GEN004660 - The SMTP service must not have the EXPN feature active.

Information

The SMTP EXPN function allows an attacker to determine if an account exists on a system, providing significant assistance to a brute force attack on user accounts. EXPN may also provide additional information concerning users on the system, such as the full names of account owners.

Solution

Edit the sendmail.cf file and add or edit the following line:
O PrivacyOptions=goaway
Restart the Sendmail service.

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-28402r1_rule, STIG-ID|GEN004660, Vuln-ID|V-4692

Plugin: Unix

Control ID: 88a7e5435f05987697f6493bf44802727bba9cd8439967928143e1c34ffa2466