4.3 Restrict NFS client requests to privileged ports - Check if 'nfssrv:nfs_portmon' is set to 1 in /etc/system.

Information

Setting this parameter causes the NFS server process on the local system to ignore NFS client requests that do not originate from the privileged port range (ports less than 1024). This should not hinder normal NFS operations but may block some automated NFS attacks that are run by unprivileged users.

See Also

https://workbench.cisecurity.org/files/633

Item Details

Audit Name: CIS Solaris 9 v1.3

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Unix

Control ID: 15e5555f5615537c599d9803001b54861bba4fea20bd4f9584c23c8a87ced95f