6.1.10 Ensure no world writable files exist

Information

Unix-based systems support variable settings to control access to files. World writable files
are the least secure. See the chmod(2) man page for more information.

Rationale:

Data in world-writable files can be modified and compromised by any user on the system.
World writable files may also indicate an incorrectly written script or program that could
potentially be the cause of a larger compromise to the system's integrity.

Solution

Removing write access for the "other" category ( chmod o-w <filename> ) is advisable, but
always consult relevant vendor documentation to avoid breaking any application
dependencies on a given file.

See Also

https://workbench.cisecurity.org/files/2420

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-6, 800-53|SC-7(10), CSCv6|14, CSCv7|5.1, CSCv7|13

Plugin: Unix

Control ID: 6b03849930d6fb87fcf2477e3b38272d4d97bb00f95b337f39356bf4b453a66e