GEN009200 - The system must not have the daytime service active.

Information

The daytime service runs as root from the inetd daemon and can provide an opportunity for Denial of Service PING or PING-PONG attacks. The daytime service is unnecessary and it increases the attack vector of the system.

Solution

Edit /etc/inetd.conf and comment out daytime service lines for both TCP and UDP protocols.
Restart the inetd service.
# refresh -s inetd

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R13_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|II, CCI|CCI-001436, CSCv6|9.1, Group-ID|V-29504, Rule-ID|SV-38708r1_rule, STIG-ID|GEN009200

Plugin: Unix

Control ID: 7b763ad3bc10feddc2fa400f08358531469212d5ba279b8ed40d9321d49fad25