GEN009340 - Xserver login managers must not be running unless needed for X11 session management.

Information

Running Xservers and X-login managers when not needed for X11 session management increases the attack vector of the system by running unnecessary services.

Solution

Comment out or remove the X login servers from the /etc/inittab file.
#vi /etc/inittab
Refresh the init process.
# init q

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|II, CCI|CCI-001436, Rule-ID|SV-38722r1_rule, STIG-ID|GEN009340, Vuln-ID|V-29518

Plugin: Unix

Control ID: 88434e5d654dea0a3fb90553e1c5e524fe2902d1855f91f97004563690f11108