Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-89643 | VRAU-SL-000560 | SV-100293r1_rule | Medium |
Description |
---|
If the alias and aliases.db files are not owned by root, an unauthorized user may modify the file to add aliases to run malicious code or redirect email. |
STIG | Date |
---|---|
VMware vRealize Automation 7.x SLES Security Technical Implementation Guide | 2018-10-12 |
Check Text ( C-89335r1_chk ) |
---|
Check the ownership of the alias file: # ls -lL /etc/aliases # ls -lL /etc/aliases.db If all the files are not owned by "root", this is a finding. |
Fix Text (F-96385r1_fix) |
---|
Change the owner of the alias files to "root": # chown root /etc/aliases # chown root /etc/aliases.db |