GEN004660 - The SMTP service must not have the EXPN feature active.

Information

The SMTP EXPN function allows an attacker to determine if an account exists on a system, providing significant assistance to a brute-force attack on user accounts. EXPN may also provide additional information concerning users on the system, such as the full names of account owners.

False Positives:
False positives may occur with the SMTP EXPN check. According to RFC821, it is acceptable for a server to respond with a 250 (success) or 550 (failure) when the server supports the EXPN command. For example, some servers return '550 EXPN command not available', meaning the command is not supported and the machine is not vulnerable. However, a result of '550 That is a mailing list, not a user' would be a failure code, but not an indication of an error, and the machine would be vulnerable. If false positive is suspected, check the log file for the response from the server.

Solution

Edit the sendmail.cf file and add Opnoexpn option.
Restart the Sendmail service.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_x86_V2R4_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-227848r603266_rule, STIG-ID|GEN004660, STIG-Legacy|SV-4692, STIG-Legacy|V-4692, Vuln-ID|V-227848

Plugin: Unix

Control ID: 6458162745158d64cf891532babfb7c291e68278cfa96c77aa4eb294d94aad14