AIX7-00-003005 - AIX must disable /usr/bin/rcp, /usr/bin/rlogin, /usr/bin/rsh, /usr/bin/rexec and /usr/bin/telnet commands - telnet

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The listed applications permit the transmission of passwords in plain text. Alternative applications such as SSH, which encrypt data, should be use instead.

Solution

Use the chmod command to remove all permissions on these commands:
# chmod ugo= /usr/bin/rcp
# chmod ugo= /usr/bin/rlogin
# chmod ugo= /usr/bin/rsh
# chmod ugo= /usr/bin/rexec
# chmod ugo= /usr/bin/telnet

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_IBM_AIX_7-x_V2R5_STIG.zip

Item Details

References: CAT|I, CCI|CCI-000197, Rule-ID|SV-215322r508663_rule, STIG-ID|AIX7-00-003005, STIG-Legacy|SV-101393, STIG-Legacy|V-91295, Vuln-ID|V-215322

Plugin: Unix

Control ID: 846ab16f1b0d2c18c20ae8ef4ea86291e754c5f6c34703d1d79039341ed86b8a