2.1.16 Ensure rsync service is not installed

Information

The rsync service can be used to synchronize files between systems over network links.

Rationale:

The rsync service presents a security risk as it uses unencrypted protocols for communication. The rsync package should be removed to reduce the attack area of the system.

Solution

Run the following command to remove rsync:

# apt purge rsync

See Also

https://workbench.cisecurity.org/files/3219

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: Unix

Control ID: 736bbeb590fb0af79d5937960b9e53e93f837563518835788a4768d9524fe3ea