Showmount -e target host information disclosure (CVE-1999-0554)

Detailed Description
Can be "showmount -e" operation on the target host, this will be a lot of sensitive information leakage target host, such as directory structure. Worse, if access control is lax, the attacker may have direct access to the data on the target host.
Solution
We recommend that you take the following measures to reduce the threat:
* Limit user can obtain IP and NFS export list.
* Unless absolutely necessary, turn off NFS services, MOUNTD.

Guess you like

Origin www.cnblogs.com/mrhonest/p/10978788.html