2.1.18 Ensure telnet server is not enabled - status

Information

The telnet-server package contains the telnet daemon, which accepts connections from users from other systems via the telnet protocol.

Rationale:

The telnet protocol is insecure and unencrypted. The use of an unencrypted transmission medium could allow a user with access to sniff network traffic the ability to steal credentials. The ssh package provides an encrypted session and stronger security.

Solution

Run the following command to disable telnet:

# systemctl disable telnet.socket
# systemctl stop telnet.socket

See Also

https://workbench.cisecurity.org/files/2449

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: Unix

Control ID: f0fbc3ed0eb1f970c135eae545e2598b8252951594a265b2be8c7259cfc04ee9