Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-773 | GEN000880 M6 | SV-37848r1_rule | ECLP-1 IAIA-1 IAIA-2 | Medium |
Description |
---|
If an account has a UID of “0”, it has root authority. Multiple accounts with a UID of “0” afford more opportunity for potential intruders to guess a password for a privileged account. |
STIG | Date |
---|---|
MAC OSX 10.6 Workstation Security Technical Implementation Guide | 2013-04-09 |
Check Text ( C-37044r1_chk ) |
---|
Enter the following command to view users with a UID of "0": grep :0 /etc/passwd If any user other than root has a UID of "0", this is a finding. |
Fix Text (F-32312r1_fix) |
---|
Edit the /etc/passwd file and change the UID of the duplicate to an unused UID. |