3.1.5.15 netstat

Information

This entry executes the command netstat -f inet. This service is displays active IP connections on a server.

The recommendation is to leave this disabled.

Rationale:

The netstat command symbolically displays the contents of various network-related data structures for active connections.

This interface requests a report of statistics or address control blocks to those items specified by the inet aka AF_INET (ipv4) address family.

Solution

In /etc/inetd.conf, comment out the netstat entry:

chsubserver -r inetd -C /etc/inetd.conf -d -v 'netstat' -p 'tcp'
refresh -s inetd

Default Value:

Disabled

See Also

https://workbench.cisecurity.org/files/4119

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 6f96e1e49bf321da220dde80703a191f251aed4e2e4960542761439ee283f929