Disable System Accounts There are a number of accounts provided with Ubuntu that are used to manage applications and are not intended to provide an interactive shell.

Ensure Firewall is active IPtables is an application that allows a system administrator to configure the IPv4 tables, chains and rules provided by the Linux kernel firewall. ufw was developed to ease IPtables firewall configuration.

Restrict at/cron to Authorized Users Configure /etc/cron.allow and /etc/at.allow to allow specific users to use these services. If /etc/cron.allow or /etc/at.allow do not exist, then /etc/at.deny and /etc/cron.deny are checked. Any user not specifically defined in those files is allowed to use at and cron. By removing the files, only users in /etc/cron.allow and /etc/at.allow are allowed to use a ...

Disable IPv6 Redirect Acceptance This setting prevents the system from accepting ICMP redirects. ICMP redirects tell the system about alternate routes for sending traffic.

Limit Password Reuse The /etc/security/opasswd file stores the users' old passwords and can be checked to ensure that users are not recycling recent passwords.

Restrict root Login to System Console The file /etc/securetty contains a list of valid terminals that may be logged in directly as root.

Ensure talk client is not installed The talk software makes it possible for users to send and receive messages across systems through a terminal session.

Verify Permissions on /etc/passwd The /etc/passwd file contains user account information that is used by many system utilities and therefore must be readable for these utilities to operate.

Ensure rsh client is not installed The rsh package contains the client commands for the rsh services.

Disable SSH X11 Forwarding The X11Forwarding parameter provides the ability to tunnel X11 traffic through the connection to enable remote graphic connections.

