Check: GEN002320
HP-UX 11.31 STIG:
GEN002320
(in versions v1 r19 through v1 r13)
Title
Audio devices must have mode 0660 or less permissive. (Cat II impact)
Discussion
Globally accessible audio and video devices have proven to be another security hazard. There is software capable of activating system microphones and video devices connected to user workstations and/or X terminals. Once the microphone has been activated, it is possible to eavesdrop on otherwise private conversations without the victim being aware of it. This action effectively changes the user's microphone into a bugging device.
Check Content
Check the mode of audio device files. Determine audio devices and class identifiers, i.e., audio should be listed as audio. # ioscan Determine audio device special files. # ioscan -fn -C <audio class ID from the above command output> Determine the device file mode. # ls -lL <device special file> If the mode of any audio device file is more permissive than 0660, this is a finding.
Fix Text
Change the mode of audio devices. # chmod 0660 <audio device>
Additional Identifiers
Rule ID: SV-38241r1_rule
Vulnerability ID: V-1048
Group Title: GEN002320
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000225 |
The organization employs the concept of least privilege, allowing only authorized accesses for users (and processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions. |
Controls
Number | Title |
---|---|
AC-6 |
Least Privilege |