Check: GEN001780
      
      
        
  Solaris 10 X86 STIG:
  GEN001780
  
    (in versions v2 r4 through v1 r17)
  
      
      
    
  Title
Global initialization files must contain the mesg -n or mesg n commands. (Cat III impact)
Discussion
If the mesg -n or mesg n command is not placed into the system profile, messaging can be used to cause a Denial of Service attack.
Check Content
Check global initialization files for the presence of "mesg -n" or "mesg n". Procedure: # grep mesg /etc/.login /etc/profile /etc/bashrc /etc/environment /etc/security/environ /etc/csh.login /etc/csh.cshrc If no existing global initialization files contain "mesg -n" or "mesg n", this is a finding.
Fix Text
Edit /etc/profile or another global initialization script and add the mesg -n command.
Additional Identifiers
Rule ID: SV-220087r603266_rule
Vulnerability ID: V-220087
Group Title: SRG-OS-000480
Expert Comments
      
        
        
      
      
        
  CCIs
      
      
        
        
      
    
  | Number | Definition | 
|---|---|
| CCI-000366 | 
           Implement the security configuration settings.  | 
      
      
        
        
      
      
        
  Controls
      
      
        
        
      
    
  | Number | Title | 
|---|---|
| CM-6 | 
           Configuration Settings  |