Allison Henry
Due to recent security incidents involving the abuse of the "chargen"
service running on (19/udp), we are asking campus administrators to
*immediately disable chargen services* on all campus hosts, or at a
minimum, block Internet access to UDP port 19 using firewalls. There
are few if any legitimate uses for this service, and as required by
campus MSSND, unnecessary services should be removed:


The chargen service is part of "Simple TCP/IP services" on Windows
Servers and "udp-small-servers" on Cisco IOS devices, so check to make
sure these services are not enabled. The chargen service is also
frequently enabled on printers and other multifunction devices so if
you administer these devices please check your configuration.

It's a good opportunity to check for any other unnecessary services
which may be running on your devices. Abuse of the chargen service is
an example of why this minimum security standard is important -- a
service that seems harmless may be still exploited by attackers.

If anyone has a legitimate use case for chargen, please let us know.
If the service cannot be disabled it should at least be blocked from
the public Internet. For more information on chargen see:


More information on this threat is being provided on the UCB-Security
mailing list: https://security.berkeley.edu/ucb-security

As a reminder, discussion of sensitive IT security issues on campus
takes place on this private list. If you have an IT job function or IT
management responsibilities, please subscribe.


Allison Henry
Security Operations Manager
Information Security and Policy Office
University of California, Berkeley
