Korean
<< Back
VID 17038
Severity 20
Port 111
Protocol TCP,UDP
Class RPC
Detailed Description The statmon service is running. Statmon (or status monitor) uses statd and lockd to provide the crash and recovery functions for the locking services on NFS.

* References:
http://www.iss.net/security_center/static/274.php
Recommendation If you do not use this service, then disable it as it may become a security threat in the future, if a vulnerability is discovered.
To disable 'statmon' service,
first, you become a root, and then stop the service like the following:

# rpcinfo -d [program num] [version num]

And comment its entry by putting a # at the beginning of the line and revoke 'inetd' daemon.

Solaris 10, Solaris 11, Enterprise Linux 6.4, CentOS 6.4, Fedora 19:
1. you become a root, and then stop the service like the following:

# rpcinfo -d [program num] [version num]

2. comment its entry by putting a # at the beginning of the line with 'statmon' in /etc/rpc
3. # pkill -HUP (x)inetd
Related URL (CVE)
Related URL (SecurityFocus)
Related URL (ISS)