Cis Ubuntu1604 V200 2 2 6

Ensure RPC is not installed

cyberstrikeus Updated

File contents

2.2.6 Ensure RPC is not installed (Automated)

Description

Remote Procedure Call (RPC) is a method for creating low level client server applications across different system architectures. It requires an RPC compliant client listening on a network port. The supporting package is rpcbind.

Rationale

If RPC is not required, it is recommended that this services be removed to reduce the remote attack surface.

Audit Procedure

Command Line

Run the following command to verify rpcbind is not installed:

dpkg -s rpcbind | grep -E '(Status:|not installed)'

Expected Result

dpkg-query: package 'rpcbind' is not installed and no information is available

Remediation

Command Line

Run the following command to remove rpcbind:

apt purge rpcbind

Default Value

rpcbind is not installed on minimal server installations.

References

  1. CIS Controls v7 - 9.2 Ensure Only Approved Ports, Protocols and Services Are Running

Profile

  • Level 1 - Server
  • Level 1 - Workstation

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-linux-16-04-lts-benchmark-v2/cis-ubuntu1604-v200-2-2-6 commit c3d76f0a2b

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu1604-v200-2-2-6