GEN002230 M6 - All shell files must not have extended ACLs - '/etc/shells'

Information

Shells with world/group-write permissions give the ability to maliciously modify the shell to obtain unauthorized access.

Solution

Open a terminal session and use the following command to remove the extended ACLs.

chmod -N <shell file with extended ACL>

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(4), CAT|II, CCI|CCI-000225, Rule-ID|SV-38098r1_rule, STIG-ID|GEN002230-M6, Vuln-ID|V-22366

Plugin: Unix

Control ID: 9cabe8a6622af8c2a48f0728cd352284cb2eaeb6baf5e1ca2ecb4b90ae041418