OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Firewall Problem
From: Peter Radcliffe (pirpir.net)
Date: Fri Jun 09 2000 - 10:22:24 CDT


Justin Stanford <jussecurity.za.net> probably said:
> You can kill the portmapper (port 111) in /etc/rc.conf by placing an
> override in there (find the override in /etc/defaults/rc.conf).
>
> Port 6000 is your X server - its best to firewall out 6000.

In this day and age I _strongly_ suggest starting X with '-nolisten tcp'
and using the unix domain socket to talk to the X server. This even
works cleanly with X forwarding over ssh.

This will stop X clients on another machine displaying on your's (unless
you use ssh forwarding) but I never do that anyway ...

P.

-- 
pir                  pirpir.net                    pirnet.tufts.edu

To Unsubscribe: send mail to majordomoFreeBSD.org with "unsubscribe freebsd-security" in the body of the message