BSI-100-2: S 5.18: Use of the NIS security mechanisms: The file /etc/passwd must not contain the entry +::0:0:::

Information

The file /etc/passwd must not contain the entry +::0:0::: since otherwise access with the name '+' without a password is possible. Should the entry be necessary, the password must be replaced by '*' (you must check whether access has actually been blocked!). Nevertheless, there still will be the risk that, in case of inadvertent deletion of the first column (i.e. '+'), privileged access will be possible without a password and without a user name.

The situation is similar as regards the group file /etc/group and all other security-relevant files which are to be made accessible network-wide through the NIS, e.g. /etc/passwd, etc/group, or etc/bootparams.

Safeguard Catalogues: S 5: Communications

S 5.18: Use of the NIS security mechanisms

See Also

https://www.bsi.bund.de/cae/servlet/contentblob/471430/publicationFile/28223/standard_100-2_e_pdf.pdf

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2

Plugin: Unix

Control ID: 86327bca056814d70809b6e64e19cf9d55322876280c12b0cfc35f86e053b1e4