User Tools

Site Tools


tips:irix:security

This is an old revision of the document!


Secure the system

Disable useless daemons

To disable useless daemons, use chkconfig :

# chkconfig <daemon> off

For a workstation, here is a list of daemons you should disable:

        appletalk            off
        automount            off
        cesag                off
        dtlogin              off
        esp                  off
        fcagent              off
        fontserver           off
        gated                off
        ldap                 off
        lp                   off
        miser                off
        mrouted              off
        named                off
        nds                  off
        nfsd                 off
        noiconlogin          off
        nostickytmp          off
        pmie                 off
        proclaim_relayagent  off
        proclaim_server      off
        proxymngr            off
        quickpage            off
        rarpd                off
        route6d              off
        routed               off
        rsvpd                off
        rwhod                off
        sar                  off
        sdpd                 off
        sesdaemon            off
        sgi_apache           off
        tfxd                 off
        timed                off
        timeslave            off
        ts                   off
        verbose              off
        videod               off
        vswap                off
        webface              off
        webface_apache       off
        yp                   off
        ypmaster             off
        ypserv               off

To just keep these on:

        autoconfig_ipaddress on
        autofs               on
        desktop              on
        ipaliases            on
        lockd                on
        mediad               on
        ndpd                 on
        neko_sshd            on
        network              on
        nfs                  on
        nsd                  on
        ntp                  on
        pmcd                 on
        privileges           on
        rtmond               on
        savecore             on
        sendmail             on
        sendmail_cf          on
        snetd                on
        soundscheme          on
        visuallogin          on
        windowsystem         on
        xdm                  on

Secure inetd

Edit /etc/inetd.conf, and comment out everything but the “sgi_” stuff. You will need it for the desktop to work.

sgi_videod/1 stream rpc/tcp wait    root    ?/usr/etc/videod         videod
sgi_fam/1-2 stream  rpc/tcp wait/lc    root    ?/usr/etc/fam            fam
sgi_snoopd/1 stream rpc/tcp wait    root    ?/usr/etc/rpc.snoopd     snoopd
sgi_pcsd/1  dgram   rpc/udp wait    root    ?/usr/etc/cvpcsd        pcsd
sgi_pod/1   stream  rpc/tcp wait    root    ?/usr/etc/podd           podd
sgi_xfsmd/1 stream  rpc/tcp wait    root    ?/usr/etc/xfsmd     xfsmd
sgi_espd/1 stream   rpc/tcp wait    root    ?/usr/etc/rpc.espd  espd
tcpmux/sgi_scanner stream tcp nowait root   ?/usr/lib/scan/net/scannerd scannerd
tcpmux/sgi_printer stream tcp nowait root   ?/usr/lib/print/printerd printerd
tcpmux/sgi_sysadm stream tcp nowait root   ?/usr/sysadm/bin/sysadmd sysadmd
tcpmux/sgi_dmusrcmd stream tcp nowait root ?/usr/etc/dmusrcmd /usr/etc/dmusrcmd

Then:

# killall -HUP inetd
tips/irix/security.1790926793.txt.gz · Last modified: by mattieu