GEN009270 - The system must not have the netstat service active on the inetd process.

Information

The netstat service can potentially give out network information on active connections if it is running. The information given out can aid in an attack and weaken the systems defensive posture.

Solution

Edit /etc/inetd.conf and comment out the netstat service line.

Restart the inetd service.
# refresh -s inetd

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R14_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17(8), CAT|II, CCI|CCI-001436, Group-ID|V-29511, Rule-ID|SV-38715r1_rule, STIG-ID|GEN009270, Vuln-ID|V-29511

Plugin: Unix

Control ID: 42df6ac5832eb27ea8438c42e793bc63ad4df7a2648b1e72c0c404d46d854329