GEN006080 - The Samba Web Administration Tool (SWAT) must be restricted to the local host or require SSL.

Information

SWAT is a tool used to configure Samba. As it modifies Samba configuration, which can impact system security, it must be protected from unauthorized access. SWAT authentication may involve the root password, which must be protected by encryption when traversing the network. Restricting access to the local host allows for the use of SSH TCP forwarding, if configured, or administration by a web browser on the local system.

Solution

Disable SWAT (e.g., remove the 'swat' line from inetd.conf or equivalent, and restart the service) or configure SSL protection for the SWAT service.

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R14_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17(8), CAT|II, CCI|CCI-001436, Group-ID|V-1026, Rule-ID|SV-1026r2_rule, STIG-ID|GEN006080, Vuln-ID|V-1026

Plugin: Unix

Control ID: 1194fa8892c97a8291add8c6350eb108fc2862395be3eb989c083dbbb32bff99