File: group.yml

package info (click to toggle)
scap-security-guide 0.1.78-1
  • links: PTS, VCS
  • area: main
  • in suites: forky, sid
  • size: 114,600 kB
  • sloc: xml: 245,305; sh: 84,381; python: 33,093; makefile: 27
file content (19 lines) | stat: -rw-r--r-- 781 bytes parent folder | download | duplicates (5)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
documentation_complete: true

title: |-
    Verify Proper Storage and Existence of Password
    Hashes

description: |-
    By default, password hashes for local accounts are stored
    in the second field (colon-separated) in
    <tt>/etc/shadow</tt>. This file should be readable only by
    processes running with root credentials, preventing users from
    casually accessing others' password hashes and attempting
    to crack them.
    However, it remains possible to misconfigure the system
    and store password hashes
    in world-readable files such as <tt>/etc/passwd</tt>, or
    to even store passwords themselves in plaintext on the system.
    Using system-provided tools for password change/creation
    should allow administrators to avoid such misconfiguration.