Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-22314 | GEN001210 | SV-38686r1_rule | ECLP-1 | Medium |
Description |
---|
Restricting permissions will protect system command files from unauthorized modification. System command files include files present in directories used by the operating system for storing default system executables and files present in directories included in the system's default executable search paths. |
STIG | Date |
---|---|
Draft AIX Security Technical Implementation Guide | 2011-08-17 |
Check Text ( C-36947r1_chk ) |
---|
Verify all system command files have no extended ACLs. # aclget /etc # aclget /bin # aclget /usr/bin # aclget /usr/lbin # aclget /usr/usb # aclget /sbin # aclget /usr/sbin If any of the command files have extended permissions enabled, this is a finding. |
Fix Text (F-32211r1_fix) |
---|
Remove the extended ACL(s) from the system command file(s) and set the extended permissions to disabled. #acledit < command path >/< command file> |