GEN004560 - The SMTP service's SMTP greeting must not provide version information.

Information

The version of the SMTP service can be used by attackers to plan an attack based on vulnerabilities present in the specific version.

Solution

Ensure sendmail or Postfix has been configured to mask the version information.

Procedure
for sendmail:
Edit the /etc/mail/sendmail.mc file to mask the veresion number by editing the line with 'dnl' as follows:
define('confSMTP_LOGIN_MSG', ' Mail Server Ready ; $b')dnl
rebuild the sendmail.cf file.

for Postfix:
Examine the 'smtpd_banner' line of /etc/postfix/main.conf and remove any '$mail_version' entry on it or comment the entire 'smtpd_banner' line to use the default value which does not display the version information.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Group-ID|V-4384, Rule-ID|SV-37505r2_rule, STIG-ID|GEN004560, Vuln-ID|V-4384

Plugin: Unix

Control ID: 03a03e84dd89a4f398d74ef22f0c46bad4b4bcde81b5122a7d35ef233438bc75