GEN008500 - The system must have IEEE 1394 (Firewire) disabled unless needed.

Information

Firewire is a common computer peripheral interface. Firewire devices may include storage devices with the potential to install malicious software on a system or exfiltrate data.

Solution

Prevent the system from loading the firewire module.
# echo 'install ieee1394 /bin/true' >> /etc/modprobe.conf

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Group-ID|V-22580, Rule-ID|SV-37983r1_rule, STIG-ID|GEN008500, Vuln-ID|V-22580

Plugin: Unix

Control ID: a639492e707134f57d02dbce36c23f26a39ca0dcc8fdeaf09f8aa284258d296d