Cis Ubuntu1204 V110 5 5

Ensure discard is not enabled

cyberstrikeus Updated

File contents

5.5 Ensure discard is not enabled (Scored)

Profile Applicability

  • Level 1

Description

discard is a network service that simply discards all data it receives. This service is intended for debugging and testing purposes. It is recommended that this service be disabled.

Rationale

Disabling this service will reduce the remote attack surface of the system.

Audit Procedure

Using Command Line

Ensure the discard services are not enabled:

grep ^discard /etc/inetd.conf

Expected Result

No results should be returned.

Remediation

Using Command Line

Remove or comment out any discard lines in /etc/inetd.conf:

sed -i 's/^discard/#discard/' /etc/inetd.conf

Default Value

Not enabled by default on Ubuntu 12.04 LTS Server.

References

  • CIS Ubuntu 12.04 LTS Server Benchmark v1.1.0

Profile

Level 1 - Scored

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-12-04-lts-server-benchmark/cis-ubuntu1204-v110-5-5 commit 68fc80f932

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu1204-v110-5-5