4.7.4.2 Ensure sendmail PrivacyOptions is configured

Information

The recommendation is to ensure that PrivacyOptions includes at least three settings:

- authwarnings (a default)
- novrfy
- noexpn

The sendmail deamon has a history of security vulnerabilities. The recommendation is to modify default sendmail settings that otherwise may provide information that can be used by an attacker.

- novrfy: No Verify: do not verify valid email addresses. This can be used by attackers, e.g., phishing attacks.
- noexpn: no expansion: do not verify/expand email list addresses - providing attackers with a list of valid email addresses.

Solution

Create a backup copy of /etc/mail/sendmail.cf :

cp -p /etc/mail/sendmail.cf /etc/mail/sendmail.cf.pre_cis

Edit:

vi /etc/mail/sendmail.cf

Replace:

O PrivacyOptions=authwarnings

With:

O PrivacyOptions=authwarnings,noexpn,novrfy

Or - append noexpn,novrfy at then end of the current PrivacyOptions settings (assuming authwarnings is already included).

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Unix

Control ID: dcf1e1040ad0586b03cb859b93ea04ae1c754148ab8f5749e71fe8494fb6a6cb