2.1.17 Ensure rsh server is not enabled - rsh.socket status

Information

The Berkeley rsh-server ( rsh , rlogin , rexec ) package contains legacy services that exchange credentials in clear-text.

Rationale:

These legacy services contain numerous security exposures and have been replaced with the more secure SSH package.

Solution

Run the following commands to disable rsh , rlogin , and rexec :

# systemctl disable rsh.socket
# systemctl disable rlogin.socket
# systemctl disable rexec.socket

# systemctl stop rsh.socket
# systemctl stop rlogin.socket
# systemctl stop rexec.socket

See Also

https://workbench.cisecurity.org/files/2449

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv7|9.2

Plugin: Unix

Control ID: 905b24c15b4821716e05f35ff7b2f15e01a02555c7d5cc3bd21f6950bc405f69