Check: AIX7-00-003138
IBM AIX 7.x STIG:
AIX7-00-003138
(in versions v3 r1 through v1 r1)
Title
There must be no .rhosts, .shosts, hosts.equiv, or shosts.equiv files on the AIX system. (Cat II impact)
Discussion
Trust files are convenient, but when used in conjunction with the remote login services, they can allow unauthenticated access to a system.
Check Content
Check for the existence of the files using: # find / -name .rhosts # find / -name .shosts # find / -name hosts.equiv # find / -name shosts.equiv If ".rhosts", ".shosts", "hosts.equiv", or "shosts.equiv" are found, this is a finding.
Fix Text
Remove the ".rhosts", ".shosts", "hosts.equiv", and/or "shosts.equiv" files.
Additional Identifiers
Rule ID: SV-215432r991591_rule
Vulnerability ID: V-215432
Group Title: SRG-OS-000480-GPOS-00229
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
CCI-000366 |
Implement the security configuration settings. |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
CM-6 |
Configuration Settings |