GEN004680 - The SMTP service must not have the VRFY feature active.

Information

The VRFY command allows an attacker to determine if an account exists on a system, providing significant assistance to a brute force attack on user accounts. VRFY may provide additional information about users on the system, such as the full names of account owners.

Solution

Add the 'novrfy' flag to your sendmail in /etc/mail/sendmail.cf.

Procedure:
Edit the definition of 'confPRIVACY_FLAGS' in /etc/mail/sendmail.mc to include 'novrfy'.

Rebuild the sendmail.cf file with:
# make -C /etc/mail

Restart the sendmail service.
# service sendmail restart

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Group-ID|V-4693, Rule-ID|SV-37511r1_rule, STIG-ID|GEN004680, Vuln-ID|V-4693

Plugin: Unix

Control ID: 7f2b31cff9ee8e4edf790678abd5ba928a7e63b7b6c47eb638b26d48b4a177a9