{"id":8682,"date":"2022-03-11T12:36:12","date_gmt":"2022-03-11T17:36:12","guid":{"rendered":"https:\/\/www.rushworth.us\/lisa\/?p=8682"},"modified":"2022-03-11T12:36:27","modified_gmt":"2022-03-11T17:36:27","slug":"brinqa-remediation-mdns","status":"publish","type":"post","link":"https:\/\/www.rushworth.us\/lisa\/?p=8682","title":{"rendered":"Brinqa Remediation &#8211; mDNS"},"content":{"rendered":"<p>Some systems were found to be responding to mDNS requests (5353\/udp). Linux hosts were running the avahi-daemon which provides this service. As the auto-discovery service is not used for service identification, the avahi-daemon was disabled.<\/p>\n<p>Confirm response is seen on 5353\/udp prior to change:<\/p>\n<pre>nmap -P0 -p 5353 -sU hostname.example.net<\/pre>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"718\" height=\"193\" class=\"wp-image-8683\" src=\"https:\/\/www.rushworth.us\/lisa\/wp-content\/uploads\/2022\/03\/word-image.png\" srcset=\"https:\/\/www.rushworth.us\/lisa\/wp-content\/uploads\/2022\/03\/word-image.png 718w, https:\/\/www.rushworth.us\/lisa\/wp-content\/uploads\/2022\/03\/word-image-300x81.png 300w\" sizes=\"auto, (max-width: 718px) 100vw, 718px\" \/><\/p>\n<p>SSH to host identified as responding to mDNS requests. Disable the avahi-daemon then stop the avahi-daemon:<\/p>\n<pre>systemctl disable avahi-daemon\r\nsystemctl stop avahi-daemon<\/pre>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"648\" height=\"256\" class=\"wp-image-8684\" src=\"https:\/\/www.rushworth.us\/lisa\/wp-content\/uploads\/2022\/03\/word-image-1.png\" srcset=\"https:\/\/www.rushworth.us\/lisa\/wp-content\/uploads\/2022\/03\/word-image-1.png 648w, https:\/\/www.rushworth.us\/lisa\/wp-content\/uploads\/2022\/03\/word-image-1-300x119.png 300w\" sizes=\"auto, (max-width: 648px) 100vw, 648px\" \/><\/p>\n<p>Verify that 5353\/udp is no longer open by repeating the nmap command.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"625\" height=\"194\" class=\"wp-image-8685\" src=\"https:\/\/www.rushworth.us\/lisa\/wp-content\/uploads\/2022\/03\/word-image-2.png\" srcset=\"https:\/\/www.rushworth.us\/lisa\/wp-content\/uploads\/2022\/03\/word-image-2.png 625w, https:\/\/www.rushworth.us\/lisa\/wp-content\/uploads\/2022\/03\/word-image-2-300x93.png 300w\" sizes=\"auto, (max-width: 625px) 100vw, 625px\" \/><\/p>\n<p><em>Fin.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Some systems were found to be responding to mDNS requests (5353\/udp). Linux hosts were running the avahi-daemon which provides this service. As the auto-discovery service is not used for service identification, the avahi-daemon was disabled. Confirm response is seen on 5353\/udp prior to change: nmap -P0 -p 5353 -sU hostname.example.net SSH to host identified as &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[30],"tags":[1551,1552,1550,1553,1548,1549],"class_list":["post-8682","post","type-post","status-publish","format-standard","hentry","category-system-administration","tag-avahi","tag-avahi-daemon","tag-brinqa","tag-mdns","tag-security-scan","tag-security-vulnerability"],"_links":{"self":[{"href":"https:\/\/www.rushworth.us\/lisa\/index.php?rest_route=\/wp\/v2\/posts\/8682","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rushworth.us\/lisa\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.rushworth.us\/lisa\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.rushworth.us\/lisa\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rushworth.us\/lisa\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8682"}],"version-history":[{"count":2,"href":"https:\/\/www.rushworth.us\/lisa\/index.php?rest_route=\/wp\/v2\/posts\/8682\/revisions"}],"predecessor-version":[{"id":8687,"href":"https:\/\/www.rushworth.us\/lisa\/index.php?rest_route=\/wp\/v2\/posts\/8682\/revisions\/8687"}],"wp:attachment":[{"href":"https:\/\/www.rushworth.us\/lisa\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8682"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.rushworth.us\/lisa\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8682"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rushworth.us\/lisa\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8682"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}