Information
The system is audited for group writable files that belong to one of the default AIX groups.
An audit should be performed on the system to search for the presence of group writable files and devices. (Directories are covered in a seperate recommendation).
The preference is no world writable files (objects) - using a group defined by system installation.
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.
Solution
- Review the currently mounted local filesystems using the following to find all world writable files on local JFS/JFS2 filesystems only:
- Note: the list generated by the command below is for all groups, not just the default system groups.
- the command without the argument -ls will create a list than can be fed to /usr/bin/xargs to blindly remove the group write permissions.
find -L / \( -fstype jfs -o -fstype jfs2 \) -type f -perm -g+w -ls
- Remedy any files in the list, e.g., chmod g-w {filename}
- Document any files, and motivate why they are group writeable, and also add documentation re: when/why this exception ceases.