UCF STIG Viewer Logo

Global initialization files must contain the mesg -n or mesg n commands.


Overview

Finding ID Version Rule ID IA Controls Severity
V-825 GEN001780 SV-38893r1_rule ECSC-1 Low
Description
If the mesg -n or mesg n command is not placed into the system profile, messaging can be used to cause a Denial of Service attack.
STIG Date
Draft AIX Security Technical Implementation Guide 2011-08-17

Details

Check Text ( C-37164r1_chk )
Check global initialization files for the presence of mesg -n or mesg n.

Procedure:
# grep "mesg” /etc/.login /etc/profile /etc/bashrc /etc/environment /etc/security/environ /etc/security/.profile

If no global initialization files contain mesg -n or mesg n, this is a finding.
Fix Text (F-979r3_fix)
Edit /etc/profile or another global initialization script, and add the mesg -n command.