GEN000880 M6 - The root account must be the only account having a UID of '0' - 'other users'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

If an account has a UID of '0', it has root authority. Multiple accounts with a UID of '0' afford more opportunity for potential intruders to guess a password for a privileged account.

Solution

Edit the /etc/passwd file and change the UID of the duplicate to an unused UID.

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-4, CAT|II, CCI|CCI-000366, Rule-ID|SV-37848r1_rule, STIG-ID|GEN000880-M6, Vuln-ID|V-773

Plugin: Unix

Control ID: a2a977d33393f70b2e5306db7ddb0ef0d6b76a478fa1b2af2a061e6de66e63db