6.2 Add 'nosuid' option to /etc/rmmount.conf, Check if nosuid option is set.

Information

Removable media is one vector by which malicious software can be introduced onto the system. By forcing these file systems to be mounted with the 'nosuid' option, the administrator prevents users from bringing set-UID programs onto the system via CDROMs and floppy disks. Note that this setting is included in the default rmmount.conf file on Solaris 8 and later.

See Also

https://workbench.cisecurity.org/files/633

Item Details

Audit Name: CIS Solaris 9 v1.3

Category: ACCESS CONTROL

References: 800-53|AC-6(10)

Plugin: Unix

Control ID: ef6da8a946515fc1d393b2ec3d53faf6a7eec85752a854b26781f1681bc621fe