| name | cis-ubuntu2004-v300-7-1-13 |
| description | Ensure SUID and SGID files are reviewed |
| category | cis-iam |
| version | 3.0.0 |
| author | cyberstrike-official |
| tags | ["cis","ubuntu","linux","ubuntu-20.04","file-permissions"] |
| cis_id | 7.1.13 |
| cis_benchmark | CIS Ubuntu Linux 20.04 LTS Benchmark v3.0.0 |
| tech_stack | ["ubuntu","linux"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
7.1.13 Ensure SUID and SGID files are reviewed (Manual)
Profile
- Level 1 - Server
- Level 1 - Workstation
Description
The owner of a file can set the file's permissions to run with the owner's or group's permissions, even if the user running the program is not the owner or a member of the group. The most common reason for a SUID or SGID program is to enable users to perform functions (such as changing their password) that require root privileges.
Rationale
There are valid reasons for SUID and SGID programs, but it is important to identify and review such programs to ensure they are legitimate. Review the files returned by the action in the audit section and check to see if system binaries have a different checksum than what from the package. This is an indication that the binary may have been replaced.
Impact
None
Audit Procedure
Command Line
Run the following script to generate a list of SUID and SGID files:
#!/usr/bin/env bash
{
l_output="" l_output2=""
a_suid=(); a_sgid=()
while IFS= read -r l_mount; do
while IFS= read -r -d $'\0' l_file; do
if [ -e "$l_file" ]; then
l_mode="$(stat -Lc '%#a' "$l_file")"
[ $(( $l_mode & 04000 )) -gt 0 ] && a_suid+=("$l_file")
[ $(( $l_mode & 02000 )) -gt 0 ] && a_sgid+=("$l_file")
fi
done < <(find "$l_mount" -xdev -type f \( -perm -2000 -o -perm -4000 \) -print0 2>/dev/null)
< <(findmnt -Dkerno fstype,target,options | awk )
! (( > ));
l_output=
l_output2=
! (( > ));
l_output=
l_output2=
[ -n ] && l_output2=
a_arr; a_suid; a_sgid
[ -z ];
-e
-e
[ -n ] && -e
}