UCF STIG Viewer Logo

All system start-up files must be group-owned by root, sys, bin, other, or system.


Overview

Finding ID Version Rule ID IA Controls Severity
V-4090 GEN001680 M6 SV-38018r1_rule ECLP-1 Medium
Description
If system start-up files do not have a group owner of root or a system group, the files may be modified by malicious users or intruders.
STIG Date
MAC OSX 10.6 Workstation Security Technical Implementation Guide Draft 2013-01-10

Details

Check Text ( C-37369r1_chk )
Open a terminal session and enter the following command to verify the ownership is set to the original installation settings.

diskutil verifyPermissions /

If files are shown with incorrect ownership, this is a finding.
Fix Text (F-32606r1_fix)
Open a terminal session and enter the following command to reset the file ownership to their original settings.

diskutil repairPermissions /