2.1.3 Ensure discard services are not enabled

Information

discardis a network service that simply discards all data it receives. This service is
intended for debugging and testing purposes. It is recommended that this service be
disabled.

Rationale:

Disabling this service will reduce the remote attack surface of the system.

Solution

Comment out or remove any lines starting with discard from /etc/inetd.conf and
/etc/inetd.d/* .
Set disable = yes on all discard services in /etc/xinetd.conf and /etc/xinetd.d/* .

See Also

https://workbench.cisecurity.org/files/2420