Skip to content
OpenSmartRoute
Skillv1.0.0

cis-bind-v100-2-5

Set root Ownership of BIND Configuration Files (Automated)

by CyberStrikeus(0) 0 installs
Free
Sign in to install

Free account. Installing gives you the manifest plus copy-paste snippets.

See reviews

About

Imported from CyberStrikeus/CyberStrike (.cyberstrike/skill/CIS_benchmarks/Server_Software/Bind/cis-isc-bind-dns-server-9-11-benchmark/cis-bind-v100-2-5/SKILL.md). Install upstream with npx skills add CyberStrikeus/CyberStrike --skill cis-bind-v100-2-5. Copyright stays with the author.

CIS 2.5 — Set root Ownership of BIND Configuration Files

Profile Applicability

  • Authoritative Name Server Level 1
  • Caching Only Name Server Level 1

Description

The configuration files in the ISC BIND directories should be owned by root. Of course, any files created at run time by BIND, such as pid files, log files and slave zone files will necessarily be owned by named.

Rationale

Restricting ownership of the configuration files provides defense in depth and will reduce the probability of unauthorized modifications to those important files. If there was a BIND vulnerability that allowed code execution as the named user, then the code would not be able modify the configuration files.

Impact

Not specified.

Audit Procedure

Run the command below to ensure that all BIND configuration files are owned by root, except for those found in the run-time directories. Ensure that the BIND benchmark variables used below are set as described in the benchmark overview, as these variables identify the run-time directories. ($DYNDIR, $SLAVEDIR, $DATADIR, $RUNDIR, $LOGDIR, $TMPDIR) If a chroot'ed directory is not used, then $LOGDIR and $TMPDIR are not generally a subdirectory of $BIND_HOME, and the two directories may be omitted, however including them will not cause any errors or false positives.

# find $BIND_HOME -type f \! -user root | egrep -v \
\^$DYNDIR\|\^$SLAVEDIR\|\^$DATADIR\|\^$RUNDIR\|\^$LOGDIR\|\^$TMPDIR

There should be no files listed in the output from the find command.

Remediation

Perform the following:

  • Capture the output of the previous audit command to a file named nonroot-files.txt and review any files not owned by root to ensure the files are necessary and are not expected run-time files. Delete any unnecessary files, and ensure any run-time files are being created in the appropriate run-time directory.
# find $BIND_HOME -type f \! -user root | egrep -v \
\^$DYNDIR\|\^$SLAVEDIR\|\^$DATADIR\|\^$RUNDIR\|\^$LOGDIR\|\^$TMPDIR > \
$TMPDIR/nonroot-files.txt
  • The remaining non-run-time files should be changed to be owned by root, with a command like the following:
\# cat $TMPDIR/nonroot-files.txt | xargs chown root
\# rm $TMPDIR/nonroot-files.txt

Default Value

The default rpm has the following configuration files owned by named.

  • /var/named/named.ca
  • /var/named/named.empty
  • /var/named/named.localhost
  • /var/named/named.loopback

References

None listed.

CIS Controls

Controls Version Control IG 1 IG 2 IG 3
v6 14.4 Protect Information With Access Control Lists N Y Y
v7 14.6 Protect Information through Access Control Lists Y Y Y

MITRE ATT&CK Mappings

Tactic Technique
Defense Evasion T1222 File and Directory Permissions Modification
Persistence T1574 Hijack Execution Flow

Profile

  • Level 1 - Authoritative Name Server
  • Level 1 - Caching Only Name Server

Use it

Copy one of these into your project. Installing also returns the manifest and these snippets.

yaml
targets:
  - https://api.opensmartroute.ai/api/v1/registry/cyberstrikeus-cyberstrike-cis-bind-v100-2-5/manifest   # or paste the manifest below

Manifest

An Open Capability Manifest: the router reads it to know what this does, what it costs and when to pick it.

cyberstrikeus-cyberstrike-cis-bind-v100-2-5.ocm.jsonjson
{
  "ocm": "1",
  "id": "cyberstrikeus-cyberstrike-cis-bind-v100-2-5",
  "kind": "skill",
  "name": "cis-bind-v100-2-5",
  "description": "Set root Ownership of BIND Configuration Files (Automated)",
  "publisher": "CyberStrikeus",
  "version": "1.0.0",
  "capabilities": {
    "domains": [
      "general"
    ],
    "tags": [
      "skill-md",
      "cis",
      "bind",
      "dns",
      "isc-bind",
      "bind9",
      "permissions-ownership",
      "github"
    ],
    "languages": [
      "en"
    ]
  },
  "quality_prior": 0.6,
  "examples": [
    "Set root Ownership of BIND Configuration Files (Automated)"
  ],
  "primary": false,
  "metadata": {
    "source": {
      "provider": "github",
      "repository": "https://github.com/CyberStrikeus/CyberStrike",
      "path": ".cyberstrike/skill/CIS_benchmarks/Server_Software/Bind/cis-isc-bind-dns-server-9-11-benchmark/cis-bind-v100-2-5/SKILL.md",
      "ref": "df28ccd3dc6d6c02391169121ee2dcdf4a6a132b",
      "url": "https://github.com/CyberStrikeus/CyberStrike/blob/df28ccd3dc6d6c02391169121ee2dcdf4a6a132b/.cyberstrike/skill/CIS_benchmarks/Server_Software/Bind/cis-isc-bind-dns-server-9-11-benchmark/cis-bind-v100-2-5/SKILL.md",
      "key": "CyberStrikeus/CyberStrike/.cyberstrike/skill/CIS_benchmarks/Server_Software/Bind/cis-isc-bind-dns-server-9-11-benchmark/cis-bind-v100-2-5/SKILL.md"
    }
  },
  "instructions": "# CIS 2.5 — Set root Ownership of BIND Configuration Files\n\n## Profile Applicability\n\n- Authoritative Name Server Level 1\n- Caching Only Name Server Level 1\n\n## Description\n\nThe configuration files in the ISC BIND directories should be owned by root. Of course, any files created at run time by BIND, such as `pid` files, log files and slave zone files will necessarily be owned by named.\n\n## Rationale\n\nRestricting ownership of the configuration files provides defense in depth and will reduce the probability of unauthorized modifications to those important files. If there was a BIND vulnerability",
  "cost": {
    "context_tokens": 828
  }
}

Fetch it by URL: GET /api/v1/registry/cyberstrikeus-cyberstrike-cis-bind-v100-2-5/manifest?version=1.0.0

Reviews

Star ratings from people who tried it. One review per account; edit yours any time.

No reviews yet. Install it, try it, and be the first to rate it.