1.6.4 Ensure access to /etc/motd is configured

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The contents of the /etc/motd file are displayed to users after login and function as a message of the day for authenticated users.

- IF - the /etc/motd file does not have the correct access configured, it could be modified by unauthorized users with incorrect or misleading information.

Solution

Run the following commands to set mode, owner, and group on /etc/motd :

# chown root:root $(readlink -e /etc/motd)
# chmod u-x,go-wx $(readlink -e /etc/motd)

- OR -

Run the following command to remove the /etc/motd file:

# rm /etc/motd

See Also

https://workbench.cisecurity.org/benchmarks/17331