Subject: dump(): request from unauthorized host
To: Pmax Netbsd Mailing List <port-pmax@netbsd.org>
From: Douglas S. Meade <doug@umd.edu>
List: port-pmax
Date: 11/15/1999 12:45:33
Perhaps this question should be on another list, but I thought it might
be of interest to others on this list. 

I have several NetBSD pmax machines on the University of Maryland 
network.  Checking the log files of each reveals a consistent 
pattern of the following (attempted?) exploits:

<machine name> portmap[ <pid> ] connect from < outside ip addr. > to 
    dump(): request from unauthorized host.

Is this an exploit that others of you have dealt with?  I've got
portmapper turned on for NFS mounts, and I thought I had outside 
connections turned off in hosts.deny.  How, then, are they making
the connection to portmap.  

My apologies if this post is on the wrong list.

Doug