Cis Ubuntu1204 V110 5 1 2

Ensure rsh server is not enabled

cyberstrikeus Updated

File contents

5.1.2 Ensure rsh server is not enabled (Scored)

Profile Applicability

  • Level 1

Description

The Berkeley rsh-server (rsh, rlogin, rcp) package contains legacy services that exchange credentials in clear-text.

Rationale

These legacy services contain numerous security exposures and have been replaced with the more secure SSH package.

Audit Procedure

Using Command Line

Ensure the rsh services are not enabled:

grep ^shell /etc/inetd.conf
grep ^login /etc/inetd.conf
grep ^exec /etc/inetd.conf

Expected Result

No results should be returned.

Remediation

Using Command Line

Remove or comment out any shell, login, or exec lines in /etc/inetd.conf:

sed -i 's/^shell/#shell/' /etc/inetd.conf
sed -i 's/^login/#login/' /etc/inetd.conf
sed -i 's/^exec/#exec/' /etc/inetd.conf

Default Value

Not enabled by default on Ubuntu 12.04 LTS Server.

References

  • CIS Ubuntu 12.04 LTS Server Benchmark v1.1.0

Profile

Level 1 - Scored

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-12-04-lts-server-benchmark/cis-ubuntu1204-v110-5-1-2 commit 969dfbb42f

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu1204-v110-5-1-2