Cis Ubuntu1204 V110 12 3

Verify Permissions on /etc/group

cyberstrikeus Updated

File contents

12.3 Verify Permissions on /etc/group (Scored)

Profile Applicability

  • Level 1

Description

The /etc/group file contains a list of all the valid groups defined in the system. The command below allows read/write access for root and read access for everyone else.

Rationale

The /etc/group file needs to be protected from unauthorized changes by non-privileged users, but needs to be readable as this information is used with many non-privileged programs.

Audit Procedure

Using Command Line

Run the following command to determine the permissions on the /etc/group file:

/bin/ls -l /etc/group

Expected Result

-rw-r--r-- 1 root root <size> <date> /etc/group

Permissions should be 644 or more restrictive.

Remediation

Using Command Line

If the permissions of the /etc/group file are incorrect, run the following command to correct them:

/bin/chmod 644 /etc/group

Default Value

644

References

  • CIS Ubuntu 12.04 LTS Server Benchmark v1.1.0

Profile

Level 1 - Scored

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-12-04-lts-server-benchmark/cis-ubuntu1204-v110-12-3 commit 9cff984394

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu1204-v110-12-3