GEN000000-AIX0110 - The /etc/netsvc.conf file must not have an extended ACL.

Information

The /etc/netsvc.conf file is used to specify the ordering of name resolution for the sendmail command, alias resolution for the sendmail command, and host name resolution routines. Malicious changes could prevent the system from functioning correctly or compromise system security.

Solution

Remove the extended ACL from the /etc/nsswitch.conf file and disable extended permissions.

#acledit /etc/netsvc.conf

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R14_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Group-ID|V-29494, Rule-ID|SV-38698r1_rule, STIG-ID|GEN000000-AIX0110, Vuln-ID|V-29494

Plugin: Unix

Control ID: 41e60715bcd33d6917873566c07615ac2f01bbd3577946fcd85b78caae62ff7b