UCF STIG Viewer Logo

The system must not have Internet Message Access Protocol (IMAP) service active.


Overview

Finding ID Version Rule ID IA Controls Severity
V-29508 GEN009240 SV-38712r1_rule ECSC-1 Medium
Description
The IMAP service should not be running unless the system is acting as a mail server for client connections. Running unnecessary services increases the attack vector on the system.
STIG Date
Draft AIX Security Technical Implementation Guide 2011-08-17

Details

Check Text ( C-37808r1_chk )
Check the /etc/inetd.conf file for active IMAP service.

#grep imapd /etc/inetd.conf | grep -v \#

If the IMAP service is enabled, this is a finding.
Fix Text (F-33066r1_fix)
Edit /etc/inetd.conf and comment out the imap2 service line.

Restart the inetd service.
#refresh –s inetd