BSI-100-2: S 5.18: Use of the NIS security mechanisms: The file /etc/group must not contain the entry +::0:0:::

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The file /etc/group must not contain the entry +::0:0::: since otherwise access with the name '+' without a password is possible. Should the entry be necessary, the password must be replaced by '*' (you must check whether access has actually been blocked!). Nevertheless, there still will be the risk that, in case of inadvertent deletion of the first column (i.e. '+'), privileged access will be possible without a password and without a user name.

The situation is similar as regards the group file /etc/group and all other security-relevant files which are to be made accessible network-wide through the NIS, e.g. /etc/hosts, etc/group, or etc/bootparams.

Safeguard Catalogues: S 5: Communications

S 5.18: Use of the NIS security mechanisms

See Also

https://www.bsi.bund.de/cae/servlet/contentblob/471430/publicationFile/28223/standard_100-2_e_pdf.pdf

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|3.1

Plugin: Unix

Control ID: 8866434aca72ce9b200ee9992d8488a2a9d83544697d8f45d57b457d1ee51fdf