2.1.3 Ensure discard services are not enabled (Scored)

Level 1 - Server 
Level 1 - Workstation

discard is a network service that simply discards all data it receives. This service is intended for debugging and testing purposes. It is recommended that this service be disabled.

Disabling this service will reduce the remote attack surface of the system.

Run the following command and verify discard-dgram and discard-stream are off or missing:

# chkconfig --list
 xinetd based services:
   discard-dgram: off 
   discard-stream: off

Run the following commands to disable discard-dgram and discard-stream:

# chkconfig discard-dgram off 
# chkconfig discard-stream off
  • centos7/2/1/3.txt
  • Last modified: 2017/05/04 15:24
  • by Piotr Kłoczewski