2.1.3 Ensure discard services are not enabled

Information

discard is a network service that simply discards all data it receives. This service is intended for debugging and testing purposes. It is recommended that this service be disabled. Disabling this service will reduce the remote attack surface of the system.

Solution

Run the following commands to disable discard and discard-udp: # chkconfig discard off# chkconfig discard-udp off

See Also

https://workbench.cisecurity.org/files/1865

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1

Plugin: Unix

Control ID: d46bec78678cef1eff1cc22e270c63e82a21bfb6328a472f57d7ae4ea97d4f09