GEN003840 - The rexec daemon must not be running.

Information

The rexecd process provides a typically unencrypted, host-authenticated remote access service. SSH should be used in place of this service.

Solution

Edit /etc/inetd.conf and comment out the line for the rexec service.
Refresh the inetd daemon.
# refresh -s inetd

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17(8), CAT|I, CCI|CCI-001435, Rule-ID|SV-38878r1_rule, STIG-ID|GEN003840, Vuln-ID|V-4688

Plugin: Unix

Control ID: 73531d5a375c599718f8f5d0ecbc78c93db4f6a5a086b19265a2ff4bb0672ccc