2.1.3 Ensure discard services are not enabled - discard-udp

Information

discard is a network service that simply discards all data it receives. This service is intended for debugging and testing purposes. It is recommended that this service be disabled.

Rationale:

Disabling this service will reduce the remote attack surface of the system.

Solution

Run the following commands to disable discard and discard -udp:

# chkconfig discard off
# chkconfig discard-udp off

See Also

https://workbench.cisecurity.org/files/3738

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|2.6

Plugin: Unix

Control ID: 089e9e0b3c2a97bfe7cae666da7ffd772eaa23e1a063dff9ff37e8304f76d36e