GEN001590 - All run control scripts must have no extended ACLs - '/etc/init.d'

Information

If the startup files are writable by other users, they could modify the startup files to insert malicious commands into the startup files.

Solution

Remove the extended ACL from the run control script(s) and disable extended permissions.

#acledit <directory>/<file>

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R13_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CAT|II, CCI|CCI-000225, Group-ID|V-22353, Rule-ID|SV-38733r1_rule, STIG-ID|GEN001590

Plugin: Unix

Control ID: 8ae5e3da9a40eefab4186d86b84e09a75a955d9517f90b21074ea729737ebaf0