13.10 Check for Presence of User .rhosts Files

Information

While no .rhosts files are shipped by default, users can easily create them. This action is only meaningful if .rhosts support is permitted in the file /etc/pam.conf. Even though the .rhosts files are ineffective if support is disabled in /etc/pam.conf, they may have been brought over from other systems and could contain information useful to an attacker for those other systems.

Solution

If any users have .rhosts files determine why they have them.

See Also

https://workbench.cisecurity.org/files/85

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1

Plugin: Unix

Control ID: 41227824fbb42b3cf15830270711f44b52e2d869c87c3f188da3f21d350b066e