3.3.27 /etc/inetd.conf - shell

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This entry starts the rshd daemon when required. This daemon executes a command from a remote system.

This shell service is used to execute a command from a remote server. The username and passwords are passed over the network in clear text and therefore insecurely. Unless required the rshd daemon will be disabled. This function, if required, should be facilitated through SSH.

Solution

In /etc/inetd.conf, comment out the shell entry-

chsubserver -r inetd -C /etc/inetd.conf -d -v 'shell' -p 'tcp6'

See Also

https://workbench.cisecurity.org/files/528