コンテンツにスキップ

0021-profile-exist-グローバル環境変数設定ファイルの存在確認


ルールID

  • 0021-profile-exist

カテゴリ

  • system

レベル

  • critical

対応バージョン

  • Linux

説明

  • ホスト上の/etc/profileの存在を監視します

スキャン頻度

  • 1 */5 * * *

理論的根拠

リスク項目

  • サービスが利用不可

監査方法

  • ホスト上の/etc/profileを確認します。以下のコマンドを実行して確認できます:
ls /etc/profile

復旧手順

  • /etc/profileが削除された場合は、以下のコマンドを実行してください:

       export PATH=/usr/bin:/usr/sbin:/bin:/sbin:/usr/X11R6/bin
    
    vim /etc/profile でprofileファイルを新規作成し、以下のコマンドをコピーして貼り付け、source /etc/profileを実行してファイルを即座に有効にします
    # /etc/profile
    
     # System wide environment and startup programs, for login setup
     # Functions and aliases go in /etc/bashrc
    
     # It"s NOT a good idea to change this file unless you know what you
     # are doing. It"s much better to create a custom.sh shell script in
     # /etc/profile.d/ to make custom changes to your environment, as this
     # will prevent the need for merging in future updates.
    
     pathmunge () {
         case ":${PATH}:" in
             *:"$1":*)
                 ;;
             *)
                 if [ "$2" = "after" ] ; then
                     PATH=$PATH:$1
                 else
                     PATH=$1:$PATH
                 fi
         esac
     }
    
    
     if [ -x /usr/bin/id ]; then
         if [ -z "$EUID" ]; then
             # ksh workaround
             EUID=`id -u`
             UID=`id -ru`
         fi
         USER="`id -un`"
         LOGNAME=$USER
         MAIL="/var/spool/mail/$USER"
     fi
    
     # Path manipulation
     if [ "$EUID" = "0" ]; then
         pathmunge /usr/sbin
         pathmunge /usr/local/sbin
     else
         pathmunge /usr/local/sbin after
         pathmunge /usr/sbin after
     fi
    
     HOSTNAME=`/usr/bin/hostname 2>/dev/null`
     HISTSIZE=1000
     if [ "$HISTCONTROL" = "ignorespace" ] ; then
         export HISTCONTROL=ignoreboth
     else
         export HISTCONTROL=ignoredups
     fi
    
     export PATH USER LOGNAME MAIL HOSTNAME HISTSIZE HISTCONTROL
    
     # By default, we want umask to get set. This sets it for login shell
     # Current threshold for system reserved uid/gids is 200
     # You could check uidgid reservation validity in
     # /usr/share/doc/setup-*/uidgid file
     if [ $UID -gt 199 ] && [ "`id -gn`" = "`id -un`" ]; then
         umask 002
     else
         umask 022
     fi
    
     for i in /etc/profile.d/*.sh ; do
         if [ -r "$i" ]; then
             if [ "${-#*i}" != "$-" ]; then
                 . "$i"
             else
                 . "$i" >/dev/null
             fi
         fi
     done
    
     unset i
     unset -f pathmunge
     #ulimit -SHn 1024000
    

影響

  • なし

デフォルト値

  • なし

参考情報

CIS コントロール

  • なし

フィードバック

このページは役に立ちましたか?