Check: GEN001470
Solaris 10 SPARC STIG:
GEN001470
(in versions v2 r4 through v1 r19)
Title
The /etc/passwd file must not contain password hashes. (Cat II impact)
Discussion
If password hashes are readable by non-administrators, the passwords are subject to attack through lookup tables or cryptographic weaknesses in the hashes.
Check Content
Verify no password hashes are present in /etc/passwd. # cut -d : -f 2 /etc/passwd | grep -v '^x$' If any password hashes are returned, this is a finding.
Fix Text
Migrate /etc/passwd password hashes to /etc/shadow. # pwconv
Additional Identifiers
Rule ID: SV-226528r603265_rule
Vulnerability ID: V-226528
Group Title: SRG-OS-000073
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
CCI-000196 |
The information system, for password-based authentication, stores only cryptographically-protected passwords. |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
IA-5 (1) |
Password-Based Authentication |