6.2.3 Ensure no legacy '+' entries exist in /etc/passwd - + entries exist in /etc/passwd

Information

The character + in various files used to be markers for systems to insert data from NIS maps at a certain point in a system configuration file. These entries are no longer required on most systems, but may exist in files that have been imported from other platforms.

Rationale:

These entries may provide an avenue for attackers to gain privileged access on the system.

Solution

Remove any legacy '+' entries from /etc/passwd if they exist.

See Also

https://workbench.cisecurity.org/files/3152

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5, 800-53|IA-5(1), CSCv6|16.9, CSCv7|16.4

Plugin: Unix

Control ID: 0f886b5f025bfdd478227fb56f9ebb56c21e23ed90ad2353c6094e9bdb3472c6