> > CERT recommends restricting the protocols for :
> > .
> > uucpd (540)
> > .
>
> Can somebody explain why this would be on the list?
In addition to what has been posted, several sites have reported breakins
due to uucpd being enabled by default in inetd.conf (Please check yours).
The sites had not planned to use UUCP and no effort had been made to change
the vendor's config files in the /usr/lib/uucp directory.
Thank you,
Ed DeHart
Computer Emergency Response Team
Internet E-mail: cert @
cert .
org
Telephone: 412-268-7090 24-hour hotline:
CERT personnel answer 7:30a.m. to 6:00p.m. EST(GMT-5)/EDT(GMT-4),
and are on call for emergencies during other hours.
|
|