| name | cis-ubuntu1604-v200-6-2-8 |
| description | Ensure no users have .netrc files |
| category | cis-iam |
| version | 2.0.0 |
| author | cyberstrike-official |
| tags | ["cis","ubuntu","linux","ubuntu-16.04","user-management","maintenance"] |
| cis_id | 6.2.8 |
| cis_benchmark | CIS Ubuntu Linux 16.04 LTS Benchmark v2.0.0 |
| tech_stack | ["ubuntu","linux"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
CIS Ubuntu Linux 16.04 LTS Benchmark v2.0.0 - Control 6.2.8
Profile
- Level: 1 - Server
- Level: 1 - Workstation
- Assessment Status: Automated
Description
The .netrc file contains data for logging into a remote host for file transfers via FTP.
While the system administrator can establish secure permissions for users' .netrc files, the users can easily override these.
Note: While the complete removal of .netrc files is recommended, if any are required on the system secure permissions must be applied.
Rationale
The .netrc file presents a significant security risk since it stores passwords in unencrypted form. Even if FTP is disabled, user accounts may have brought over .netrc files from other systems which could pose a risk to those systems.
If a .netrc file is required, and follows local site policy, it should have permissions of 600 or more restrictive.
Audit Procedure
Command Line
Run the following script. This script will return:
FAILED: for any .netrc file with permissions less restrictive than 600
WARNING: for any .netrc files that exist in interactive users' home directories.
#!/bin/bash
awk -F: '($1!~/(halt|sync|shutdown)/ && $7!~/^(\/usr)?\/sbin\/nologin(\/)?\$/
&& $7!~/(\/usr)?\/bin\/false(\/)?\$/) { print $1 " " $6 }' /etc/passwd | while
read -r user dir; do
if [ -d "$dir" ]; then
file="$dir/.netrc"
if [ ! -h "$file" ] && [ -f "$file" ]; then
if -L -c | -c4-10 | grep -Eq ;