![skybox 7000 Скачать руководство пользователя страница 63](http://html.mh-extra.com/html/skybox/7000/7000_quick-start-manual_1290110063.webp)
Chapter 16 CIS benchmarks for CentOS 7
Skybox version 10.1.200
63
Recommend
ation
Scored Description
6.1.5 – 6.1.9
Permission to user- and group-related files:
•
/etc/gshadow
•
/etc/passwd-
•
/etc/shadow-
•
/etc/group-
•
/etc/gshadow-
Rationale: It is critical to ensure that these files are protected
from unauthorized access. Although they are protected by
default, the file permissions could be changed either
inadvertently or through malicious actions.
6.1.10
Ensure that no world writable files exist. Unix-based systems
support variable settings to control access to files. World
writable files are the least secure. See the
chmod(2) man
page
for more information.
Rationale: Data in world-writable files can be modified and
compromised by any user on the system. World writable files
may also indicate an incorrectly written script or program that
could potentially be the cause of a larger compromise to the
system’s integrity.
6.1.11
Ensure that no unowned files or directories exist. Sometimes
when administrators delete users from the password file they
neglect to remove all files owned by those users from the
system.
Rationale: A new user who is assigned the deleted user’s user
ID or group ID may then end up ‘owning’ these files, and thus
have more access on the system than was intended.
Note: For additional information, refer to CIS CentOS 7 Linux Benchmark, v2.1.1