Skip to content

SMTP service must not have the EXPN or VRFY features active on AIX systems.

An XCCDF Rule

Description

<VulnDiscussion>The SMTP EXPN function allows an attacker to determine if an account exists on a system, providing significant assistance to a brute force attack on user accounts. EXPN may also provide additional information concerning users on the system, such as the full names of account owners. The VRFY (Verify) command allows an attacker to determine if an account exists on a system, providing significant assistance to a brute force attack on user accounts. VRFY may provide additional information about users on the system, such as the full names of account owners.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-215415r508663_rule
Severity
Medium
References
Updated



Remediation - Manual Procedure

Edit the "sendmail.cf" file and add or edit the following line: 
O PrivacyOptions=goaway 

Restart the "Sendmail" service:
# startsrc -s sendmail -a "-bd -q30m"