GEN009250 - The system must not have the PostOffice Protocol (POP3) service active.

Information

The POP3 service is only needed if the server is acting as a mail server and clients are using applications that only support POP3. Users' ids and passwords are sent in plain text to the POP3 service. If mail client access is needed, consider using IMAP or SSL enabled POP3.

Solution

Edit /etc/inetd.conf and comment out POP3 the service line. Restart the inetd service.
# refresh -s inetd

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17(8), CAT|II, CCI|CCI-001436, Rule-ID|SV-38713r1_rule, STIG-ID|GEN009250, Vuln-ID|V-29509

Plugin: Unix

Control ID: 6418261c970d8a219329771d08d60452eb8a23fb85560b8adefbdb7cd8e7048d