2.1.1 Ensure chargen services are not enabled - 'chargen-dgram'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

chargen is a network service that responds with 0 to 512 ASCII characters for each connection it receives. This service is intended for debugging and testing purposes. It is recommended that this service be disabled. Disabling this service will reduce the remote attack surface of the system.

Solution

Comment out or remove any lines starting with chargen from /etc/inetd.conf and /etc/inetd.d/*. Set disable = yes on all chargen services in /etc/xinetd.conf and /etc/xinetd.d/*.

See Also

https://benchmarks.cisecurity.org/tools2/linux/CIS_Ubuntu_Linux_14.04_LTS_Benchmark_v2.0.0.pdf

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv6|9.1

Plugin: Unix

Control ID: cb242d9fe859c486189a44e63c8a9f04812b08b16212bbcfe72a8a73b815ce59