GEN009210 - The system must not have the discard service active.

Information

The discard service runs as root from the inetd server and can be used in Denial of Service attacks. The discard service is unnecessary and it increases the attack vector of the system.

Solution

Edit /etc/inetd.conf and comment out the discard service line for both TCP and UDP protocols.
Restart the inetd service.
#refresh -s inetd

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R14_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17(8), CAT|II, CCI|CCI-001436, Group-ID|V-29505, Rule-ID|SV-38709r1_rule, STIG-ID|GEN009210, Vuln-ID|V-29505

Plugin: Unix

Control ID: 1658e257fe7177f14c6be0e945480f77b541e8a4cca48cf8e4b37cfc6192eabe