SV-219187r610963_rule
V-219187
SRG-OS-000138-GPOS-00069
UBTU-18-010120
CAT II
10
Configure all public directories to have the sticky bit set to prevent unauthorized and unintended information transferred via shared system resources.
Set the sticky bit on all public directories using the command, replace "[Public Directory]" with any directory path missing the sticky bit:
# sudo chmod +t [Public Directory]
Verify that all public (world writeable) directories have the public sticky bit set.
Find world-writable directories that lack the sticky bit by running the following command:
# sudo find / -type d -perm -002 ! -perm -1000
If any world-writable directories are found missing the sticky bit, this is a finding.
V-219187
False
UBTU-18-010120
Verify that all public (world writeable) directories have the public sticky bit set.
Find world-writable directories that lack the sticky bit by running the following command:
# sudo find / -type d -perm -002 ! -perm -1000
If any world-writable directories are found missing the sticky bit, this is a finding.
M
4055