rstatd vulnerability
Summary
rstatd provides information about a machine's performance.
Impact
A Bad Guy(tm) could build a table of a machine's usage based on the
load average and uptime.
Background
rstatd is normally used to check a machine's load average and availability.
Some systems administrators use this information to assess a machine's status
without having to log into the machine.
The problem
By knowing when a system is not being used, a cracker could start an
attack during off-hours. Also, an attacker might be able to make some
assumptions about the machine and its importance.
Fix
- Disable rstatd from the /etc/inetd.conf file and signal inetd.