Current Issue


Table of contents

CD-ROM

Sys Admin and The Perl Journal CD-ROM version 12.0

Version 12.0 delivers every issue of Sys Admin from 1992 through 2006 and every
issue of The Perl Journal from 1996-2002 in one convenient CD-ROM!

Order now!

Sys Admin Magazine > Archives > 2001 > April 2001

Solaris Network Hardening: First Steps

Reg Quinton

There is a security principle that says you should "configure computers to provide only selected network services" (CERT Coordination Centre: http://www.cert.org/security-improvement/practices/p038.html). The idea is that every network service you offer is an opportunity for hackers and a risk to your system. That's not to say that you shouldn't offer any services -- a mail server that doesn't offer mail services isn't very useful. Instead, you should have a good understanding of network services and you should not offer any unnecessary service. This paper is a discussion of tools you'll need to determine services offered by a Solaris server. As such it's a first step in hardening a Solaris server.

Baseline -- What's There?

Before hardening a system you need to know what's on the system and, better yet, how to find that out. There are three valuable tools:

  • netstat and rpcinfo, as provided by the vendor
  • lsof, a public domain add on

All can be used to identify network services that your system offers to clients on the network -- services that might be exploited.

You can find lsof at several sites. The home location is:

ftp://vic.cc.purdue.edu/pub/unix/lsof

The netstat Command

To determine the services that your system offers, try this command:

[2:20pm wally] netstat -a

UDP
Local Address         Remote Address     State
------------------- -------------------- -------
   *.sunrpc                              Idle
   *.*                                   Unbound
   *.32771                               Idle
   *.n

				  



MarketPlace

Build IT Knowledge with Current & Trusted Content
Helps Employees Develop & Hone New Technical Programming Skills. Sign Up & Get Full Access.

Villanova University Six Sigma & IT Certificate Programs
100% Online programs in Six Sigma, IS Security, CISSP Prep, Business Analysis, Proj. Mgmt. and more!

WinDev 11 - Powerful IDE
Develop 10 times faster ! ALM, IDE, .Net, RAD, 5GL, Database, 5GL, 64-bit, etc. Free Express version

Domain Name Registrations, Web Hosting, Email
Pay less for Domain Names, Increase your company's bottom line - get a raise. Accredited domain name registrar, ZippyNames.us : Discount bulk transfers, email, webhosting, dedicated servers. Earn money as a domain name reseller - better discounts!

Wanna see your ad here?