GEN001780 - Global initialization files must contain the 'mesg -n' or 'mesg n' commands - '/etc/suid_profile'

Information

If the 'mesg -n' or 'mesg n' command is not placed into the system profile, messaging can be used to cause a Denial of Service attack.

Solution

Edit /etc/profile or another global initialization script, and add the 'mesg -n' command.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Group-ID|V-825, Rule-ID|SV-37289r1_rule, STIG-ID|GEN001780, Vuln-ID|V-825

Plugin: Unix

Control ID: 5872c38bb07a6ecc2a898e2043a3448cd57237b841c3a9f746cf12ceb668238e