summaryrefslogtreecommitdiff
path: root/etc/inetd.conf
AgeCommit message (Collapse)Author
2002-07-155 new uid/gid sets; millert okTheo de Raadt
2002-06-28go back to running these as root from inetd. however once rpc.{rusersd,rstatd}Theo de Raadt
starts, do a chroot to /var/empty and change to user nobody. hi mom, i'm in jail!
2002-06-05try to avoid DNS hereTheo de Raadt
2002-05-30space nitsTheo de Raadt
2002-05-24Not that kvm parts are removed, run rpc.rstatd and rpc.rusers asTheo de Raadt
nobody. While I do not like running things as nobody since the step up is very small, we use this for other daemons in inetd. And it is still a small step.
2002-05-06rlogind and rexecd are historyTodd C. Miller
2002-05-02localhost:comsat appears to work. might be DNS issues, but only if we ↵Theo de Raadt
deploy it can we see such issues
2002-02-01make tftpd address family independent.Jun-ichiro itojun Hagino
2001-09-25popa3d piecesTheo de Raadt
2001-04-14Remove the -o flag from identd's default invocation as it serves only toHugh Graham
obfuscate, and confuses some software. derradt + millert concur.
2001-03-08integrate IPv6 items into the list of IPv4 items, to avoidJun-ichiro itojun Hagino
them from going out of sync (like additional option flag to daemon).
2000-12-19add identd example for tcp6Todd T. Fries
2000-10-11disable talkd and fingerd by default, what the heck, they are less used ↵Theo de Raadt
these days
2000-02-09add rshd/rlogind for tcp6 cases.Jun-ichiro itojun Hagino
1999-12-11add fingerd on tcp6.Jun-ichiro itojun Hagino
1999-12-11add telnetd on tcp6 (commented out).Jun-ichiro itojun Hagino
1999-12-08sample entry for IPv6 ftp.Jun-ichiro itojun Hagino
1999-09-26disable telnet/ftp/login by default, for nowTheo de Raadt
1999-04-10rsh off by defaultTheo de Raadt
1998-12-19squish program args together moreTheo de Raadt
1998-07-24remove unused kerberos entriesArtur Grabowski
1998-07-13run fingerd -m by defaultTheo de Raadt
1998-06-22the -x option to rshd does not existArtur Grabowski
1998-06-10identd should be nowait.Bob Beck
1998-06-10to inetd, nobody.nobody == nobody, since it does an initgroups()Theo de Raadt
1998-06-10take away gid kmem for identd and change to options appropriate for new versionBob Beck
1998-04-02add #kx; and reindent what art failed to indent!Theo de Raadt
1998-02-18add encrypted rsh and kauthd (kerberos)Artur Grabowski
1998-02-10disable kerberos login tools by defaultTheo de Raadt
1998-02-07 Take out smtp line - users can add if neededBob Beck
1998-02-07 Flags and startup for smtpd/smtpfwdd - not enabled by default.Bob Beck
1997-12-24use group nobody for fingerdTheo de Raadt
1997-04-23even more local services must dieTheo de Raadt
1997-02-16do not suggest mountd can run out of inetd.conf; the code was never finishedTheo de Raadt
1996-11-09By default, run telnetd with -k (no auto kludge)Jason Downs
1996-09-23trash other internal udp spoofable serviecs by defaultTheo de Raadt
1996-09-23disable udp echo/chargen by default; avoid DOS attacksTheo de Raadt
1996-09-22We support vesion 1 of rusers too nowThorsten Lockert
1996-09-13fingerd -ls; shut down tftpTheo de Raadt
1996-08-10ftpd -US; create /var/log/ftpd for wu-style log filesTheo de Raadt
1996-07-31explicitly run identd as nobody.kmem; this solves ptrace problem tooTheo de Raadt
1996-07-29ftpd -UlTheo de Raadt
1996-06-25default to logging rsh connectionsTheo de Raadt
1996-05-26sync & labelTheo de Raadt
1996-02-27Identd ras as nobody.kmem. Changed it to root.dm
Running anything as nobody.kmem allows any "nobody" process to get into the kmem group through ptrace(). Kmem is a privileged enough group that we might as well just run identd as root.
1996-01-02there is no such thing as "nntpd"Theo de Raadt
also, always enable identd -- many things expect it now
1995-12-17Enable non-master kerberos services by defaultThorsten Lockert
1995-11-26enable tftp as it has security builtin;Theo de Raadt
disable walld/1 by default for security (as pointed out by Chris Cappuccio)
1995-10-18initial import of NetBSD treeTheo de Raadt