GEN009230 - The system must not have the echo service active.

Information

The echo service can be used in Denial of Service or SMURF attacks. It can also used at someone else to get through a firewall or start a data storm. The echo service is unnecessary and it increases the attack vector of the system.

Solution

Edit /etc/inetd.conf and comment out the echo service lines for both TCP and UDP.

Restart the inetd service.
# refresh -s inetd

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R14_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17(8), CAT|II, CCI|CCI-001436, Group-ID|V-29507, Rule-ID|SV-38711r1_rule, STIG-ID|GEN009230, Vuln-ID|V-29507

Plugin: Unix

Control ID: 151026190d5223454417f6cebe984a59b360a3e4efdce55fb6910df3951c89c4