4.5.19 Ensure icmptimestamp is disabled

Information

The icmptimestamp parameter determines whether the system responds to an ICMP timestamp request.

Responding to an ICMP timestamp request may provide a remote user with more detailed information about the current date/time of the system. By accurately determining the target's clock state, an attacker can more effectively attack certain time-based pseudorandom number generators (PRNGs) and the authentication systems that rely on them

Solution

Run the following command to set the icmptimestamp entry:

no -p -o icmptimestamp=0

See Also

https://workbench.cisecurity.org/benchmarks/22751

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 994212ba517bcb98302f755b92ed0f7eff011da6d82d5cbb2beee1c8d024abca