4.3.4.19 Ensure rlogin daemon is not in use

Information

This entry starts the rlogin daemon when required. This service authenticates remote user logins.

This login service is used to authenticate a remote user connection when logging in via the rlogin command. The username and password are passed over the network in clear text and therefore insecurely. Unless required the rlogin daemon will be disabled. This function, if required, should be facilitated through SSH.

Solution

In /etc/inetd.conf, comment out the rlogin entry and refresh the inetd process:

# /usr/sbin/chsubserver -r inetd -C /etc/inetd.conf -d -v 'login' -p tcp6
# /usr/bin/lssrc -s inetd && refresh -s inetd

See Also

https://workbench.cisecurity.org/benchmarks/22751

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: Unix

Control ID: c54a97c51a0d8393a931d83f8c022ecb5e1370b73879544fdd8a1f34bb746b7a