콘텐츠로 이동

0021-profile-exist-전역 환경 변수 파일 존재 여부


규칙 ID

  • 0021-profile-exist

카테고리

  • system

수준

  • critical

호환 버전

  • Linux

설명

  • 호스트의 /etc/profile 존재 여부 모니터링

스캔 빈도

  • 1 */5 * * *

이론적 근거

위험 항목

  • 서비스 불가

감사 방법

  • 호스트의 /etc/profile을 확인합니다. 다음 명령을 실행하여 확인할 수 있습니다:
ls /etc/profile

조치

  • /etc/profile이 삭제된 경우 다음 명령을 실행하세요:

       export PATH=/usr/bin:/usr/sbin:/bin:/sbin:/usr/X11R6/bin
    
    vim /etc/profile을 사용하여 profile 파일을 새로 만들고 다음 명령을 복사한 후, source /etc/profile을 실행하여 즉시 적용합니다
    # /etc/profile
    
     # System wide environment and startup programs, for login setup
     # Functions and aliases go in /etc/bashrc
    
     # It"s NOT a good idea to change this file unless you know what you
     # are doing. It"s much better to create a custom.sh shell script in
     # /etc/profile.d/ to make custom changes to your environment, as this
     # will prevent the need for merging in future updates.
    
     pathmunge () {
         case ":${PATH}:" in
             *:"$1":*)
                 ;;
             *)
                 if [ "$2" = "after" ] ; then
                     PATH=$PATH:$1
                 else
                     PATH=$1:$PATH
                 fi
         esac
     }
    
    
     if [ -x /usr/bin/id ]; then
         if [ -z "$EUID" ]; then
             # ksh workaround
             EUID=`id -u`
             UID=`id -ru`
         fi
         USER="`id -un`"
         LOGNAME=$USER
         MAIL="/var/spool/mail/$USER"
     fi
    
     # Path manipulation
     if [ "$EUID" = "0" ]; then
         pathmunge /usr/sbin
         pathmunge /usr/local/sbin
     else
         pathmunge /usr/local/sbin after
         pathmunge /usr/sbin after
     fi
    
     HOSTNAME=`/usr/bin/hostname 2>/dev/null`
     HISTSIZE=1000
     if [ "$HISTCONTROL" = "ignorespace" ] ; then
         export HISTCONTROL=ignoreboth
     else
         export HISTCONTROL=ignoredups
     fi
    
     export PATH USER LOGNAME MAIL HOSTNAME HISTSIZE HISTCONTROL
    
     # By default, we want umask to get set. This sets it for login shell
     # Current threshold for system reserved uid/gids is 200
     # You could check uidgid reservation validity in
     # /usr/share/doc/setup-*/uidgid file
     if [ $UID -gt 199 ] && [ "`id -gn`" = "`id -un`" ]; then
         umask 002
     else
         umask 022
     fi
    
     for i in /etc/profile.d/*.sh ; do
         if [ -r "$i" ]; then
             if [ "${-#*i}" != "$-" ]; then
                 . "$i"
             else
                 . "$i" >/dev/null
             fi
         fi
     done
    
     unset i
     unset -f pathmunge
     #ulimit -SHn 1024000
    

영향

  • 없음

기본값

  • 없음

참고 문헌

CIS 제어

  • 없음

문서 평가

이 페이지가 도움이 되었나요?