2.1.6 Ensure rsh server is not enabled - rsh

Information

The Berkeley rsh-server ( rsh , rlogin , rexec ) package contains legacy services that exchange credentials in clear-text.

Rationale:

These legacy services contain numerous security exposures and have been replaced with the more secure SSH package.

Solution

Run the following commands to disable rsh , rlogin , and rexec :

# chkconfig rexec off
# chkconfig rlogin off
# chkconfig rsh off

See Also

https://workbench.cisecurity.org/files/3738

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|2.6

Plugin: Unix

Control ID: 37863f49a5266b14eabf8a67a265a3f17e12f023b986ca297abc1eb0ec84f529