5.3 Set Sticky Bit on World Writable Directories

Information

When the so-called sticky bit (set with chmod +t) is set on a directory, then only the owner of a file may remove that file from the directory (as opposed to the usual behavior where anybody with write access to that directory may remove the file).

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

To set the sticky bit on a directory, run the following command-
chmod +t [directory name]

See Also

https://workbench.cisecurity.org/files/614

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Unix

Control ID: 97e2d261939fc8187affbe7fc190269cbee43a459b025a33074a90f26a865894