Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-810 | GEN002640 | SV-38897r1_rule | IAAC-1 | Medium |
Description |
---|
Vendor accounts and software may contain backdoors allowing unauthorized access to the system. These backdoors are common knowledge and present a threat to system security if the account is not disabled. |
STIG | Date |
---|---|
AIX 6.1 SECURITY TECHNICAL IMPLEMENTATION GUIDE | 2015-06-16 |
Check Text ( C-37188r1_chk ) |
---|
Determine if default system accounts (such as those for guest, sys, bin, uucp, nuucp, daemon, smtp, and lpd) have been disabled. Procedure: # lsuser -a account_locked ALL If there are any unlocked default system accounts, this is a finding. |
Fix Text (F-24500r1_fix) |
---|
Lock the default system account(s). # chuser account_locked=true |