2.1.6 Ensure rsh server is not enabled - rexec

Information

The Berkeley rsh-server ( rsh , rlogin , rexec ) package contains legacy services that
exchange credentials in clear-text.

Rationale:

These legacy services contain numerous security exposures and have been replaced with
the more secure SSH package.

Solution

Comment out or remove any lines starting with shell , login , or exec from
/etc/inetd.conf and /etc/inetd.d/* .
Set disable = yes on all rsh , rlogin , and rexec services in /etc/xinetd.conf and
/etc/xinetd.d/* .

See Also

https://workbench.cisecurity.org/files/2420

Item Details

Category: IDENTIFICATION AND AUTHENTICATION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|IA-2(1), 800-53|SI-4, CSCv6|3.4, CSCv6|9.1, CSCv7|4.5, CSCv7|9.2

Plugin: Unix

Control ID: 831ea9e30fae99835936897b0a7fc494e991d29e9e23052fbdc65032a9478970