5.5 Ensure discard is not enabled

Information

discard is a network service that simply discards all data it receives. This service is
intended for debugging and testing purposes. It is recommended that this service be
disabled.

*Rationale*

Disabling this service will reduce the remote attack surface of the system.

Solution

Remove or comment out any discard lines in /etc/inetd.conf-#discard stream tcp nowait root internal

See Also

https://workbench.cisecurity.org/files/91

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1

Plugin: Unix

Control ID: 2e4efe87cd5f98e2d9d5b686ece519f4398e3d8756edd83133cf2e8f537d2523