2.1.6 Ensure rsh server is not enabled - rlogin

Information

The Berkeley rsh-server (rsh, rlogin, rexec) package contains legacy services that exchange credentials in clear-text. These legacy services contain numerous security exposures and have been replaced with the more secure SSH package.

Solution

Run the following commands to disable rsh, rlogin, and rexec: # chkconfig rexec off# chkconfig rlogin off# chkconfig rsh off

See Also

https://workbench.cisecurity.org/files/1865

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1

Plugin: Unix

Control ID: ac0622db8f7266d7a19e28b4890b7213a6f43e70a8a5425970ea75f33581d040