Check: GEN002220 M6
MACOSX 10.6:
GEN002220 M6
(in version v1 r3)
Title
All shell files must have mode 0755 or less permissive. (Cat I impact)
Discussion
Shells with world/group write permissions give the ability to maliciously modify the shell to obtain unauthorized access.
Check Content
Open a terminal session and enter the following command. cat /etc/shells | xargs -n1 ls -lL If any shell has a mode more permissive than 0755, this is a finding.
Fix Text
Open a terminal session and enter the following command to set the mode. chmod 0755 <shell file>
Additional Identifiers
Rule ID: SV-38015r1_rule
Vulnerability ID: V-922
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000225 |
The organization employs the concept of least privilege, allowing only authorized accesses for users (and processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions. |
Controls
Number | Title |
---|---|
AC-6 |
Least Privilege |