3.6.2.1 /etc/mail/sendmail.cf - SmtpGreetingMessage

Information

The recommendation is to change the default sendmail greeting string to not display the sendmail version and other related information.

Rationale:

The sendmail deamon has a history of security vulnerabilities. The recommendation is to change the default sendmail greeting string so as not to display the sendmail version and other related information, which can be used by an attacker for fingerprinting purposes.

Solution

Create a backup copy of /etc/mail/sendmail.cf:

cp -p /etc/mail/sendmail.cf /etc/mail/sendmail.cf.pre_cis

Edit:

vi /etc/mail/sendmail.cf

Replace:

O SmtpGreetingMessage=$j Sendmail $b

With:

O SmtpGreetingMessage=mailerready

Default Value:

SmtpGreetingMessage=$j Sendmail $b




Additional Information:

Reversion:

Copy back the original /etc/sendmail.cf file:

cp -p /etc/mail/sendmail.cf.pre_cis /etc/mail/sendmail.cf

See Also

https://workbench.cisecurity.org/files/4119

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: faa5edcf48a8daa704e3463b2d7915ff3e78993b3447c4de9cca93bd1cb9af1f