Check: AIX7-00-002089
IBM AIX 7.x STIG:
AIX7-00-002089
(in versions v3 r1 through v1 r1)
Title
Samba packages must be removed from AIX. (Cat II impact)
Discussion
If the smbpasswd file has a mode more permissive than 0600, the smbpasswd file may be maliciously accessed or modified, potentially resulting in the compromise of Samba accounts.
Check Content
Run the following command to check if samba packages are installed on AIX: # lslpp -l samba* If the above command shows that samba packages are installed, this is a finding.
Fix Text
Run the following command to un-install the samba packages: # installp -ug samba*
Additional Identifiers
Rule ID: SV-215280r991589_rule
Vulnerability ID: V-215280
Group Title: SRG-OS-000480-GPOS-00227
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
CCI-000366 |
Implement the security configuration settings. |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
CM-6 |
Configuration Settings |