5.2 Ensure chargen is not enabled

Information

chargen is a network service that responds with 0 to 512 ASCII characters for each
connection it receives. This service is intended for debugging and testing purposes. It is
recommended that this service be disabled.

*Rationale*

Disabling this service will reduce the remote attack surface of the system.

Solution

Remove or comment out any chargen lines in /etc/inetd.conf-
#chargen stream tcp nowait root internal

See Also

https://workbench.cisecurity.org/files/91

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1

Plugin: Unix

Control ID: d8699db900953ed6e3cb7e991196d9d3f821dbd6ae97040a2855dc57b0a649bf