GEN001190 M6 - All network services daemon files must not have extended ACLs - '/usr/sbin/*'

Information

Restricting permission on daemons will protect them from unauthorized modification and possible system compromise.

Solution

Open a terminal session and enter the following command to remove the extended ACLs.

chmod -N /usr/sbin/ <file with extended ACL>

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(4), CAT|II, CCI|CCI-000225, Rule-ID|SV-38070r1_rule, STIG-ID|GEN001190-M6, Vuln-ID|V-22313

Plugin: Unix

Control ID: 0a108ef0184873becc26bc04faca22279a571638d410f20dc5ba34dabbc768aa