The IBM z/OS UNIX Telnet server warning banner must be properly specified.
DISA Rule
SV-223868r958586_rule
Vulnerability Number
V-223868
Group Title
SRG-OS-000228-GPOS-00088
Rule Version
RACF-UT-000050
Severity
CAT II
CCI(s)
- CCI-001384 - For publicly accessible systems, display system use information with organization-defined conditions before granting further access to the publicly accessible system.
- CCI-001385 - For publicly accessible systems, displays references, if any, to monitoring that are consistent with privacy accommodations for such systems that generally prohibit those activities.
- CCI-001386 - For publicly accessible systems, displays references, if any, to recording that are consistent with privacy accommodations for such systems that generally prohibit those activities.
- CCI-001387 - For publicly accessible systems, displays references, if any, to auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities.
- CCI-001388 - For publicly accessible systems, includes a description of the authorized uses of the system.
Weight
10
Fix Recommendation
Configure the startup parameters in the inetd.conf file for otelnetd to exclude option -h.
Note: -h indicates that the logon banner should not be displayed.
Check Contents
From the ISPF Command Shell enter:
ISHELL
Enter /etc/ for a pathname - you may need to issue a CD /etc/
select FILE NAME inetd.conf
If Option -h is included on the otelnetd command, this is a finding.
Vulnerability Number
V-223868
Documentable
False
Rule Version
RACF-UT-000050
Severity Override Guidance
From the ISPF Command Shell enter:
ISHELL
Enter /etc/ for a pathname - you may need to issue a CD /etc/
select FILE NAME inetd.conf
If Option -h is included on the otelnetd command, this is a finding.
Check Content Reference
M
Target Key
4101