Check: GEN003815
Title
The portmap or rpcbind service must not be installed unless needed. (Cat II impact)
Discussion
The portmap and rpcbind services increase the attack surface of the system and should only be used when needed. The portmap or rpcbind services are used by a variety of services using Remote Procedure Calls (RPCs).
Check Content
If the system needs the portmap service to operate, this is not applicable. Verify the permissions on the rpcbind file. # ls -lL /usr/etc/rpcbind If the rpcbind service is not required and the rpcbind file has non-zero permissions, this is a finding.
Fix Text
Remove all permissions from the rpcbind file. Procedure: # chmod 0000 /usr/etc/rpcbind
Additional Identifiers
Rule ID:
Vulnerability ID: V-22430
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000305 |
The organization develops a list of software programs not authorized to execute on the information system. |
Controls
Number | Title |
---|---|
No controls are assigned to this check |