-2.03 Setuid, Setgid 설정
chmod 755 /usr/bin/at
chmod 755 /usr/bin/atq
chmod 755 /usr/bin/atrm
chmod 755 /usr/bin/lpset
chmod 755 /usr/bin/newgrp
chmod 755 /usr/bin/rdist
chmod 755 /usr/dt/bin/dtappgather
chmod 755 /usr/dt/bin/dtprintinfo
chmod 755 /usr/dt/bin/sdtcm_convert
chmod 755 /usr/lib/fs/ufs/ufsdump
chmod 755 /usr/lib/fs/ufs/ufsrestore
chmod 755 /usr/lib/lp/bin/netpr
chmod 755 /usr/openwin/bin/xlock
chmod 755 /usr/platform/sun4u/sbin/prtdiag
chmod 755 /usr/sbin/lpmove
chmod 755 /usr/sbin/sparcv9/prtconf
chmod 755 /usr/sbin/sparcv9/sysdef
-3.01 RPC 서비스 설정
svcadm disable svc:/network/rpc/rstat:default
svcadm disable svc:/network/rpc/rusers:default
svcadm disable svc:/network/rpc-100235_1/rpc_ticotsord:default
svcadm disable svc:/network/rpc-100068_2-5/rpc_udp:default
svcadm disable svc:/network/rpc-100083_1/rpc_tcp:default
-3.02 NFS 설정
svcadm disable svc:/network/nfs/cbd:default
svcadm disable svc:/network/nfs/status:default
svcadm disable svc:/network/nfs/mapid:default
svcadm disable svc:/network/nfs/nlockmgr:default
svcadm disable svc:/network/nfs/client:default
svcadm disable svc:/network/nfs/rquota:default
-3.07 ‘r’ commands 설정
svcadm disable svc:/network/login:rlogin
svcadm disable svc:/network/shell:default
-3.11 기타 서비스 설정
svcadm disable svc:/network/finger:default
svcadm disable svc:/network/ntp:default
-4.01 Inetd Services 로그 설정
inetadm -M tcp_trace=TRUE
inetadm -p
-5.02 FTP UMASK 설정
/var/svc/manifest/network/ftp.xml
exec='/usr/sbin/in.ftpd -a -u 077'
-5.04 SNMP 서비스 설정
svcadm disable svc:/application/management/snmpdx:default
svcadm disable svc:/application/management/sma:default
-5.07 Sendmail 버전 점검
svcadm disable svc:/network/smtp:sendmail
-6.01 /etc/system파일 보안 설정
vi /etc/system
set noexec_user_stack = 1
set noexec_user_stack_log = 1
-6.2 Kernel 파라메터 설정
vi /etc/init.d/inetinit
ndd -set /dev/ip ip_respond_to_echo_broadcast 0
ndd -set /dev/ip ip_forward_directed_broadcasts 0
ndd -set /dev/ip ip_respond_to_timestamp 0
ndd -set /dev/ip ip_respond_to_timestamp_broadcast 0
ndd -set /dev/ip ip_forward_src_routed 0
ndd -set /dev/ip ip_ignore_redirect 1
ndd -set /dev/ip ip_forwarding 0
-6.3 TCP seq. 파라메터 설정
vi /etc/default/inetinit
TCP_STRONG_ISS=1 [변경전]
TCP_STRONG_ISS=2 [변경후]