[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Ensure shadow group is empty

ID: oval:org.secpod.oval:def:68708Date: (C)2021-01-31   (M)2023-12-20
Class: COMPLIANCEFamily: unix




The shadow group allows system programs which require access the ability to read the /etc/shadow file. No users should be assigned to the shadow group. Rationale: Any users assigned to the shadow group would be granted read access to the /etc/shadow file. If attackers can gain read access to the /etc/shadow file, they can easily run a password cracking program against the hashed passwords to break them. Other security information that is stored in the /etc/shadow file (such as expiration) could also be useful to subvert additional user accounts.

Platform:
Ubuntu 18.04
Reference:
CCE-95655-7
CPE    1
cpe:/o:ubuntu:ubuntu_linux:18.04
CCE    1
CCE-95655-7
XCCDF    1
xccdf_org.secpod_benchmark_general_Ubuntu_18_04

© SecPod Technologies