Check: SOL-11.1-070170
Solaris 11 SPARC STIG:
SOL-11.1-070170
(in versions v2 r10 through v1 r10)
Title
The system must not allow users to configure .forward files. (Cat II impact)
Discussion
Use of the .forward file poses a security risk in that sensitive data may be inadvertently transferred outside the organization. The .forward file also poses a secondary risk as it can be used to execute commands that may perform unintended actions.
Check Content
The root role is required. # for dir in \ `logins -ox | awk -F: '($8 == "PS") { print $6 }'`; do ls -l ${dir}/.forward 2>/dev/null done If output is produced, this is a finding.
Fix Text
The root role is required. Remove any .forward files that are found. # pfexec rm [filename]
Additional Identifiers
Rule ID: SV-216433r603267_rule
Vulnerability ID: V-216433
Group Title: SRG-OS-000480
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |