1.7.8 Ensure GDM autorun-never is enabled

Information

The autorun-never setting allows the GNOME Desktop Display Manager to disable autorun through GDM.

Malware on removable media may taking advantage of Autorun features when the media is inserted into a system and execute.

Solution

- IF - A user profile exists run the following command to set autorun-never to true for GDM users:

# gsettings set org.gnome.desktop.media-handling autorun-never true

Note:

- gsettings commands in this section MUST be done from a command window on a graphical desktop or an error will be returned.
- The system must be restarted after all gsettings configurations have been set in order for CIS-CAT Assessor to appropriately assess.
- If the dconf database is not updating correctly due to umask requirements contain in the benchmark, then use (umask 0022 && gsetting set) commands from above to temporarily set umask ensuring that any files or directories created by gsettings will have the required permissions.

- OR/IF - A lock does not exist:

- create the file /etc/dconf/db/local.d/locks/00-media-autorun with the following content:

[org/gnome/desktop/media-handling]
autorun-never=true <xhtml:ol start="2"> - Update the systems databases:

# dconf update

Note: Users must log out and back in again before the system-wide settings take effect.

See Also

https://workbench.cisecurity.org/benchmarks/18960

Item Details

Category: MEDIA PROTECTION

References: 800-53|MP-7, CSCv7|8.5

Plugin: Unix

Control ID: 3efb3fe812a28d220171846810c04c293521562d3b8d31c7f067aac94c3dde5b