UCF STIG Viewer Logo

The SMTP service must not have the VRFY feature active.


Finding ID Version Rule ID IA Controls Severity
V-89671 VRAU-SL-000630 SV-100321r1_rule Medium
The VRFY (Verify) command allows an attacker to determine if an account exists on a system, providing significant assistance to a brute force attack on user accounts. VRFY may provide additional information about users on the system, such as the full names of account owners.
VMware vRealize Automation 7.x SLES Security Technical Implementation Guide 2018-10-12


Check Text ( C-89363r1_chk )
Use the following command to check if VRFY is disabled:

# grep -v "^#" /etc/sendmail.cf |grep -i PrivacyOptions

If "novrfy" is not returned, this is a finding.
Fix Text (F-96413r1_fix)
Add "novrfy" to the "PrivacyOptions" flag in /etc/sendmail.cf