This guide applies to Mac computers
About the Applications, Library, and System world writable Parameters
These Blueprint Parameters audit Mac computers for files with overly permissive permissions in the Applications, Library, and System folders. They identify security vulnerabilities caused by world writable files.How It Works
These Parameters scan the Applications, Library, and System folders for world writable files. The Applications Parameter changes out-of-compliance applications to be world executable. The Library Parameter can attempt to remediate world writable directories if found. The System Parameter alerts you to their presence.What are World Writable Files?
World writable files in macOS are files or directories that any user on the system can modify. While this might seem convenient, it poses significant security risks. Any user, including those with malicious intent, can alter these files, potentially leading to unauthorized changes, data corruption, or even system compromise. Being aware of these files is crucial because they can be exploited to inject malicious code or disrupt services. Regularly auditing and managing file permissions helps maintain system integrity and security. Minimizing or eliminating world writable permissions protects Mac computers from those vulnerabilities.Check Applications folder for appropriate permissions
This Parameter verifies applications located anywhere within the/Applications directory are not world writable. Applications found to be out of compliance will have their permissions changed to be world executable.
A Parameter can be configured on a Blueprint (Assignment Map) to audit for world writable applications in the Applications folder and remediate them if found. To configure the Parameter:
1
Access Parameters
Open your Blueprint, then click Parameters.
2
Edit Parameters
Select Edit Parameters. If this is the first Parameter you’re adding, select Add Parameters.
3
Search for Parameter
In the search field, enter “Applications folder”.
4
Enable Parameter
Locate the Check Applications folder for appropriate permissions Parameter, and enable it by toggling the switch.
5
Configure notifications
Optionally, click the bell icon to mute notifications for this Parameter.
6
Save Configuration
Click Save.
Check Library folder for world writable files
This Parameter verifies directories in/Library aren’t set to be world writable. Directory exclusions can be created for Iru to skip over specified folders. This is useful for applications that don’t function properly if their directories are modified to comply with this Parameter. Adobe is an example of this.
A Parameter can be configured on a Blueprint (Assignment Map) to audit for world writable files located in the Library folder and attempt to remediate them if found. To configure the Parameter:
1
Access Parameters
Open your Blueprint, then click Parameters.
2
Edit Parameters
Select Edit Parameters. If this is the first Parameter you’re adding, select Add Parameters.
3
Search for Parameter
In the search field, enter “world writable”.
4
Enable Parameter
Locate the Check Library folder for world writable files Parameter, and enable it by toggling the switch.
5
Add directory exclusions
Optionally, click Add Directory Exclusion and enter the full path of each directory Iru Endpoint should skip under Full paths of excluded directories.
6
Configure notifications
Optionally, click the bell icon to mute notifications for this Parameter.
7
Save Configuration
Click Save.
Check System folder for world writable files
This Parameter verifies directories in/System aren’t set to be world writable.
Because of Apple’s System Integrity Protection (SIP), world writable files found in the System folder cannot be remediated automatically. Manual intervention is required to resolve alerts for world writable files found in this location.
1
Access Parameters
Open your Blueprint, then click Parameters.
2
Edit Parameters
Select Edit Parameters. If this is the first Parameter you’re adding, select Add Parameters.
3
Search for Parameter
In the search field, enter “world writable”.
4
Enable Parameter
Locate the Check System folder for world writable files Parameter, and enable it by toggling the switch.
5
Configure notifications
Optionally, click the bell icon to mute notifications for this Parameter.
6
Save Configuration
Click Save.