Security and Network Setup
Multicast routing disabled
Sendmail daemon secured
Network parameters secured
Executable stacks disabled
NFS port monitor restricted
Remote CDE login disabled
3-10
Multicast is used to send data to many systems at the same
time while using one address.
OS and host information hidden
The ftp, telnet and sendmail banners are set to null so that
users in cannot see the hostname and OS level.
NOTE: All of these services are prohibited with a high
security setting, but if they are re-enabled manually the
hostname information will remain hidden.
Sendmail is forced to perform only outgoing mail. No
incoming mail will be accepted.
Suns nddconfig security tool is run. For additional
information, view Suns document, Solaris Operating
Environment Network Settings for Security, at
http://www.sun.com/solutions/ blueprints/1200/network-
updt1.pdf.
The system stack is made non-executable. This is done so
security exploitation programs cannot take advantage of the
Solaris OE kernel executable system stack and thereby
attack the system.
The NFS server normally accepts requests from any port
number. The NFS Server is altered to process only those
requests from privileged ports. Note that with the high
security setting, NFS is disabled; however if the service is re-
enabled manually, the port restriction will still apply.
The Remote CDE login is disabled.
System Guide