6.2.3 Ensure no legacy "+" entries exist in /etc/shadow (Scored)

Level 1 - Server
Level 1 - Workstation 

The character + in various files used to be markers for systems to insert data from NIS maps at a certain point in a system configuration file. These entries are no longer required on most systems, but may exist in files that have been imported from other platforms.

These entries may provide an avenue for attackers to gain privileged access on the system.

Run the following command and verify that no output is returned:

# grep '^+:' /etc/shadow

Remove any legacy '+' entries from /etc/shadow if they exist.

  • centos7/6/2/3.txt
  • Last modified: 2017/05/04 20:02
  • by 127.0.0.1