9.11 Check Permissions on User .netrc Files

Information

While the system administrator can establish secure permissions for users' .netrc files, the users can easily override these.

Rationale:

.netrc files may contain unencrypted passwords that can be used to attack other systems.

Solution

Correct or justify any items discovered in the Audit step. Determine if any user .netrc files are group- or world-readable or writable, and work with those users to determine the best course of action in accordance with site policy.

See Also

https://workbench.cisecurity.org/benchmarks/4777

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: 71c6d98db2a23d86596182ff57f45b99ec796a527d2b4e7447f360791591fe88