GEN008500 - The system must have IEEE 1394 (Firewire) disabled unless needed.

Information

Firewire is a common computer peripheral interface. Firewire devices may include storage devices with the potential to install malicious software on a system or exfiltrate data.

Solution

Prevent the system from loading the Firewire module.
# echo 'install ieee1394 /bin/true' >> /etc/modprobe.conf

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V2R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-218716r603259_rule, STIG-ID|GEN008500, STIG-Legacy|SV-63173, STIG-Legacy|V-22580, Vuln-ID|V-218716

Plugin: Unix

Control ID: a06a7bdc439f974e8fb4d06ec5b422dcd707e4fdcd6d2bdb903fd964a50cfff5