Check: SOL-11.1-070160
Solaris 11 SPARC STIG:
SOL-11.1-070160
(in versions v2 r10 through v1 r10)
Title
User .netrc files must not exist. (Cat II impact)
Discussion
The .netrc file presents a significant security risk since it stores passwords in unencrypted form.
Check Content
The root role is required. Check for the presence of user .netrc files. # for dir in \ `logins -ox | awk -F: '($8 == "PS") { print $6 }'`; do ls -l ${dir}/.netrc 2>/dev/null done If output is produced, this is a finding.
Fix Text
The root role is required. Determine if any .netrc files exist, and work with the owners to determine the best course of action in accordance with site policy.
Additional Identifiers
Rule ID: SV-216432r603267_rule
Vulnerability ID: V-216432
Group Title: SRG-OS-000480
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
CM-6 |
Configuration Settings |