2025-08-25 20:46:27 +05:30
id : linux-world-writable-file
info :
name : Linux World-Writable File Permission
author : songyaeji
severity : high
description : |
System files were configured with world-writable (chmod o+w) permissions.Malicious users could modify them, leading to privilege escalation, backdoors, or service disruption.
reference :
- https://isms.kisa.or.kr
2025-08-28 23:41:32 +05:30
tags : linux,local,audit,compliance,kisa
2025-08-25 20:46:27 +05:30
self-contained : true
code :
- engine :
- sh
- bash
source : |
find / -type f -perm -0002 ! -path "/tmp/*" -exec ls -l {} \; 2>/dev/null
matchers :
- type : regex
name : world-writable-files
part : response
regex :
2025-08-27 03:24:08 +00:00
- "^-........w.*"
2025-08-29 10:06:03 +00:00
# digest: 4b0a00483046022100cb4eeed99539ca94bafeaaa60912f67fcac73a5d2c5a4f77d1f5085271959995022100e8df18d9e16d1dd7a187b6bde457f4706e1863500ba810dae15f383f8942bace:922c64590222798bb761d5b6d8e72950