GEN001590 M6 - Launch control scripts must not have extended ACLs - '/System/Library/LaunchAgents'

Information

If the launch control scripts are writable by other users, they could modify to insert malicious commands into the startup files.

Solution

Open a terminal session and enter the following command to remove the extended ACLs.

chmod -N <launch control script with extended ACL>

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(4), CAT|II, CCI|CCI-000225, Rule-ID|SV-38096r1_rule, STIG-ID|GEN001590-M6, Vuln-ID|V-22353

Plugin: Unix

Control ID: 94daf542d2b1af1f95f4e55bb439e1db7c949744c8796fa3a4a5bea6fcac67e1