UCF STIG Viewer Logo

All system startup files must be group-owned by root, sys, bin or other.


Overview

Finding ID Version Rule ID IA Controls Severity
V-4090 GEN001680 SV-38421r1_rule ECLP-1 Medium
Description
If system startup files do not have a group owner of root or a system group, the files may be modified by malicious users or intruders.
STIG Date
HP-UX 11.31 Security Technical Implementation Guide 2018-09-14

Details

Check Text ( C-36373r2_chk )
System start-up files are identified as follows:

Run control scripts reside in the /sbin/init.d directory.

Links to the run control scripts exist in the /sbin/rc*.d directories.

Run control script configuration files exist in the /etc/rc.config.d directory.

Check system start-up script file group ownership.
# ls -lL /sbin/init.d/* /etc/rc.config.d/* /etc/rc.config.d/*

If any system start-up script file is not group-owned by root, sys, bin or other, this is a finding.
Fix Text (F-31711r1_fix)
Change the group ownership of the run control script(s) with incorrect group ownership.

Procedure:
# chgrp root