Skip to content

All OL 8 local initialization files must have mode "0740" or less permissive.

An XCCDF Rule

Description

<VulnDiscussion>Local initialization files are used to configure the user's shell environment upon logon. Malicious modification of these files could compromise accounts upon logon.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-248645r779501_rule
Severity
Medium
References
Updated



Remediation - Manual Procedure

Set the mode of the local initialization files to "0740" with the following command: 
 
Note: The example will be for the smithj user, who has a home directory of "/home/smithj". 
 
$ sudo chmod 0740 /home/smithj/.<INIT_FILE>