3.3.6 /etc/rc.tcpip - sendmail

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This entry starts the sendmail daemon on system startup. This means that the system can operate as a mail server.

sendmail is a service with many historical vulnerabilities and where possible should be disabled. If the system is not required to operate as a mail server i.e. sending, receiving or processing e-mail, comment out the sendmail entry.

Solution

In /etc/rc.tcpip, comment out the sendmail entry-

chrctcp -d sendmail

See Also

https://workbench.cisecurity.org/files/528