Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-227714 | GEN002640 | SV-227714r603266_rule | Medium |
Description |
---|
Vendor accounts and software may contain backdoors allowing unauthorized access to the system. These backdoors are common knowledge and present a threat to system security if the account is not disabled. |
STIG | Date |
---|---|
Solaris 10 X86 Security Technical Implementation Guide | 2020-12-04 |
Check Text ( C-29876r488726_chk ) |
---|
Determine if default system accounts (such as, those for sys, bin, uucp, nuucp, daemon, smtp, gdm, lp, nobody) have been disabled. # cat /etc/shadow If an account's password field is "*", "*LK*", "NP", or is prefixed with a "!", the account is locked or disabled. If any default system account is not locked and its use is not justified and documented with the ISSO, this is a finding. |
Fix Text (F-29864r488727_fix) |
---|
Lock the default system account(s). # passwd -l |