Академический Документы
Профессиональный Документы
Культура Документы
2. Edit the file /lib/svc/method/net-init and add these lines after the ISS generation:
# Don't respond to timestamp requests. This may break rdate on some systems.
/usr/sbin/ndd -set /dev/ip ip_respond_to_timestamp 0
# Combat IP DOS attacks by decreasing the rate at which errors are sent.
/usr/sbin/ndd -set /dev/ip ip_icmp_err_interval 1000
/usr/sbin/ndd -set /dev/ip ip_icmp_err_burst 5
To apply the changes and update the system configuration restart the initial network
service:
3. ONLY on SPARC servers add these two lines to /etc/system to disallow execution of
instructions in the stack. The changes are made effective only after a reboot:
set noexec_user_stack=1
set noexec_user_stack_log=1
4. Change the value of TCP_STRONG_ISS to 2 (/etc/default/inetinit file).