STIGQter STIGQter: STIG Summary: VMware ESX 3 Server Version: 1 Release: 2 Benchmark Date: 22 Jul 2016: All files and directories contained in interactive user's home directories must be owned by the home directory's owner.

DISA Rule

SV-914r2_rule

Vulnerability Number

V-914

Group Title

GEN001540

Rule Version

GEN001540

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Change the ownership of files and directories in user's home directories to the owner of the home directory.

Procedure:
# chown accountowner filename
OR
# find /<usershomedirectory> ! -fstype nfs ! -user <username> ! /( -name .login -o -name .cshrc -o -name .logout -o -name .profile -o -name .bash_profile -o -name .bashrc -o -name .env -o -name .dtprofile -o -name .dispatch -o -name .emacs -o -name .exrc \) -exec chown <username> {} \;

Check Contents

For each user in the /etc/passwd file, check for the presence of files and directories within the user's home directory not owned by the home directory owner.

Procedure:
# find /<usershomedirectory> ! -fstype nfs ! -user <username> ! \( -name .login -o -name .cshrc -o -name .logout -o -name .profile -o -name .bash_profile -o -name .bashrc -o -name .env -o -name .dtprofile -o -name .dispatch -o -name .emacs -o -name .exrc \) -exec ls -ld {} \;

If user's home directories contain files or directories not owned by the home directory owner, this is a finding.

Vulnerability Number

V-914

Documentable

True

Rule Version

GEN001540

Severity Override Guidance

For each user in the /etc/passwd file, check for the presence of files and directories within the user's home directory not owned by the home directory owner.

Procedure:
# find /<usershomedirectory> ! -fstype nfs ! -user <username> ! \( -name .login -o -name .cshrc -o -name .logout -o -name .profile -o -name .bash_profile -o -name .bashrc -o -name .env -o -name .dtprofile -o -name .dispatch -o -name .emacs -o -name .exrc \) -exec ls -ld {} \;

If user's home directories contain files or directories not owned by the home directory owner, this is a finding.

Check Content Reference

M

Responsibility

Information Assurance Officer

Target Key

1386

Comments