GEN003602 - The system must not process Internet Control Message Protocol (ICMP) timestamp requests

Information

The processing of ICMP timestamp requests increases the attack surface of the system.

Solution

Disable ICMP Timestamp responses on the system.
# ndd -set /dev/ip ip_respond_to_timestamp 0

Edit /etc/rc.config.d/nddconf and add/set:
TRANSPORT_NAME[x]=ip
NDD_NAME[x]=ip_respond_to_timestamp
NDD_VALUE[x]=0

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CAT|III, CCI|CCI-001551, CSCv6|9.2, Rule-ID|SV-35022r1_rule, STIG-ID|GEN003602, Vuln-ID|V-22409

Plugin: Unix

Control ID: 7c93d59c5e5a4e04567b54d5f5c18632d299fefc83ca512b7dd32f95827a37d1