STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 1 hour ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to IBM AIX 7.x Security Technical Implementation Guide

V-215376

CAT II (Medium)

The chargen daemon must be disabled on AIX.

Rule ID

SV-215376r958478_rule

STIG

IBM AIX 7.x Security Technical Implementation Guide

Version

V3R2

CCIs

CCI-000381

Discussion

This service is used to test the integrity of TCP/IP packets arriving at the destination. This chargen service is a character generator service and is used for testing the integrity of TCP/IP packets arriving at the destination. An attacker may spoof packets between machines running the chargen service and thus provide an opportunity for DoS attacks. Disable this service to prevent attacks unless testing the network.

Check Content

From the command prompt, execute the following command: 
# grep "^chargen[[:blank:]]" /etc/inetd.conf

If there is any output from the command, this is a finding.

Fix Text

In "/etc/inetd.conf", comment out the "chargen" entries by running commands: 
# chsubserver -r inetd -C /etc/inetd.conf -d -v 'chargen' -p 'tcp' 
# chsubserver -r inetd -C /etc/inetd.conf -d -v 'chargen' -p 'udp'

Restart inetd:
# refresh -s inetd