6.2.4 Ensure no legacy "+" entries exist in /etc/group

Information

The character + in various files used to be markers for systems to insert data from NIS
maps at a certain point in a system configuration file. These entries are no longer required
on most systems, but may exist in files that have been imported from other platforms.

Rationale:

These entries may provide an avenue for attackers to gain privileged access on the system.

Solution

Remove any legacy '+' entries from /etc/group if they exist.,CSCv6|16.9,CSCv7|16.2

See Also

https://workbench.cisecurity.org/files/2420

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2, CSCv6|16.9, CSCv7|16.2

Plugin: Unix

Control ID: d42c909856332a0d7a02a02e211e37ce950858afd6fbfffab3900827905713a5