GEN003790 - The services file must not have an extended ACL.

Information

The services file is critical to the proper operation of network services and must be protected from unauthorized modification. If the services file has an extended ACL, it may be possible for unauthorized users to modify the file. Unauthorized modification could result in the failure of network services.

Solution

Remove the extended ACL from the file.
# setfacl --remove-all /etc/services

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R17_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CAT|II, CCI|CCI-000225, Group-ID|V-22428, Rule-ID|SV-37438r1_rule, STIG-ID|GEN003790

Plugin: Unix

Control ID: c1bddf08c3fce61d5c28465a8c351df31c0fbd706833f87f3d277e997342ed4c