1.1.20 Ensure sticky bit is set on all world-writable directories

Information

Setting the sticky bit on world writable directories prevents users from deleting or renaming files in that directory that are not owned by them.
Rationale:
This feature prevents the ability to delete or rename files in world writable directories (such as /tmp ) that are owned by another user.

Solution

Run the following command to set the sticky bit on all world writable directories:
# df --local -P | awk {'if (NR!=1) print $6'} | xargs -I '{}' find '{}' -xdev -type d -perm -0002 2>/dev/null | xargs chmod a+t
Notes:
Some distributions may not support the --local option to df.

See Also

https://workbench.cisecurity.org/files/2429

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(3), CSCv6|13, CSCv7|5.1

Plugin: Unix

Control ID: 58bab2a87f39ff55aa4f736290843b31bacab59f3fd8ce0631a06f26d92a97e3