GEN004560 - The SMTP services SMTP greeting must not provide version information.

Information

The version of the SMTP service can be used by attackers to plan an attack based on vulnerabilities present in the specific version.

Solution

Ensure Sendmail or its equivalent has been configured to mask the version information. If necessary, change the O SmtpGreetingMessage line in the /etc/mail/sendmail.cf file as noted below.
O SmtpGreetingMessage=$j Sendmail $v/$Z; $b
Change it to:
O SmtpGreetingMessage= Mail Server Ready ; $b

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_SPARC_V2R4_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-220047r603265_rule, STIG-ID|GEN004560, STIG-Legacy|SV-42310, STIG-Legacy|V-4384, Vuln-ID|V-220047

Plugin: Unix

Control ID: 0ba86def0654000cbccdceae6dd404eb633f748537c221ba4b883ecc55caa56f