GEN001780 - Global initialization files must contain the mesg -n or mesg n commands. - '/etc/security/.profile'

Information

If the mesg -n or mesg n command is not placed into the system profile, messaging can be used to cause a Denial of Service attack.

Solution

Edit /etc/profile or another global initialization script and add the mesg -n command.

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-38893r1_rule, STIG-ID|GEN001780, Vuln-ID|V-825

Plugin: Unix

Control ID: c4506edaae45fa0062cc40abbe9244ce5d6ce6e2cb2587b51807ac5450dfe7a8