AUTH-9308 - Protect single user mode
Physical access to the machine can be used to load alternative software or a different operating system, during the boot phase. Configure a password in the boot loader to prevent this risk. This test applies to Linux based systems only.
How to solve
For emergency maintenance and password recovery, single user mode is used on Linux systems. In such an event, the system can run a limited set of commands, and has limited access to system resources. However, this is enough to reset a root password, or try mounting a previously failed file system mount.
While single user mode is great for system engineers to performance emergency maintenance activities, it can also be abused by evildoers with access to the system. For that reason single user mode should be as limited as possible. The more sensitive data, the higher the restricted access to this feature.
Single user mode on Linux is protected in different ways. It depends on which service manager. For distributions using systemd, have a look at the related targets like rescue, console-shell, and emergency.
Linux and Unix System Hardening
This information is provided as part of the Lynis community project. It is related to Lynis control AUTH-9308. All information should be considered as-is, without guarantees. Any advice or snippets should be tested before implementing in production environments.
Lynis is a technical security audit tool for systems running Linux, UNIX, *BSD, and macOS. It is open source software and free to use. The project has an active community, and can also be found on GitHub.
Need more advanced features, like vulnerability scanning, or reporting installed software packages? Lynis Enterprise will collect more data and present it with an easy to use web interface.
Gain additional benefits: automating security audits, reporting, and the implementation of related security measures.
- Centralized management
- Prioritized plans
- Integration (API)
- Improvement snippets for tools like Ansible, Chef, Cfengine and Puppet