GEN003840 - The rexec daemon must not be running.

Information

The rexecd process provides a typically unencrypted, host-authenticated remote access service. SSH should be used in place of this service.

Solution

Edit /etc/inetd.conf and comment out the line for the rexec service.
Refresh the inetd daemon.
# refresh -s inetd

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R14_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17(8), CAT|I, CCI|CCI-001435, Group-ID|V-4688, Rule-ID|SV-38878r1_rule, STIG-ID|GEN003840, Vuln-ID|V-4688

Plugin: Unix

Control ID: a8f452c2e6503d30d7b2a526f0229b2b79a0e4027aaeb145472ddbe031f03574