Check: GEN000480
VMware ESX 3 Server:
GEN000480
(in version v1 r2)
Title
The delay between login prompts following a failed login attempt must be at least 4 seconds. (Cat II impact)
Discussion
Enforcing a delay between successive failed login attempts increases protection against automated password guessing attacks.
Check Content
Attempt to log on to the system with an invalid user account name and an incorrect password. If the system does not pause for at least 4 seconds before displaying another logon prompt, this is a finding.
Fix Text
Configure the system to delay at least 4 seconds between login prompts following a failed login attempt.
Additional Identifiers
Rule ID: SV-768r2_rule
Vulnerability ID: V-768
Group Title: GEN000480
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002238 |
The information system automatically locks the account or node for either an organization-defined time period, until the locked account or node is released by an administrator, or delays the next logon prompt according to the organization-defined delay algorithm when the maximum number of unsuccessful logon attempts is exceeded. |
Controls
Number | Title |
---|---|
AC-7 |
Unsuccessful Logon Attempts |