Check: GEN003810
AIX 6.1 SECURITY TECHNICAL IMPLEMENTATION GUIDE:
GEN003810
(in versions v1 r14 through v1 r10)
Title
The portmap or rpcbind service must not be running unless needed. (Cat II impact)
Discussion
The portmap and rpcbind services increase the attack surface of the system and should only be used when needed. The portmap or rpcbind services are used by a variety of services using Remote Procedure Calls (RPCs).
Check Content
If the portmap service is required for system operations, this is not a finding. Determine if the portmap service is running. #ps -ef|grep portmap If portmap is running, this is a finding.
Fix Text
Disable the portmap service from auto starting by commenting out portmap from /etc/rc.tcpip. # vi /etc/rc.tcpip Shutdown the portmap service. # ps -ef | grep portmap # kill <pid of portmap>
Additional Identifiers
Rule ID: SV-38874r1_rule
Vulnerability ID: V-22429
Group Title: GEN003810
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001336 |
The organization retains individual training records for an organization-defined time period. |
Controls
Number | Title |
---|---|
AT-4 |
Security Training Records |