GEN004560 - The SMTP service's SMTP greeting must not provide version information.

Information

The version of the SMTP service can be used by attackers to plan an attack based on vulnerabilities present in the specific version.

Solution

Ensure Sendmail or its equivalent has been configured to mask the version information. If necessary, change the O SmtpGreetingMessage line in the /etc/sendmail.cf file.

O SmtpGreetingMessage=$j Sendmail $v/$Z; $b

Change it to:

O SmtpGreetingMessage= Mail Server Ready ; $b

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R14_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Group-ID|V-4384, Rule-ID|SV-39164r1_rule, STIG-ID|GEN004560, Vuln-ID|V-4384

Plugin: Unix

Control ID: 312a1079dfe4f0d2aab4f4e8e67ef92661a075a5d3d05d1807046b9f9d229021