SV-270703r1066598_rule
V-270703
SRG-OS-000259-GPOS-00100
UBTU-24-300013
CAT II
10
Configure the system commands to be protected from unauthorized access. Run the following command, replacing "[FILE]" with any system command file not group-owned by "root" or a required system account:
$ sudo chgrp [SYSTEMACCOUNT] [FILE]
Verify the system commands contained in the following directories are group-owned by root or a required system account with the following command:
$ find /bin /sbin /usr/bin /usr/sbin /usr/local/bin /usr/local/sbin \-type f -perm -u=x -exec stat --format="%n %G" {} + | \awk '$2 != "root" && $2 != "daemon" && $2 != "adm" && $2 != "shadow" && $2 != "mail" && $2 != "crontab" && $2 != "_ssh"'
Note: The above command uses awk to filter out common system accounts. If your system uses other required system accounts, add them to the awk condition to filter them out of the results.
If any system commands are returned that are not group-owned by a required system account, this is a finding.
V-270703
False
UBTU-24-300013
Verify the system commands contained in the following directories are group-owned by root or a required system account with the following command:
$ find /bin /sbin /usr/bin /usr/sbin /usr/local/bin /usr/local/sbin \-type f -perm -u=x -exec stat --format="%n %G" {} + | \awk '$2 != "root" && $2 != "daemon" && $2 != "adm" && $2 != "shadow" && $2 != "mail" && $2 != "crontab" && $2 != "_ssh"'
Note: The above command uses awk to filter out common system accounts. If your system uses other required system accounts, add them to the awk condition to filter them out of the results.
If any system commands are returned that are not group-owned by a required system account, this is a finding.
M
5673