tips:irix:security
This is an old revision of the document!
Secure the system
Disable useless daemons
To disable useless daemons, use chkconfig :
# chkconfig <daemon> off
For a workstation, here is a list of daemons you should disable:
appletalk off
automount off
cesag off
dtlogin off
esp off
fcagent off
fontserver off
gated off
ldap off
lp off
miser off
mrouted off
named off
nds off
nfsd off
noiconlogin off
nostickytmp off
pmcd off
pmie off
proclaim_relayagent off
proclaim_server off
proxymngr off
quickpage off
rarpd off
route6d off
routed off
rsvpd off
rwhod off
sar off
sdpd off
sesdaemon off
sgi_apache off
tfxd off
timed off
timeslave off
ts off
verbose off
videod off
vswap off
webface off
webface_apache off
yp off
ypmaster off
ypserv off
To just keep these on:
autoconfig_ipaddress on
autofs on
desktop on
ipaliases on
lockd on
mediad on
ndpd on
neko_sshd on
network on
nfs on
nsd on
ntp on
privileges on
rtmond on
savecore on
sendmail on
sendmail_cf on
snetd on
soundscheme on
visuallogin on
windowsystem on
xdm on
Secure inetd
Edit /etc/inetd.conf, and comment out everything but the “sgi_” stuff. You will need it for the desktop to work.
sgi_videod/1 stream rpc/tcp wait root ?/usr/etc/videod videod sgi_fam/1-2 stream rpc/tcp wait/lc root ?/usr/etc/fam fam sgi_snoopd/1 stream rpc/tcp wait root ?/usr/etc/rpc.snoopd snoopd sgi_pcsd/1 dgram rpc/udp wait root ?/usr/etc/cvpcsd pcsd sgi_pod/1 stream rpc/tcp wait root ?/usr/etc/podd podd sgi_xfsmd/1 stream rpc/tcp wait root ?/usr/etc/xfsmd xfsmd sgi_espd/1 stream rpc/tcp wait root ?/usr/etc/rpc.espd espd tcpmux/sgi_scanner stream tcp nowait root ?/usr/lib/scan/net/scannerd scannerd tcpmux/sgi_printer stream tcp nowait root ?/usr/lib/print/printerd printerd tcpmux/sgi_sysadm stream tcp nowait root ?/usr/sysadm/bin/sysadmd sysadmd tcpmux/sgi_dmusrcmd stream tcp nowait root ?/usr/etc/dmusrcmd /usr/etc/dmusrcmd
Then:
# killall -HUP inetd
Improve kernel security
Add a bit of entropy to the TCP sequence number and drop ICMP redirects:
# systune ipforwarding 0 # systune ip6forwarding 0 # systune tcpiss_md5 1 # systune icmp_dropredirects 1 # systune restricted_chown 1 # systune allow_brdaddr_srcaddr 0 # systune tcp_2msl 60
These kernel settings can be found in the /var/sysgen/stune file.
Finally:
# autoconfig -vf # reboot
Make sendmail just listen on localhost
Edit /etc/mail/sendmail.mc. Switch the two lines to be:
DAEMON_OPTIONS(`Name=MTA-v4,Family=inet,Addr=127.0.0.1')dnl dnl DAEMON_OPTIONS(`Name=MTA-v6,Family=inet6')dnl
Then run configmail to update sendmail.cf and restart it:
# configmail mc2cf # /etc/init.d/mail restart
tips/irix/security.1790943824.txt.gz · Last modified: by mattieu
