Skip to main content
This guide applies to Mac computers

About the Applications, Library, and System world writable Parameters

These Blueprint Parameters audit Mac computers for files with overly permissive permissions in the Applications, Library, and System folders. They identify security vulnerabilities caused by world writable files.

How It Works

These Parameters scan the Applications, Library, and System folders for world writable files. The Applications Parameter changes out-of-compliance applications to be world executable. The Library Parameter can attempt to remediate world writable directories if found. The System Parameter alerts you to their presence.

What are World Writable Files?

World writable files in macOS are files or directories that any user on the system can modify. While this might seem convenient, it poses significant security risks. Any user, including those with malicious intent, can alter these files, potentially leading to unauthorized changes, data corruption, or even system compromise. Being aware of these files is crucial because they can be exploited to inject malicious code or disrupt services. Regularly auditing and managing file permissions helps maintain system integrity and security. Minimizing or eliminating world writable permissions protects Mac computers from those vulnerabilities.

Check Applications folder for appropriate permissions

This Parameter verifies applications located anywhere within the /Applications directory are not world writable. Applications found to be out of compliance will have their permissions changed to be world executable. A Parameter can be configured on a Blueprint (Assignment Map) to audit for world writable applications in the Applications folder and remediate them if found. To configure the Parameter:
1

Access Parameters

Open your Blueprint, then click Parameters.
2

Edit Parameters

Select Edit Parameters. If this is the first Parameter you’re adding, select Add Parameters.
3

Search for Parameter

In the search field, enter “Applications folder”.
4

Enable Parameter

Locate the Check Applications folder for appropriate permissions Parameter, and enable it by toggling the switch.
5

Configure notifications

Optionally, click the bell icon to mute notifications for this Parameter.
6

Save Configuration

Click Save.

Check Library folder for world writable files

This Parameter verifies directories in /Library aren’t set to be world writable. Directory exclusions can be created for Iru to skip over specified folders. This is useful for applications that don’t function properly if their directories are modified to comply with this Parameter. Adobe is an example of this.
Test thoroughly before mass deployment. Certain applications do not function properly if their associated directories in /Library aren’t world writable.
A Parameter can be configured on a Blueprint (Assignment Map) to audit for world writable files located in the Library folder and attempt to remediate them if found. To configure the Parameter:
1

Access Parameters

Open your Blueprint, then click Parameters.
2

Edit Parameters

Select Edit Parameters. If this is the first Parameter you’re adding, select Add Parameters.
3

Search for Parameter

In the search field, enter “world writable”.
4

Enable Parameter

Locate the Check Library folder for world writable files Parameter, and enable it by toggling the switch.
5

Add directory exclusions

Optionally, click Add Directory Exclusion and enter the full path of each directory Iru Endpoint should skip under Full paths of excluded directories.
6

Configure notifications

Optionally, click the bell icon to mute notifications for this Parameter.
7

Save Configuration

Click Save.

Check System folder for world writable files

This Parameter verifies directories in /System aren’t set to be world writable.
Because of Apple’s System Integrity Protection (SIP), world writable files found in the System folder cannot be remediated automatically. Manual intervention is required to resolve alerts for world writable files found in this location.
A Parameter can be configured on a Blueprint (Assignment Map) to audit for world writable files located in the System folder and alert admins to their presence. To configure the Parameter:
1

Access Parameters

Open your Blueprint, then click Parameters.
2

Edit Parameters

Select Edit Parameters. If this is the first Parameter you’re adding, select Add Parameters.
3

Search for Parameter

In the search field, enter “world writable”.
4

Enable Parameter

Locate the Check System folder for world writable files Parameter, and enable it by toggling the switch.
5

Configure notifications

Optionally, click the bell icon to mute notifications for this Parameter.
6

Save Configuration

Click Save.
For more detailed information on Parameters, see the Parameters section of our Knowledge Base.