Rule ID
SV-216183r959010_rule
Version
V3R5
CCIs
.netrc files may contain unencrypted passwords that can be used to attack other systems.
The root role is required.
Check that permissions on user .netrc files are 750 or less permissive.
# for dir in \
`logins -ox | awk -F: '($8 == "PS") { print $6 }'`; do
find ${dir}/.netrc -type f \( \
-perm -g+r -o -perm -g+w -o -perm -g+x -o \
-perm -o+r -o -perm -o+w -o -perm -o+x \) \
-ls 2>/dev/null
done
If output is produced, this is a finding.The root role is required. Change the permissions on users' .netrc files to 750 or less permissive. # chmod 750 [file name]