Xerox 6180N DocuSP Common Controller System Guide - Page 60

Environment Network Settings for Security,

Page 60 highlights

Security and Network Setup Multicast routing disabled Multicast is used to send data to many systems at the same time while using one address. OS and host information hidden The ftp, telnet and sendmail banners are set to null so that users in cannot see the hostname and OS level. NOTE: All of these services are prohibited with a high security setting, but if they are re-enabled manually the hostname information will remain hidden. Sendmail daemon secured Sendmail is forced to perform only outgoing mail. No incoming mail will be accepted. Network parameters secured Suns nddconfig security tool is run. For additional information, view Suns document, Solaris Operating Environment Network Settings for Security, at http://www.sun.com/solutions/ blueprints/1200/networkupdt1.pdf. Executable stacks disabled The system stack is made non-executable. This is done so security exploitation programs cannot take advantage of the Solaris OE kernel executable system stack and thereby attack the system. NFS port monitor restricted The NFS server normally accepts requests from any port number. The NFS Server is altered to process only those requests from privileged ports. Note that with the high security setting, NFS is disabled; however if the service is reenabled manually, the port restriction will still apply. Remote CDE login disabled The Remote CDE login is disabled. 3-10 System Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140

Security and Network Setup
3-10
System Guide
Multicast routing disabled
Multicast is used to send data to many systems at the same
time while using one address.
OS and host information hidden
The ftp, telnet and sendmail banners are set to null so that
users in cannot see the hostname and OS level.
NOTE:
All of these services are prohibited with a high
security setting, but if they are re-enabled manually the
hostname information will remain hidden.
Sendmail daemon secured
Sendmail is forced to perform only outgoing mail. No
incoming mail will be accepted.
Network parameters secured
Suns nddconfig security tool is run. For additional
information, view Suns document, Solaris Operating
Environment Network Settings for Security, at
http://www.sun.com/solutions/ blueprints/1200/network-
updt1.pdf.
Executable stacks disabled
The system stack is made non-executable. This is done so
security exploitation programs cannot take advantage of the
Solaris OE kernel executable system stack and thereby
attack the system.
NFS port monitor restricted
The NFS server normally accepts requests from any port
number. The NFS Server is altered to process only those
requests from privileged ports.
Note that with the high
security setting, NFS is disabled; however if the service is re-
enabled manually, the port restriction will still apply.
Remote CDE login disabled
The Remote CDE login is disabled.