Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-227580 | GEN000520 | SV-227580r854468_rule | Medium |
Description |
---|
If an application is providing a continuous display and is running with root privileges, unauthorized users could interrupt the process and gain root access to the system. |
STIG | Date |
---|---|
Solaris 10 X86 Security Technical Implementation Guide | 2022-09-07 |
Check Text ( C-36443r602932_chk ) |
---|
If there is an application running on the system continuously in use (such as a network monitoring application), ask the SA what the name of the application is. Execute the following to determine which user owns the process(es) associated with the application. If the owner is root, this is a finding. # ps -ef | more |
Fix Text (F-36407r602933_fix) |
---|
Configure the system so the owner of a session requiring a continuous screen display, such as a network management display, is not root. Ensure the display is also located in a secure, controlled access area. Document and justify this requirement. Ensure the terminal and keyboard for the display (or workstation) are secure from all but authorized personnel by maintaining them in a secure area, in a locked cabinet where a swipe card, or other positive forms of identification, must be used to gain entry. |