Check: GEN001890
Solaris 10 X86 STIG:
GEN001890
(in versions v2 r4 through v1 r17)
Title
Local initialization files must not have extended ACLs. (Cat II impact)
Discussion
Local initialization files are used to configure the user's shell environment upon login. Malicious modification of these files could compromise accounts upon logon.
Check Content
Check user home directories for local initialization files with extended ACLs. # cut -d : -f 6 /etc/passwd | xargs -n1 -IDIR ls -alL DIR/.login DIR/.cshrc DIR/.logout DIR/.profile DIR/.bash_profile DIR/.bashrc DIR/.bash_logout DIR/.env DIR/.dtprofile DIR/.dispatch DIR/.emacs DIR/.exrc If the permissions include a "+", the file has an extended ACL, this is a finding.
Fix Text
Remove the extended ACL from the file. # chmod A- [local initialization file with extended ACL]
Additional Identifiers
Rule ID: SV-227681r603266_rule
Vulnerability ID: V-227681
Group Title: SRG-OS-000480
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |