Item Search

NameAudit NamePluginCategory
GEN003540 - The system must implement non-executable program stacks.DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

GEN003602 - The system must not process ICMP timestamp requests.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003609 - The system must ignore IPv4 ICMP redirect messages.DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

GEN003612 - The system must be configured to use TCP syncookies when experiencing a TCP SYN flood.DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

GEN003640 - The root file system must employ journaling or another mechanism ensuring file system consistencyDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003660 - The system must log authentication informational data - 'auth.notice'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN003700 - Inetd and xinetd must be disabled or removed if no network services utilizing them are enabledDISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN003720 - The inetd.conf file, xinetd.conf file, and the xinetd.d directory must be owned by root or bin - 'xinetd.d'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN003730 - The inetd.conf file, xinetd.conf file, and the xinetd.d directory must be group-owned by bin, sys, or system - 'inetd.conf'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN003790 - The services file must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003820 - The rsh daemon must not be running.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN003840 - The rexec daemon must not be running.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN003865 - Network analysis tools must not be installed - 'ethereal'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN003930 - The hosts.lpd (or equivalent) file must be group-owned by bin, sys, or system.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN003950 - The hosts.lpd (or equivalent) file must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN004370 - The aliases file must be group-owned by sys, bin, or system.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN004410 - Files executed through a mail aliases file must be group-owned by root, bin, sys, or other.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN004440 - Sendmail logging must not be set to less than nine in the sendmail.cf file.DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN004460 - The system syslog service must log informational and more severe SMTP service messages.DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN004500 - The SMTP service log file must have mode 0644 or less permissive.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN004540 - The SMTP service HELP command must not be enabled.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN004700 - The Sendmail service must not have the wizard backdoor active.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN004980 - The FTP daemon must be configured for logging or verbose mode - '/etc/syslog.conf contains daemon.info or *.info'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN005080 - The TFTP daemon must operate in 'secure mode' which provides access only to a single directory on the host file system.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN005100 - The TFTP daemon must have mode 0755 or less permissive.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN005120 - The TFTP daemon must be configured to vendor specs including a home directory owned by the TFTP user - 'tftp user exists'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN005120 - The TFTP daemon must be configured to vendor specs including a home directory owned by the TFTP user - 'tftp user shell'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN005360 - The snmpd.conf file must be owned by root - '/etc/snmpdv3.conf'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN005450 - The system must use a remote syslog server (log host).DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN005507 - SSH daemon must be configured to only use MACs employing FIPS 140-2 approved cryptographic hash algorithmsDISA AIX 5.3 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

GEN005511 - The SSH client must be configured to not use CBC-based ciphers.DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

GEN005533 - The SSH daemon must limit connections to a single session.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN005540 - The SSH daemon must be configured for IP filtering - '/etc/hosts.deny'DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

GEN005560 - The system must be configured with a default gateway for IPv4 if the system uses IPv4, unless the system is a router.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN005820 - The NFS anonymous UID and GID must be configured to values without permissions.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN006150 - The /usr/lib/smb.conf file must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN006330 - The /etc/news/passwd.nntp file must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN006380 - The system must not use UDP for NIS/NIS+.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN006565 - The system package management tool must be used to verify system software periodically.DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

GEN006575 - The file integrity tool must use FIPS 140-2 approved cryptographic hashes for validating file contents.DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

GEN006600 - The system's access control program must log each system access attempt - 'auth.info'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN006600 - The system's access control program must log each system access attempt - 'mail.debug'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN006600 - The system's access control program must log each system access attempt - 'mail.none'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN006640 - The system must use and update a DoD-approved virus scan program - 'clean.dat'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN006640 - The system must use and update a DoD-approved virus scan program - 'clean.dat' - update dateDISA AIX 5.3 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

GEN006640 - The system must use and update a DoD-approved virus scan program - 'names.dat'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN006640 - The system must use and update a DoD-approved virus scan program - 'names.dat' - update dateDISA AIX 5.3 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

GEN007480 - The Reliable Datagram Sockets (RDS) protocol must be disabled or not installed unless required.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN007760 - Proxy Neighbor Discovery Protocol (NDP) must not be enabled on the system.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN007820 - The system must not have IP tunnels configured - 'ifconfig -a'DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION