info: name:/etc/hosts File Owner and Permission Check author: songyaeji severity: high description:> If the /etc/hosts file is writable by non-root users, attackers may register malicious DNS mappings and redirect legitimate domains to malicious sites (pharming attacks). This check ensures /etc/hosts is owned by root and has appropriate permissions. reference: - https://isms.kisa.or.kr/main/csap/notice/ - Cloud Vulnerability Assessment Guide (2024) by KISA tags: linux,local,hosts,file,permission,ownership,misconfiguration metadata: verified:true os: linux max-request:1 classification: cwe-id: CWE-732 cvss-metrics: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H cvss-score:7.4