3.1.5.5 discard

Information

This entry starts the discard service when required. This service is used as a debugging tool by setting up a listening socket which ignores the data it receives.

Rationale:

The discard service is used as a debugging and measurement tool. It sets up a listening socket and ignores data that it receives. This is a /dev/null service and is obsolete. This can be used in DoS attacks and therefore, must be disabled.

Solution

In /etc/inetd.conf, comment out the discard entry and refresh the inetd process:

chsubserver -r inetd -C /etc/inetd.conf -d -v 'discard' -p udp
lssrc -s inetd && refresh -s inetd

Default Value:

Commented out

See Also

https://workbench.cisecurity.org/files/4119

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 13b1f8fd153eec9dcb9c91229e08b1a0594b353eaef17206880ac4a5a882a1b3