Permissions on user .netrc files must be 750 or less permissive.
Severity | Group ID | Group Title | Version | Rule ID | Date | STIG Version |
|---|---|---|---|---|---|---|
| medium | V-216420 | SRG-OS-000480 | SOL-11.1-070040 | SV-216420r959010_rule | 2026-02-19 | 3 |
Description
.netrc files may contain unencrypted passwords that can be used to attack other systems.
ℹ️ Check
The root role is required.
Check that permissions on user .netrc files are 750 or less permissive.
# for dir in \
`logins -ox | awk -F: '($8 == "PS") { print $6 }'`; do
find ${dir}/.netrc -type f \( \
-perm -g+r -o -perm -g+w -o -perm -g+x -o \
-perm -o+r -o -perm -o+w -o -perm -o+x \) \
-ls 2>/dev/null
done
If output is produced, this is a finding.
✔️ Fix
The root role is required.
Change the permissions on users' .netrc files to 750 or less permissive.
# chmod 750 [file name]