2.1.8 Ensure telnet server is not enabled

Information

The telnet protocol is insecure and unencrypted. The use of an unencrypted transmission medium could allow a user with access to sniff network traffic the ability to steal credentials. The ssh package provides an encrypted session and stronger security.

Solution

Run the following command to disable telnet - # chkconfig telnet off

See Also

https://workbench.cisecurity.org/files/1863

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1

Plugin: Unix

Control ID: 3833321995ed55f2bd4c6327b9cc44973d7ab6af5ee590faafa7281d6bc045fd