Is Primary Defense for Secure Machines
Feb 16

Online vandals smoke New York Times site
Feb 16

Network Solutions sells its database
Feb 16

Intrusion detection rules drafted
Feb 16

Monitoring Unix Logins
Feb 16

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000