6.2.3 Ensure no legacy "+" entries exist in /etc/shadow

Information

The character + in various files used to be markers for systems to insert data from NIS maps at a certain point in a system configuration file. These entries are no longer required on most systems, but may exist in files that have been imported from other platforms.

Rationale:

These entries may provide an avenue for attackers to gain privileged access on the system.

Solution

Remove any legacy '+' entries from /etc/shadow if they exist.

See Also

https://workbench.cisecurity.org/files/2449

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv7|5.1

Plugin: Unix

Control ID: ecfd61c0dcb87c1098ceb640a30f2047d2ec37f6b8946787d0a570103a7c3128