Solved

is it possible to stop nfs shares from reporting any information about the shares

Posted on 2011-09-13
3
296 Views
Last Modified: 2012-06-21
I have two nfs shares between a as400 and 2 linux serves.  The rhel5 serves will answer a query with the ip address shares.  Is there anyway to have the shares run without telling any computer that they are running?

In other words a stealth share that one can use only if he already knows that it is there.

gary
0
Comment
Question by:javagair
  • 2
3 Comments
 
LVL 21

Accepted Solution

by:
Papertrip earned 500 total points
ID: 36532658
You might be able to accomplish this with TCP wrappers.

First, in /etc/hosts.deny, add
portmap: ALL
rpc.mountd: ALL
rpc.rquotad: ALL

Open in new window


Then, in /etc/hosts.allow, add
portmap: your.ip.address or.your.hostname
rpc.mountd:  your.ip.address or.your.hostname
rpc.rquotad: your.ip.address or.your.hostname

Open in new window

like
rpc.mountd:  192.168.1.1
rpc.rquotad: bob.domain.com

Open in new window



Then restart the NFS server.

I'm not sure if this is going to work, I've never come across the need for this before.  If this way doesn't work, then I don't think it's possible.  Perhaps someone else knows more, but try my idea first.
0
 

Author Comment

by:javagair
ID: 36537463
the reason I asked the question is we got written up on a vulnerability report because they could see which ip address where connected to the nfs shares.

gary
0
 

Author Closing Comment

by:javagair
ID: 36545129
I am accepting this as the answer because after reading this I checked linux information on these subjects and the information appears to correct.  I would have liked to wait till the next vulnerability test was run but that is not for 30 days and questions don't stay open that long.

gary
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Nfsen sflow support. 10 146
ovirt web management page 1 78
Help with Ubuntu 14.04 LTS 10 135
Ubuntu Server 14.04.3 LS Cleanup Boot Partition 9 142
In order for businesses to be compliant with certain information security laws in some countries, you need to be able to prove that a user (which user it was becomes important to the business to take action against the user after an event has occurr…
The purpose of this article is to show how we can create Linux Mint virtual machine using Oracle Virtual Box. To install Linux Mint we have to download the ISO file from its website i.e. http://www.linuxmint.com. Once you open the link you will see …
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

831 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question