Great Circle Associates Firewalls
(September 1992)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: ports to filter [Was: Sun's firewall special]
From: ken @ porsche . visix . COM (Ken Mayer)
Date: Thu, 24 Sep 1992 13:21:57 -0400
To: firewalls @ GreatCircle . COM
In-reply-to: smb @ ulysses . att . com's message of Thu, 24 Sep 92 10:45:34 EDT
Reply-to: ken @ porsche . visix . COM

-->On Thu, 24 Sep 92 10:45:34 EDT, smb @
 ulysses .
 att .
 com said:

 Brian> 	 Brian Utterback writes:
	 > CERT recommends restricting the protocols for :
	 >	.
	 >	.
	 > uucpd			(540)
	 >	.
	 >	.

 Brian> 	 Can somebody explain why this would be on the list?  I've been
 Brian> 	 through the uucpd code and didn't see anything particularly
 Brian> 	 problematic with it.  Am I missing something?

>From the man page uucpd(1)

     This daemon acts as a login server to start UUCP connec-
     tions.  First, it prompts with the word ``login:'' and waits
     for the login name to be given.  If there is a password for
     the account (as is advisable), this is prompted for and
     checked.  The account used must have the login shell set to
     /usr/lib/uucp/uucico to be considered valid for this type of
     connection.

     Once a valid login has been established, the command
     /usr/lib/uucp/uucico is executed to begin the UUCP session.
 
If you don't want uucp connections you should definitely turn this
off. I don't know how dangerous uuxqt's are, but you could be
vulnerable to a loss of service type attack if someone started dumping
huge files into your /usr/spool/uucppublic directory.

Ken






Follow-Ups:
Indexed By Date Previous: Re: SGI ipfilterd.conf
From: mandrews @ alias . com (Mark Andrews)
Next: Mail and gateways
From: Paul R. Joslin <news_for @ ae . ge . com>
Indexed By Thread Previous: Re: ports to filter [Was: Sun's firewall special]
From: smb @ ulysses . att . com
Next: Re: ports to filter [Was: Sun's firewall special]
From: Tom Moore <tmoore @ wnas . DaytonOH . NCR . COM>

Google
 
Search Internet Search www.greatcircle.com