GEN004560 - The SMTP services SMTP greeting must not provide version information.

Information

The version of the SMTP service can be used by attackers to plan an attack based on vulnerabilities present in the specific version.

Solution

Ensure sendmail or Postfix has been configured to mask the version information.

Procedure
for sendmail:
Change the O SmtpGreetingMessage line in the /etc/mail/sendmail.cf file as noted below:
O SmtpGreetingMessage=$j Sendmail $v/$Z; $b
change it to:
O SmtpGreetingMessage= Mail Server Ready ; $b

for Postfix:
Examine the 'smtpd_banner' line of /etc/postfix/main.conf and remove any '$mail_version' entry on it or comment the entire 'smtpd_banner' line to use the default value which does not display the version information.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V2R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-218545r603259_rule, STIG-ID|GEN004560, STIG-Legacy|SV-63771, STIG-Legacy|V-4384, Vuln-ID|V-218545

Plugin: Unix

Control ID: 61a6858dd5440af9e15acbfdb031d9c0827dd0621515e3028b551d3de933df2a