GEN001540 - All files and directories contained in interactive user home directories must be owned by the home directorys owner.

Information

If users do not own the files in their directories, unauthorized users may be able to access them. Additionally, if files are not owned by the user, this could be an indication of system compromise.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Change the ownership of files and directories in user home directories to the owner of the home directory.

Procedure:
# chown accountowner filename

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V2R1_STIG.zip

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT

References: 800-53|AC-6, 800-53|CM-6b., CAT|III, CCI|CCI-000225, CCI|CCI-000366, Rule-ID|SV-218312r603259_rule, STIG-ID|GEN001540, STIG-Legacy|SV-63831, STIG-Legacy|V-914, Vuln-ID|V-218312

Plugin: Unix

Control ID: 4f64feab216140f6a75d5b7fd99deb9e8b920ad288a1726385b42fd6da3fadd3