4.1.2.6 Ensure access on /var/adm/ras is configured

Information

The /var/adm/ras directory contains log files which contain sensitive information such as login times and IP addresses.

The log files in the /var/adm/ras directory can contain sensitive information such as login times and IP addresses, which may be altered by an attacker when removing traces of system access. All files in this directory must be secured from unauthorized access and modifications.

Solution

Remove world read and write access from all files in /var/adm/ras :

chmod o-rw /var/adm/ras/*

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: 659740863e40a6fdb19389c5167631e17a8bb94004a5a0e116ac6dc10fd22515