2.1.21 Ensure talk server is not enabled

Information

The talk software makes it possible for users to send and receive messages across systems through a terminal session. The talk client (allows initiate of talk sessions) is installed by default.

Rationale:

The software presents a security risk as it uses unencrypted protocols for communication.

Solution

Run the following command to disable talk:

# systemctl stop ntalk ntalk.socket
# systemctl disable ntalk ntalk.socket

See Also

https://workbench.cisecurity.org/files/2449

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1, CSCv7|9.2

Plugin: Unix

Control ID: c20455d03ebba728f9be7b9d3e6baef61b97b1235946d6cbb8f10db8ef50c7f4