2.1.3 Ensure discard services are not enabled - discard-dgram

Information

discard is a network service that simply discards all data it receives. This service is intended for debugging and testing purposes. It is recommended that this service be disabled.

Rationale:

Disabling this service will reduce the remote attack surface of the system.

Solution

Run the following commands to disable discard -dgram and discard -stream:

# chkconfig discard-dgram off
# chkconfig discard-stream off

See Also

https://workbench.cisecurity.org/files/3152

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1, CSCv7|9.2

Plugin: Unix

Control ID: 42cb618acbcf46126d10d12051965648ebdae038e9a39f777fa6e9c7249dc844