SV-215419r508663_rule
V-215419
SRG-OS-000480-GPOS-00227
AIX7-00-003124
CAT II
10
Edit the "/etc/hosts.allow" and "/etc/hosts.deny" files to configure access restrictions.
Add "ALL: ALL" entry to "/etc/hosts.deny" file.
Check for the existence of the "/etc/hosts.allow" and "/etc/hosts.deny" files using commands:
# ls -la /etc/hosts.allow
-rw-r--r-- 1 root system 11 Jan 28 11:09 /etc/hosts.allow
# ls -la /etc/hosts.deny
-rw-r--r-- 1 root system 0 Jan 28 11:02 /etc/hosts.deny
If either file does not exist, this is a finding.
Check for the presence of a default deny entry using command:
# grep -E "ALL:[[:blank:]]*ALL" /etc/hosts.deny
ALL:ALL
If the "ALL: ALL" entry is not present in the "/etc/hosts.deny" file, any TCP service from a host or network not matching other rules will be allowed access.
If the entry is not in "/etc/hosts.deny", this is a finding.
V-215419
False
AIX7-00-003124
Check for the existence of the "/etc/hosts.allow" and "/etc/hosts.deny" files using commands:
# ls -la /etc/hosts.allow
-rw-r--r-- 1 root system 11 Jan 28 11:09 /etc/hosts.allow
# ls -la /etc/hosts.deny
-rw-r--r-- 1 root system 0 Jan 28 11:02 /etc/hosts.deny
If either file does not exist, this is a finding.
Check for the presence of a default deny entry using command:
# grep -E "ALL:[[:blank:]]*ALL" /etc/hosts.deny
ALL:ALL
If the "ALL: ALL" entry is not present in the "/etc/hosts.deny" file, any TCP service from a host or network not matching other rules will be allowed access.
If the entry is not in "/etc/hosts.deny", this is a finding.
M
4012