1.7.4 Ensure access to /etc/motd is configured

Information

The contents of the /etc/motd file are displayed to users after login and function as a message of the day for authenticated users.

Rationale:

-IF- the /etc/motd file does not have the correct access configured, it could be modified by unauthorized users with incorrect or misleading information.

Solution

Run the following commands to set mode, owner, and group on /etc/motd:

# chown root:root $(readlink -e /etc/motd)
# chmod u-x,go-wx $(readlink -e /etc/motd)

-OR-
Run the following command to remove the /etc/motd file:

# rm /etc/motd

See Also

https://workbench.cisecurity.org/benchmarks/15287

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: 974bbe60f2804ec92d887ed64b737ad1ca9b119d9a051ca1b720c97aa3117572