Uninstall rsync Package
An XCCDF Rule
Description
The rsyncd service can be used to synchronize files between systems over network links.
The rsync-daemon
package can be removed with the following command:
$ sudo yum erase rsync-daemon
Rationale
The rsyncd service presents a security risk as it uses unencrypted protocols for communication.
- ID
- xccdf_org.ssgproject.content_rule_package_rsync_removed
- Severity
- Medium
- References
- Updated
Remediation - Anaconda Pre-Install Instructions
package --remove=rsync-daemon
Remediation - Ansible
- name: Ensure rsync-daemon is removed
package:
name: rsync-daemon
state: absent
tags:
- CCE-86335-7
Remediation - Puppet
include remove_rsync-daemon
class remove_rsync-daemon {
package { 'rsync-daemon':
ensure => 'purged',
}
Remediation - Shell Script
# CAUTION: This remediation script will remove rsync-daemon
# from the system, and may remove any packages
# that depend on rsync-daemon. Execute this
# remediation AFTER testing on a non-production
# system!