Commit Graph

33 Commits

Author SHA1 Message Date
dillon
7031b69d1e comsat sandbox prevents biff/comsat from being able to print partial
mailbox contents.  comsat instead simply prints that new mail is
    available.  Add appropriate comment to inetd.conf but leave comsat in
    sandbox.
1998-12-01 22:01:59 +00:00
dillon
12b32d0e17 Added group bind(53), added sandbox users tty(4), kmem(5), and bind(53),
adjustd inetd.conf to run comsat and ntalk from tty sandbox, and
    the (commented out) ident from the kmem sandbox.

    Note that it is necessary to give each group access it's own uid to
    prevent programs running under a single uid from being able to gdb
    or otherwise mess with other programs (with different group perms) running
    under the same uid.
1998-12-01 21:19:49 +00:00
phk
c5f22a4fdf Add example for the internal "ident server". 1998-11-04 19:42:35 +00:00
wosch
f856b3bfee Limit the fingerd daemon to:
runs only 3 simultaneous fingerd processes and
        limit the connections-per-ip-per-minute to 10.
1998-09-30 16:12:40 +00:00
brian
53ce9b5024 Add Id keywords 1998-09-02 01:34:57 +00:00
markm
bd3587a0bf Clean up the kerberos entries, and add example CVS entries 1998-08-15 17:32:27 +00:00
hoek
2fbfcdc516 MFC: sample qmail entry. 1998-07-18 20:01:03 +00:00
jkh
42008a0193 Restore the Samba entries which were spammed when someone added
the imap4 entry.
1997-09-28 22:25:29 +00:00
ache
f95ee18036 Add commented out example entry for imap4 1997-01-12 17:55:16 +00:00
peter
7134c99b53 The kerberised network services should only be active in inetd.conf
if kerberos is installed.  So far as I'm aware, kerberos aware clients
detect ECONNREFUSED and (if allowed) fall back to the non-kerberos
servers.  They do not know how to interpret messages such as
"rlogind: unknown option -k".

I believe Garrett also mentioned this.

Unfortunately, this adds an extra step to bringing up kerberos.

It also stops /var/log/messages getting quite so many useless (and
confusing) error messages when somebody does a port scan on you.
1996-11-10 13:06:14 +00:00
pst
14627fbd27 In the brave new world, that that does not make us strong, kills us.
Turn OFF the "small servers" by default.  FreeBSD systems should only
serve actively used programs.  Jewels like chargen and echo are too
useful in attack scenarios.
1996-10-02 03:52:58 +00:00
phk
c56be07b2d Add commented out example for bootps 1996-09-19 08:19:25 +00:00
graichen
624e971113 changed /etc/[daily,weekly,monthly] to not rotate the logfiles by
"hand", changed /etc/crontab to call /usr/sbin/newsyslog every hour
(the entry was there before - but we haven't had any newsyslog until
today :-) and changed /etc/inetd.conf to also contain (commentet out)
entries for rpc.rquotad and rpc.sprayd (taken from NetBSD)
1996-01-05 10:09:13 +00:00
joerg
3900b47e4e Add /tftpboot as an argument to the commented-out example for tftp, so
people don't compromise their system by blindly un-commenting the
entry.
1995-12-23 17:12:49 +00:00
gibbs
2221ea6581 inetd.conf:
Add rkinit at 2108/tcp.

services:
Add rkinitd.
1995-09-15 22:02:06 +00:00
ache
30e31eb73a Restore tabs in inetd line
Submitted by:
Obtained from:
1995-07-29 22:22:08 +00:00
ache
da416ccfe0 Rename in.identd -> identd according recent ports rename 1995-07-27 23:56:43 +00:00
ache
3342359329 Add ident (commented out) 1995-04-08 16:21:45 +00:00
wollman
c9ad65f32a Disable UDP echo, chargen, date, and daytime services. 1994-12-21 20:32:44 +00:00
ache
969667ba20 Uncomment uucpd by default, it is working and secure now 1994-12-19 01:11:19 +00:00
ats
82eb2b5607 Change the example line for popper to point to /usr/local/libexec/popper
instead of /usr/local/etc/popper. The 2.0 installation installs it there.
1994-11-18 20:01:21 +00:00
pst
e5889daca3 Secure fingerd by default 1994-09-29 09:58:07 +00:00
pst
fb7a7444ee Disable rexecd by default (major security hole) 1994-09-29 09:20:40 +00:00
pst
6cf567e0b4 Add an entry for pcnfsd (commented out) 1994-09-28 17:09:38 +00:00
wollman
b744cddb1e Added comment about registerd and kpasswdd not working in 1.x.
Deleted commented-out line which would start mountd; that's not
the right pplace to do it (don't confuse the users).
Should probablyhave uncommented rpc.rstatd, but didn't.
1994-06-13 22:41:04 +00:00
ache
8fcc804f24 Comment out uucpd, not properly configured as default
Comment out walld/rusersd/rstatd, may be too verbose
1994-05-31 17:55:38 +00:00
ache
f6d7255fb6 Uncomment uucpd, now it works
Uncomment rstatd/rusersd/rwalld all three worked
mountd still commented out, I remember some problem with it
1994-05-31 04:48:49 +00:00
ats
bb980903cb Added entries for sup into services.
Added an example entry for the pop3 popper into inetd.conf as a comment.
1993-12-05 16:39:47 +00:00
rgrimes
b9ec1a9ac4 Change space to tab in ruserd line per Guido van Rooij 1993-10-21 17:34:32 +00:00
rgrimes
00bed1b631 Disable rpc services so that inetd no longer hangs when you are not
running portmapper.  These are site specific functionality and should only
be enabled for sites that want them, not by default.

These services REQUIRE portmapper to be running
1993-10-13 06:32:06 +00:00
jtc
6882311f51 Entries so RPC servers are started. 1993-09-23 17:41:08 +00:00
rgrimes
65fc4ac297 Added /etc/networks to the files that get installed, some how it got
dropped out of the Makefile.  Commented out talk in inetd.conf since
it refers to the old non-existent otalkd.
1993-09-02 11:10:02 +00:00
rgrimes
241ccdeaf3 Initial import of 386BSD 0.1 othersrc/etc 1993-06-20 13:41:45 +00:00