AIX7-00-002058 - The AIX rexec daemon must not be running.

Information

The exec service is used to execute a command sent from a remote server. The username and passwords are passed over the network in clear text and therefore insecurely. Unless required the rexecd daemon will be disabled. This function, if required, should be facilitated through SSH.

Solution

Disable the 'rexecd' entry in '/etc/inetd.conf' using command:
# chsubserver -r inetd -C /etc/inetd.conf -d -v 'exec' -p 'tcp6'

Reload the inetd process:
# refresh -s inetd

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_IBM_AIX_7-x_V2R9_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(c), CAT|I, CCI|CCI-000197, Rule-ID|SV-215257r877396_rule, STIG-ID|AIX7-00-002058, STIG-Legacy|SV-101401, STIG-Legacy|V-91303, Vuln-ID|V-215257

Plugin: Unix

Control ID: 118073b481f34b67c664c14ee9ac1d7f191402a1e67686f257b211577508d9c2