GEN003602 M6 - The system must not process Internet Control Message Protocol (ICMP) timestamp requests - 'net.inet.icmp.timestamp:1'

Information

The processing of ICMP timestamp requests increases the attack surface of the system.

Solution

Open a terminal session and edit the /etc/sysctl.conf file and add the following line.

net.inet.icmp.timestamp=1

NOTE- If the sysctl.conf file does not exist use the following command to create one.
touch /etc/sysctl.conf

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(16), CAT|III, CCI|CCI-001551, Rule-ID|SV-38200r1_rule, STIG-ID|GEN003602-M6, Vuln-ID|V-22409

Plugin: Unix

Control ID: c30a4057852f06ac87fdf9825c6ab311fa5ed7f48d779e27c6430066f48c39f4