5.2 Ensure chargen is not enabled

Information

chargen is a network service that responds with 0 to 512 ASCII characters for each
connection it receives. This service is intended for debugging and testing purposes. It is
recommended that this service be disabled.

*Rationale*

Disabling this service will reduce the remote attack surface of the system.

Solution

Remove or comment out any chargen lines in /etc/inetd.conf-
#chargen stream tcp nowait root internal

See Also

https://workbench.cisecurity.org/files/91

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1

Plugin: Unix

Control ID: d99ad6d871c987aa76e91ebcddea2c7653aff8471f4b7ecd62eda52641d2798b