3.2 Restrict Core Dumps to Protected Directory - Check if permissions for /var/cores are OK.

Information

Level: 1

Solution

To restrict core files to a protected directory, run the following commands-

mkdir -p /var/cores

chown root:root /var/cores

chmod 700 /var/cores

coreadm -g /var/cores/core_%n_%f_%u_%g_%t_%p -e log -e global -e global-setid -d process -d proc-setid

If the local site chooses, dumping of core files can be completely disabled with the following command-

coreadm -d global -d global-setid -d process -d proc-setid

See Also

https://benchmarks.cisecurity.org/tools2/solaris/CIS_Oracle_Solaris_10_Benchmark_v5.2.0.pdf

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6

Plugin: Unix

Control ID: d37187421f3669301ace5f3d759612497ecda40ef102fe45898bbd4527bb9d20