GEN003850 - The telnet daemon must not be running

Information

The telnet daemon provides a typically unencrypted remote access service which does not provide for the confidentiality and integrity of user passwords or the remote session. If a privileged user were to log on using this service, the privileged user password could be compromised.

Solution

Consult vendor documentation to determine the procedure to disable the telnet daemon. If the system uses inetd, edit /etc/inetd.conf and comment out the telnetd line. Restart the inetd service via the following command:
# inetd -c

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|I, CCI|CCI-000197, CSCv6|9.1, Rule-ID|SV-35134r1_rule, STIG-ID|GEN003850, Vuln-ID|V-24386

Plugin: Unix

Control ID: 01cb6d22c874e1457201146344645a7a22ae6df41e755e139ce200ca255f614c