3.1.5.21 rstatd

Information

This entry starts the rstatd daemon. This service is used to provide kernel statistics and other monitorable parameters such as CPU usage, system uptime, network usage etc.

This service should be disabled if not explicitly required by performance monitoring software to collect statistics.

Rationale:

The rstatd service is used to provide kernel statistics and other monitorable parameters pertinent to the system such as: CPU usage, system uptime, network usage etc.

An attacker may use this information in a DoS attack.

Solution

In /etc/inetd.conf, comment out the rstatd entry and refresh the inetd process:

chsubserver -r inetd -C /etc/inetd.conf -d -v 'rstatd' -p udp
lssrc -s inetd && refresh -s inetd

Default Value:

Disabled

See Also

https://workbench.cisecurity.org/files/4119

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: a1f51670af7368ab92c1d9b72056f875e2e75233d942eb5cfdf20acbb71e1206