[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

 
 
Paid content will be excluded from the download.

Filter
Matches : 194074 Download | Alert*

The group of the audit logs must be wheel. The audit files are under /var/audit; set the group for each via chgrp.

The permissions of the audit logs must be 0640 or as appropriate. The audit files are under /var/audit; set the permission for each via chmod.

The login window must be configured to prompt all users for both a username and a password. By default, the system displays a list of known users at the login screen. This gives an advantage to an attacker with physical access to the system, as the attacker would only have to guess the password for one of the listed accounts.

Controls whether the login window shows a list of non-local (other) users from which to choose when logging in, or shows fields in which a user and a password can be entered. In loginwindow.plist, set the SHOWOTHERUSERS_MANAGED key = false. If the key does not exist, a list of users is displayed.

The audit logs must not have extended ACLs. Use the chmod command to apply or remove the extended ACL permissions as appropriate.

Hide or display the shutdown button in the login window. In loginwindow.plist, set the ShutDownDisabled key = true to hide the button. If the key does not exist, the button is displayed.

The permissions of the audit configuration files must be 0555 or less. In /etc/security, audit_class, audit_control, audit_event, audit_warn, and audit_user permissions set via chmod.

Hide or display the sleep button in the login window. In loginwindow.plist, set the SleepDisabled key = true to hide the button. If the key does not exist, the button is displayed.

The audit tool executables should not have extended ACLs. Use the chmod command to apply or remove the extended ACL permissions as appropriate. In /usr/sbin, auditd, audit, auditreduce, and praudit set via chmod.

Controls when, and if, a password hint is given the user, based on the number of failed login attempts. In loginwindow.plist, set the RetriesUntilHint key = X to show a hint after X login failures, or set the key = 0 to disable hints.


Pages:      Start    11957    11958    11959    11960    11961    11962    11963    11964    11965    11966    11967    11968    11969    11970    ..   19407

© SecPod Technologies