CIS Ubuntu 14.04 LTS - 2.1.10 Ensure xinetd is not enabled

Verify that the xinetd super daemon is disabled when not required

cyberstrikeus Updated

File contents

2.1.10 Ensure xinetd is not enabled (Scored)

Profile Applicability

  • Level 1 - Server
  • Level 1 - Workstation

Description

The eXtended InterNET Daemon (xinetd) is an open source super daemon that replaced the original inetd daemon. The xinetd daemon listens for well known services and dispatches the appropriate daemon to properly respond to service requests.

Rationale

If there are no xinetd services required, it is recommended that the daemon be disabled.

Audit Procedure

Run the following commands to verify no start conditions listed for xinetd:

initctl show-config xinetd

Verify the output shows xinetd with no start conditions.

Expected Result

The xinetd service should have no start conditions listed.

Remediation

Remove or comment out start lines in /etc/init/xinetd.conf:

#start on runlevel [2345]

Default Value

xinetd is not enabled by default on Ubuntu 14.04.

References

  • CIS Controls: 9.1 Limit Open Ports, Protocols, and Services

Profile

  • Level 1 - Server
  • Level 1 - Workstation

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-linux-14-04-lts-benchmark-v2/cis-ubuntu1404-v210-2-1-10 commit 0cbfc777ee

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu-14-04-lts-2-1-10-ensure-xinetd-is-not-enabled