0043-libbin-priv-/bin Directory File Permission Modified
Rule ID
Category
Level
Compatible Versions
Description
- Monitor whether file permissions under the host
/bin directory have been modified.
Scan Frequency
Rationale
- The
/bin directory contains executable files for essential system commands. If permissions are changed, commands may become unexecutable, affecting the system.
Risk Items
Audit Method
- Run the following command on the specified file (using
users as an example) and verify that Uid and Gid are both 0/root and permissions are 755:
stat /bin/users
Access: (0755/-rwxr-xr-x) Uid: ( 0/ root) Gid: ( 0/ root)
- If file permissions under the
/bin directory are detected to have been changed, log in to the server as the root user, restore the permissions, and audit the change.
Impact
Default Value
References
CIS Controls