2.1.8 Ensure telnet server is not enabled

Information

The telnet-server package contains the telnet daemon, which accepts connections from users from other systems via the telnet protocol.

Rationale:

The telnet protocol is insecure and unencrypted. The use of an unencrypted transmission medium could allow a user with access to sniff network traffic the ability to steal credentials. The ssh package provides an encrypted session and stronger security.

Solution

Run the following command to disable telnet:

# chkconfig telnet off

See Also

https://workbench.cisecurity.org/files/3738

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 2a80157e28a9a9730b8c68a25abc3619bf8727b6b6fcdef6f6ac46371a8cdbd1