1.7.4 Ensure permissions on /etc/motd are configured

Information

The contents of the /etc/motd file are displayed to users after login and function as a message of the day for authenticated users.

If the /etc/motd file does not have the correct ownership it could be modified by unauthorized users with incorrect or misleading information.

Solution

Run the following commands to set permissions on /etc/motd :

# chown root:root $(readlink -e /etc/motd)
# chmod u-x,go-wx $(readlink -e /etc/motd)

-- OR --

Run the following command to remove the /etc/motd file:

# rm /etc/motd

See Also

https://workbench.cisecurity.org/benchmarks/15023

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: 46e7dc0c24a8c958c46e5e1b9d481fd8a91f33ede8d6f3f46e8704886a63c63f