From HP-UX 11.31 Security Technical Implementation Guide
Part of GEN003900
Associated with IA controls: ECCD-2, ECCD-1
Associated with: CCI-000366
Having the "+" character in the hosts.lpd (or equivalent) file allows all hosts to use local system print resources.
Look for the presence of a print service configuration file. The hosts.lpd file is not used on HP, only inetd.sec, hosts.equiv, and/or the system (lp) .rhosts will apply.
When rlpdaemon is started via inetd, access control is provided via the fileinetd.sec to allow or prevent a host from making print requests.
When rlpdaemon is started at boot via a run command file, all requests must come from one of the machines listed in the file /etc/hosts.equiv or /var/spool/lp/.rhosts.
Procedure:
First, determine the rlpdaemon startup method:
1) Print services started via inetd?
# cat /etc/inetd.conf | grep -v "^#" | grep -c rlpdaemon
If the above command return value is 1, check the services file.
# cat /etc/services | grep -v "^#" | grep printer | grep -c spooler
If the above command return value is 1, check the inetd.sec file.
# cat /var/adm/inetd.sec | grep -v "^#" | tr '\011' ' ' | tr -s ' ' | grep printer | grep allow | grep -c "\+"
If the above command return value is 1, this is a finding.
2) The rlpdaemon is started as a service, and not via inetd. Verify neither the /etc/hosts.equiv nor /var/spool/lp/.rhosts contains a "+":
# cat /etc/hosts.equiv | grep -v "^#" | grep -c "\+"
# cat /var/spool/lp/.rhosts | grep -v "^#" | grep -c "\+"
If the return value of either of the above two command(s) is 1, this is a finding.
If none of the files are found, this check should be marked not a finding.
Otherwise, examine the configuration file.
# more
Remove the "+" entries from the hosts.lpd (or equivalent) file.
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer