| name | cis-ubuntu1204-v110-5-5 |
| description | Ensure discard is not enabled |
| category | cis-os-hardening |
| version | 1.1.0 |
| author | cyberstrike-official |
| tags | ["cis","ubuntu",12.04,"linux","discard","inetd","attack-surface"] |
| cis_id | 5.5 |
| cis_benchmark | CIS Ubuntu 12.04 LTS Server Benchmark v1.1.0 |
| tech_stack | ["ubuntu","linux"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
5.5 Ensure discard is not enabled (Scored)
Profile Applicability
Description
discard is a network service that simply discards all data it receives. This service is intended for debugging and testing purposes. It is recommended that this service be disabled.
Rationale
Disabling this service will reduce the remote attack surface of the system.
Audit Procedure
Using Command Line
Ensure the discard services are not enabled:
grep ^discard /etc/inetd.conf
Expected Result
No results should be returned.
Remediation
Using Command Line
Remove or comment out any discard lines in /etc/inetd.conf:
sed -i 's/^discard/#discard/' /etc/inetd.conf
Default Value
Not enabled by default on Ubuntu 12.04 LTS Server.
References
- CIS Ubuntu 12.04 LTS Server Benchmark v1.1.0
Profile
Level 1 - Scored