GEN003603 M6 - System must not respond to ICMP (ICMPv4) echoes to a broadcast address - 'net.inet.icmp.bmcastecho:1'

Information

Responding to broadcast ICMP echoes facilitates network mapping and provides a vector for amplification attacks.

Solution

Open a terminal session and edit the /etc/sysctl.conf file and add the following line.

net.inet.icmp.bmcastecho=1

NOTE- If the sysctl.conf file does not exist use the following command to create one.
touch /etc/sysctl.conf

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(16), CAT|II, CCI|CCI-001551, Rule-ID|SV-38201r1_rule, STIG-ID|GEN003603-M6, Vuln-ID|V-22410

Plugin: Unix

Control ID: eba21938318428eb571dd9656da00ab6bc803ebb86f770976393cd7ccf062b80