From HP-UX 11.31 Security Technical Implementation Guide
Part of GEN002100
Associated with: CCI-000366
.rhosts files are used to specify a list of hosts permitted remote access to a particular account without authenticating. The use of such a mechanism defeats strong identification and authentication requirements.
Verify the remsh and rexec services have not been configured to use the PAM module: # cat /etc/pam.conf | tr '\011' ' ' | tr -s ' ' | sed -e 's/^[ \t]*//' | grep -v "^#" | grep "^rcomds" | egrep "auth|account" | egrep "libpam_unix|libpam_hpsec" If any of the following lines are returned, this is a finding. rcomds auth required libpam_hpsec.so.1 rcomds auth required libpam_unix.so.1 rcomds account required libpam_hpsec.so.1 rcomds account required libpam_unix.so.1
Edit /etc/pam.conf and comment/remove the "rcomds" line(s).
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer