Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-769 | GEN000520 | SV-37232r1_rule | PESL-1 | Medium |
Description |
---|
If an application is providing a continuous display and is running with root privileges, unauthorized users could interrupt the process and gain root access to the system. |
STIG | Date |
---|---|
Red Hat Enterprise Linux 5 Security Technical Implementation Guide | 2016-06-01 |
Check Text ( C-35914r1_chk ) |
---|
If there is an application running on the system continuously in use (such as a network monitoring application), ask the SA what the name of the application is. Verify documentation exists for the requirement and justification of the application. If no documentation exists, this is a finding. Execute "ps -ef | more" to determine which user owns the process(es) associated with the application. If the owner is root, this is a finding. |
Fix Text (F-31178r1_fix) |
---|
Configure the system so the owner of a session requires a continuous screen display, such as a network management display, is not root. Ensure the display is also located in a secure, controlled access area. Document and justify this requirement and ensure the terminal and keyboard for the display (or workstation) are secure from all but authorized personnel by maintaining them in a secure area, in a locked cabinet where a swipe card, or other positive forms of identification, must be used to gain entry. |