Cis Ubuntu1204 V110 12 4

Verify User/Group Ownership on /etc/passwd

cyberstrikeus Updated

File contents

12.4 Verify User/Group Ownership on /etc/passwd (Scored)

Profile Applicability

  • Level 1

Description

The /etc/passwd file contains a list of all the valid userIDs defined in the system, but not the passwords. The command below sets the owner and group of the file to root.

Rationale

The /etc/passwd file needs to be protected from unauthorized changes by non-privileged users, but needs to be readable as this information is used with many non-privileged programs.

Audit Procedure

Using Command Line

Run the following command to determine the user and group ownership on the /etc/passwd file:

/bin/ls -l /etc/passwd

Expected Result

-rw-r--r-- 1 root root <size> <date> /etc/passwd

Owner should be root and group should be root.

Remediation

Using Command Line

If the user and group ownership of the /etc/passwd file are incorrect, run the following command to correct them:

/bin/chown root:root /etc/passwd

Default Value

root:root

References

  • CIS Ubuntu 12.04 LTS Server Benchmark v1.1.0

Profile

Level 1 - Scored

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-12-04-lts-server-benchmark/cis-ubuntu1204-v110-12-4 commit 21c99de912

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu1204-v110-12-4