Skybox Appliance 8000 Quick Start Guide
Skybox version 10.1.200
66
Recommend
ation
Scored Description
6.1.5 – 6.1.9
Permission to user- and group-related files:
•
/etc/gshadow
•
/etc/passwd-
•
/etc/shadow-
•
/etc/group-
•
/etc/gshadow-
Rationale: It is critical to ensure that these files are protected
from unauthorized access. Although they are protected by
default, the file permissions could be changed either
inadvertently or through malicious actions.
6.1.10
Ensure that no world writable files exist. Unix-based systems
support variable settings to control access to files. World
writable files are the least secure. See the
chmod(2) man
page
for more information.
Rationale: Data in world-writable files can be modified and
compromised by any user on the system. World writable files
may also indicate an incorrectly written script or program that
could potentially be the cause of a larger compromise to the
system’s integrity.
6.1.11
Ensure that no unowned files or directories exist. Sometimes
when administrators delete users from the password file they
neglect to remove all files owned by those users from the
system.
Rationale: A new user who is assigned the deleted user’s user
ID or group ID may then end up ‘owning’ these files, and thus
have more access on the system than was intended.
Note: For additional information, refer to CIS CentOS 7 Linux Benchmark, v2.1.1