RE: entry in /etc/passwd

From: Aaron Sierra (AaronS@webex.com)
Date: 05/03/02


From: Aaron Sierra <AaronS@webex.com>
To: "'focus-linux@securityfocus.com'" <focus-linux@securityfocus.com>
Date: Thu, 2 May 2002 16:27:15 -0700 

Per CIS hardening standard:
"'+' entries in various files used to be markers for systems to insert data
from NIS
maps at a certain point in a system configuration file. These entries are no
longer
required on Solaris systems, but may exist in files that have been imported
from other
platforms. These entries may provide an avenue for attackers to gain
privileged
access on the system, and should be deleted if they exist."

You may also want to check other files:
grep '^+:' /etc/passwd /etc/shadow /etc/group



Relevant Pages

  • Re: Setting the entry order in a NIS group file
    ... I have a scenario where the order of the entries in my NIS group is ... > created with the groups in seemingly random order. ... > NIS master just in case, but it has made no difference. ... The maps are hashed, so the order will be essentially random. ...
    (comp.sys.sun.admin)
  • Re: add lines between two markers
    ... I've got a file with those entries in the middle of the file: ... Now I want to insert these lines between the two markers: ... hello1 = tuesday ... hello2 = wednesday ...
    (comp.unix.shell)
  • add lines between two markers
    ... I've got a file with those entries in the middle of the file: ... Now I want to insert these lines between the two markers: ... hello1 = tuesday ... hello2 = wednesday ...
    (comp.unix.shell)
  • Re: comp.sys.hp.hpux FAQ
    ... why can't I find any entries when using the following searches (in ... Kind request: Could you perhaps use other markers for really recent ... additions/updates, i.e. the ones since the previous "Last-modified:" ...
    (comp.sys.hp.hpux)
  • Re: tao.thought.org is back.....
    ... It's hard to guess without seeing the log file entries for the rejected ... work, so my next guess is that I didn't restart my maps, databases ... Maps are not 'restarted'. ...
    (freebsd-questions)