5.5 Ensure discard is not enabled

Information

discard is a network service that simply discards all data it receives. This service is
intended for debugging and testing purposes. It is recommended that this service be
disabled.

*Rationale*

Disabling this service will reduce the remote attack surface of the system.

Solution

Remove or comment out any discard lines in /etc/inetd.conf-#discard stream tcp nowait root internal

See Also

https://workbench.cisecurity.org/files/91

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1

Plugin: Unix

Control ID: 08fb959d50eb91c70e14194e2ad6a5551bd8ad6298c1847f60d0b6ab4885388d