Rule ID
SV-45095r1_rule
Version
V1R12
CCIs
Global initialization files are used to configure the user's shell environment upon login. Malicious modification of these files could compromise accounts upon logon.
Check global initialization files permissions: # ls -l /etc/bash.bashrc # ls -l /etc/csh.cshrc # ls -l /etc/csh.login # ls -l /etc/environment # ls -l /etc/ksh.kshrc # ls -l /etc/profile # ls -l /etc/profile.d/* # ls -l /etc/zshrc If global initialization files are more permissive than 0644, this is a finding.
Change the mode of the global initialization file(s) to 0644. # chmod 0644 <global initialization file>