4.6 Capture All Failed Login Attempts - Check if SYSLOG_FAILED_LOGINS is set to 0 in /etc/default/login.

Information

The SYS_FAILED_LOGINS variable is used to determine how many failed login attempts occur before a failed login message is logged. Setting the value to 0 will cause a failed login message on every failed login attempt.

Solution

Perform the following to implement the recommended state-
cd /etc/default
awk '/SYSLOG_FAILED_LOGINS=/ { $1 = 'SYSLOG_FAILED_LOGINS=0' }; { print }' login >login.new
mv login.new login # pkgchk -f -n -p /etc/default/login

See Also

https://workbench.cisecurity.org/files/614

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: Unix

Control ID: 5e8469c3035fdbfcf736b5b80172a239276c825ffd42d78eb3db997e54dbe5a2