NFS安全设置
NFS服务器漏扫:目标主机showmount -e信息泄露(CVE-1999-0554)
解决方法:
1.NFS Server服务器/etc/hosts.allow中添加如下内容:
[root@zyfw ~]# more /etc/hosts.allow
#
# hosts.allow This file describes the names of the hosts which are
# allowed to use the local INET services, as decided
# by the '/usr/sbin/tcpd' server.
#
mountd:10.10.10.100:allow //允许100这个地址使用mount
rpcbind:10.10.10.100:allow //允许100这个地址使用rpcbind
2..NFS Server服务器/etc/hosts.deny中添加如下内容:
[root@zyfw ~]# more /etc/hosts.deny
#
# hosts.deny This file describes the names of the hosts which are
# *not* allowed to use the local INET services, as decided
# by the '/usr/sbin/tcpd' server.
#
# The portmap line is redundant, but it is left to remind you that
# the new secure portmap uses hosts.deny and hosts.allow. In particular
# you should know that NFS uses portmap!
mountd:ALL
rpcbind:ALL
[root@zyfw ~]#
3、保存完成后,不用重启nfs相关服务,在其他未授权的服务器上执行showmount -s IP(NFS服务器的IP地址),会提示如下:
[root@web ~]# showmount -e 10.10.10.100
rpc mount export: RPC: Authentication error; why = Failed (unspecified error)
[root@web ~]#
未保存之前的效果:
[root@web ~]# showmount -e 10.10.10.100
Export list for 10.10.10.100:
/war/rua/webapps 10.10.10.*
/war/sptwl/webapps 10.10.10.*
[root@web ~]#
本文来自博客园,作者:花之旭,转载请注明原文链接:https://www.cnblogs.com/huazhixu/p/16556102.html
【推荐】国内首个AI IDE,深度理解中文开发场景,立即下载体验Trae
【推荐】编程新体验,更懂你的AI,立即体验豆包MarsCode编程助手
【推荐】抖音旗下AI助手豆包,你的智能百科全书,全免费不限次数
【推荐】轻量又高性能的 SSH 工具 IShell:AI 加持,快人一步
· Manus重磅发布:全球首款通用AI代理技术深度解析与实战指南
· 被坑几百块钱后,我竟然真的恢复了删除的微信聊天记录!
· 没有Manus邀请码?试试免邀请码的MGX或者开源的OpenManus吧
· 园子的第一款AI主题卫衣上架——"HELLO! HOW CAN I ASSIST YOU TODAY
· 【自荐】一款简洁、开源的在线白板工具 Drawnix