1.8.4 Ensure permissions on /etc/motd are configured

Information

The contents of the /etc/motd file are displayed to users after login and function as a message of the day for authenticated users.

Note: If Message of the day is not needing, this file can be removed.

Rationale:

If the /etc/motd file does not have the correct ownership it could be modified by unauthorized users with incorrect or misleading information.

Solution

Run the following commands to set permissions on /etc/motd :

# chown root:root /etc/motd

# chmod u-x,go-wx /etc/motd

OR
Run the following command to remove the /etc/motd file:

# rm /etc/motd

See Also

https://workbench.cisecurity.org/files/2920

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|3.1, CSCv7|5.1

Plugin: Unix

Control ID: ddf5e68237f0848f9b9f9092ee19d857f66156a9d6b7f902d78562ca3afbd469