Information
If NIS has been de-installed in the environment, or has historically been used, ensure the + markers are removed from/etc/passwd and /etc/group.
Rationale:
The + entries in /etc/passwd and /etc/group were used as markers to insert data from a NIS map. These entries may provide an avenue for attackers to gain privileged access on the system. The + entries must be deleted if they still exist.
Solution
Examine the /etc/passwd and /etc/group files:
grep '^+' /etc/passwd /etc/group
If the above command yields output, delete the + line:
vi /etc/passwd
vi /etc/group
Default Value:
N/A
Additional Information:
Reversion:
Add the + line back to the same point in the file/s:
vi /etc/passwd
vi /etc/group