GEN005880 - The NFS server must not allow remote root access - 'no_root_squash'

Information

If the NFS server allows root access to local file systems from remote hosts, this access could be used to compromise the system.

Solution

Edit the '/etc/exports' file and add 'root_squash' (or 'all_squash') and remove 'no_root_squash'.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCE|CCE-4544-3, CCI|CCI-000225, Group-ID|V-935, Rule-ID|SV-37859r1_rule, STIG-ID|GEN005880, Vuln-ID|V-935

Plugin: Unix

Control ID: 6f9e162f5f6339a2bdd1fd0353a9d7de16b0c03595f590c9fb04dcd76224c1c1