CIS Ubuntu 14.04 LTS - 3.2.5 Ensure broadcast ICMP requests are ignored
Verify that broadcast ICMP echo and timestamp requests are ignored to prevent Smurf attacks
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Verify that broadcast ICMP echo and timestamp requests are ignored to prevent Smurf attacks
Verify that bogus ICMP error responses are ignored to prevent log file pollution
Verify that reverse path filtering is enabled to prevent IP spoofing
Verify that TCP SYN Cookies are enabled to protect against SYN flood attacks
Verify that IPv6 ICMP redirects are not accepted to prevent routing to compromised machines
Verify that IPv6 is disabled if not required to reduce the attack surface
Verify that TCP Wrappers is installed for host-based access control
Verify that /etc/hosts.allow is configured to permit authorized network access
Verify that /etc/hosts.deny is configured to deny all unauthorized network access
Verify that /etc/hosts.allow has correct ownership and permissions (root:root 644)