4.1.5.15 netstat

Information

This entry executes the command netstat -f inet. This service is displays active IP connections on a server.

The recommendation is to leave this disabled.

Rationale:

The netstat command symbolically displays the contents of various network-related data structures for active connections.

This interface requests a report of statistics or address control blocks to those items specified by the inet aka AF_INET (ipv4) address family.

Solution

In /etc/inetd.conf, comment out the netstat entry:

chsubserver -r inetd -C /etc/inetd.conf -d -v 'netstat' -p 'tcp'
refresh -s inetd

Default Value:

Disabled

See Also

https://workbench.cisecurity.org/benchmarks/13069

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: Unix

Control ID: 626de57565637481ac5a3f0818754287d8a630a7962b869d4e8519da1b07fe41