Check: GEN001560
Solaris 9 X86 STIG:
GEN001560
(in version v1 r9)
Title
All files and directories contained in user's home directories must have mode 0750 or less permissive. (Cat III impact)
Discussion
Excessive permissions allow unauthorized access to user's files.
Check Content
For each user in the /etc/passwd file, check for files and directories with a mode more permissive than 0750. Procedure: # find /<usershomedirectory> ! -fstype nfs \( -perm -0001 -o -perm -0002 -o -perm -0004 -o -perm -0020 -o -perm -2000 -o -perm -4000 \) -exec ls -ld {} \; If user's home directories contain files or directories more permissive than 0750, this is a finding.
Fix Text
Change the mode of files and directories within user's home directories to 0750. Procedure: # chmod 0750 filename Document all changes.
Additional Identifiers
Rule ID: SV-39840r1_rule
Vulnerability ID: V-915
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000225 |
The organization employs the concept of least privilege, allowing only authorized accesses for users (and processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions. |
Controls
Number | Title |
---|---|
AC-6 |
Least Privilege |