6.7 Ensure NFS and RPC are not enabled - /etc/rc*.d

Information

The Network File System (NFS) is one of the first and most widely distributed file systems
in the UNIX environment. It provides the ability for systems to mount file systems of other
servers through the network.

*Rationale*

If the server does not export NFS shares or act as an NFS client, it is recommended that
these services be disabled to reduce remote attack surface.

Solution

Remove or comment out start lines in /etc/init/rpcbind-boot.conf-#start on virtual-filesystems and net-device-up IFACE=lo
Remove any start links for nfs-kernel-server from /etc/rc*.d-# rm /etc/rc*.d/S*nfs-kernel-server

See Also

https://workbench.cisecurity.org/files/91

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1

Plugin: Unix

Control ID: 96e8c6e24ce1e740a73c19bfdc9cf6e3b4840bbecd2a52722dd0a9b167cea4b3