GEN000000-AIX0090 - The /etc/netsvc.conf file must be group-owned by bin, sys, or system.

Information

The /etc/netsvc.conf file is used to specify the ordering of name resolution for the sendmail command, alias resolution for the sendmail command, and host name resolution routines. Malicious changes could prevent the system from functioning correctly or compromise system security.

Solution

Change the group owner of the /etc/netsvc.conf file to bin, sys, or system.

Procedure:
# chgrp system /etc/netsvc.conf

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R14_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Group-ID|V-29492, Rule-ID|SV-38696r1_rule, STIG-ID|GEN000000-AIX0090, Vuln-ID|V-29492

Plugin: Unix

Control ID: d07e0fca5d33c6eeef9016098903438e7ab0110ac660e8d0f6bc7f3b46e8688e