Cis Ubuntu1604 V200 1 1 1 4

Ensure mounting of hfs filesystems is disabled

cyberstrikeus Updated

File contents

Ensure mounting of hfs filesystems is disabled

Description

The hfs filesystem type is a hierarchical filesystem that allows you to mount Mac OS filesystems.

Rationale

Removing support for unneeded filesystem types reduces the local attack surface of the system. If this filesystem type is not needed, disable it.

Impact

None noted.

Audit Procedure

Command Line

# modprobe -n -v hfs | grep -E '(hfs|install)'
# lsmod | grep hfs

Expected Result

install /bin/true

The lsmod command should return no output.

Remediation

Command Line

# Edit or create a file in the /etc/modprobe.d/ directory ending in .conf
# Example: vi /etc/modprobe.d/hfs.conf
# and add the following line:
install hfs /bin/true

# Run the following command to unload the hfs module:
rmmod hfs

Default Value

Not disabled by default.

References

  • CIS Controls Version 7 - 5.1 Establish Secure Configurations: Maintain documented, standard security configuration standards for all authorized operating systems and software.

Profile

Level 1 - Server / Level 1 - Workstation, Assessment: Automated

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-linux-16-04-lts-benchmark-v2/cis-ubuntu1604-v200-1-1-1-4 commit 65837b5a64

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu1604-v200-1-1-1-4