3.4 Ensure world writable files are secured

Information

The system is audited for world writable files.

An audit should be performed on the system to search for the presence of world writable files.

In an extreme case - where this permission is required - the file needs to be added to the TSD and audit configurations.

The preference is no world writeable files.

Solution

Run the following command to remove the write bit from other:

find / \( -fstype jfs -o -fstype jfs2 \) -type f -perm -o+w -exec chmod o-w {} +

See Also

https://workbench.cisecurity.org/benchmarks/19066

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: e1428efc1b091bcef7fc72b4d840034d7aeb358707d0760e8ffe83ea3c4ec7c4