Commit Graph

342 Commits

Author SHA1 Message Date
Samson-W f2f851c8ce Add audit and apply methods for 8.2.4, and remove 8.2.5 2019-04-30 23:42:49 +08:00
Samson-W 3ffe674af9 Add audit and apply methods for 8.2.5 2019-04-24 17:26:36 +08:00
Samson-W 6a302f13c4 Add 8.2.3 8.2.4 for rsyslog. 2019-04-23 04:41:54 +08:00
Samson-W 94bee135ba Add audit and apply methods for 8.2.2: enable rsyslog. 2019-04-23 03:36:23 +08:00
Samson-W 80ac5bfe5b Add 8.2.1 for rsyslog and Adjust the use case number. 2019-04-22 23:58:47 +08:00
Samson-W 6412559d7d Fix a bug for 8.1.16 2019-04-21 06:30:22 +08:00
Samson-W 6157ec0bfc Update methods for 8.1.16 2019-04-21 06:19:07 +08:00
Samson-W 647d94d11c Modify apply method of 8.1.1.6: Need manual opration set Kerberos related. 2019-04-19 15:20:41 +08:00
Samson-W ee9eac8550 Set MAC default to apparmor. 2019-04-18 23:10:53 +08:00
Samson-W e6040d5ee4 Modify audit method for apparmor or selinux. 8.1.7 2019-04-17 18:18:18 +08:00
Samson-W 8abbca05e5 Update about howto fix description. 2019-04-17 12:10:48 +08:00
Samson-W 97d921c2c6 1. Add method for if ipv6 is disabled.
2. Modify ipv6 iptables rules check with check_ipv6_is_enable.
2019-04-17 03:48:49 +08:00
Samson-W 5867efd5d6 Add audit and apply methods for ipv6 firewall rules. 2019-04-16 18:09:05 +08:00
Samson-W 1c9ebf578f Fix a bug for 7.7.6 2019-04-16 15:03:13 +08:00
Samson-W 9a238af3e8 Modify some description for 7.7.6 2019-04-16 14:39:31 +08:00
Samson-W f23c662b7c Fix bug for 8.2.4: when create file if dir is not, create file is fail. 2019-04-16 03:57:53 +08:00
Samson-W 40246ee3b7 Add a method when the system architecture is 32-bit for some audit check. 2019-04-15 01:45:32 +08:00
Samson-W 8b59848f42 Add a method when the system architecture is 32-bit for 8.1.10. 2019-04-14 08:24:03 -04:00
Samson-W 568d82253b Add method for check machine architecture and modify 8.1.4 2019-04-14 08:09:04 -04:00
Samson-W 822159dce1 Modify for lib and 8.1.2 2019-04-14 05:56:05 -04:00
Samson-W e2313bd1ff Implement audit and apply methods for 7.6 disable_wireless. 2019-04-12 04:07:44 -04:00
Samson-W b2fd0dd674 1.Add audit and apply methods for 7.7.7: Ensure outbound and established connections are configured.
2.Fix some bug for lib and 7.7.6
2019-04-12 00:27:50 -04:00
Samson-W ee9f4dfff4 Add audit and apply methods for 7.7.6 Ensure firewall rules exist for all open ports 2019-04-10 02:40:57 +08:00
Samson-W 8a873e2652 Fix bug for 7.7.4. 2019-04-09 17:18:17 +08:00
Samson-W f9c5a21dff Fix some bug for 7.7.4 and 7.7.5 2019-04-09 04:59:31 -04:00
Samson-W 86ca90d417 Fix some bugs for 7.7.5 2019-04-09 16:31:57 +08:00
Samson-W 582476f7e8 Fix bug for 7.7.5. 2019-04-09 12:28:45 +08:00
Samson-W ea03f5f7e5 Add audit and apply methods for 7.7.5: Ensure IPv6 loopback traffic is configured. (Include ipv4 and ip6) 2019-04-09 04:29:36 +08:00
Samson-W 3be3101d13 Add 7.7.5 2019-04-09 04:03:38 +08:00
Samson-W d5152a656f Add audit and apply methods for ip6tables check: 7.7.2 7.7.3 2019-03-08 23:52:52 +08:00
Samson-W ba1e7b4195 Add audit and apply methods for 7.7.4: Ensure default deny firewall policy. (Include ipv4 and ip6) 2019-04-09 03:01:17 +08:00
samson c8713c4fba Adjust the order of detection cases. 2019-04-04 17:52:01 +08:00
samson 4ed4b90321 Modify for 11.2 and delete not implemented 11.3 2019-04-04 17:07:20 +08:00
samson c641faef11 Add methods of audit and apply for 6.20: configure chrony 2019-04-03 06:13:44 +08:00
samson aac2b3bf9e Add link of new use case doc to Readme and add comment for guide. 2019-04-02 03:44:15 +08:00
samson 24a7dd810e Add comment for 6.5. 2019-04-02 03:33:59 +08:00
samson e17aab2467 Add method of analogons pakeage check for 6.5: Configure Network Time Protocol. 2019-04-02 03:29:00 +08:00
samson 2ac2c2538b Add audit and apply methods for 6.19: ensure time sync server(ntp or chrony) is installed. 2019-04-02 02:59:52 +08:00
samson 5caa36d5af Modify is_service_enabled method for debian 9, and apply to 2.25. 2019-04-01 04:15:09 +08:00
samson ebed556653 Implement the exception handling feature for the specified service. 2019-03-29 17:02:58 +08:00
samson 0985aedee2 Modify comment. 2019-03-28 11:56:23 +08:00
samson 372b6627ed Add new feature: Implement the exception handling feature for the specified service. Just implement http for 6.10 2019-03-28 03:39:16 +08:00
samson 4f01ec6289 Modify hardening.sh 2018-12-17 16:49:25 +08:00
samson e0f97af8a7 Fix a bug for 4.5 2018-12-11 17:31:49 +08:00
samson b7f4300e59 Modify 3.2 2018-12-11 16:55:05 +08:00
samson 5eed5789f9 Fix a bug for 12.10, and remove the unwanted exceptions. 2018-12-11 04:44:01 +08:00
samson 9d4dc5f1c4 Fix bugs for 10.1.7 and 10.1.8 2018-12-09 15:58:06 +08:00
samson ded285c533 Fix bug for 2.1 2018-12-07 23:52:00 +08:00
samson 8798f43866 Fix bugs: Exec some script return error when use grep -c, and clamav daily file extension maybe changed. 2018-12-06 16:01:22 +08:00
samson 00ab71cc2e Fix some bugs for mount options of tmp partition 2018-12-06 14:45:31 +08:00
samson 5185fff59a Fix bug 2018-12-06 14:03:05 +08:00
samson 5c52acf20a Fix some bugs for mount option of tmp partition 2018-12-06 13:44:55 +08:00
samson e720cc891e Update format. 2018-12-06 05:01:42 +08:00
samson 0e146384de Update format. 2018-12-06 05:00:20 +08:00
samson 2a881a5fbe Modify audit and apply methods for 2.1 2018-12-06 04:30:55 +08:00
samson 2772e8a55f Fix some bugs for mount options check of removable device 2018-12-06 02:41:44 +08:00
samson 5d5e575f8f Fix some bugs for 4.5 2018-12-05 18:03:49 +08:00
samson 7433811fa0 Fix some bugs. 2018-12-05 16:28:34 +08:00
samson d45ddb82f7 Fix some bugs. 2018-12-05 16:06:35 +08:00
samson f2ebec8e38 Fix bug for 9.3.23 9.3.24 2018-12-05 15:17:29 +08:00
samson 64ab792e6c Fix bug for 10.1.9 and modify apt_update_if_needed function. 2018-12-05 15:10:06 +08:00
samson 73c1e12910 Optimization: Replace grep|wc -l combination with grep -c. 2018-12-05 13:59:04 +08:00
samson 85d3e1dbf9 Rename 99.1 to 10.6, 99.2 to 4.6, Add description to benchmark doc for 4.6 10.6 2018-12-04 04:16:39 +08:00
samson e6f204b7f0 Modify function for dpkg verity 2018-12-03 00:47:10 +08:00
samson dc19e48928 Fix some bugs 2018-12-02 23:08:56 +08:00
samson 5f9346486d Fix some bugs. 2018-12-02 21:11:10 +08:00
samson a3a0c25d1a Fix a bug 2018-12-02 20:34:40 +08:00
samson 9c7ae21bee Fix some bug and add CIS_Debian_Linux_8_Benchmark to docs dir. 2018-12-01 04:36:21 +08:00
samson ae6f4297af Fix bug for 8.1.13 2018-11-30 16:30:46 +08:00
Samson-W 17fff469b2 Add audit item for iptables save path 2018-11-28 07:52:29 -05:00
Samson-W 94c467485e Add check iptables persistent function for 7.7.1 2018-11-28 06:14:34 -05:00
samson 4a9704551a Add description to benchmark doc for 7.7.2 7.7.3 2018-11-27 03:52:59 +08:00
Samson-W 217c3cd020 Modify functions for firewall 2018-11-27 02:05:23 +08:00
Samson-W 0aa16f3e6d Modify for firewall 2018-11-26 12:45:43 -05:00
Samson-W 60be85163b Add audit and apply firewall(iptables) rules for 7.7.1 7.7.2 2018-11-26 09:52:46 -05:00
Samson-W c4a61dcf94 Add audit entry for 8.1.27 2018-11-24 08:31:57 -05:00
Samson-W 70e6f42e56 Add audit rules to configurations dir. 2018-11-22 09:05:22 -05:00
Samson-W 6e59f0289b Add audit and apply methods for 8.1.27 2018-11-22 08:42:11 -05:00
Samson-W 8b770013fd Remove auditd item for umount syscall 2018-11-22 04:19:57 -05:00
Samson-W 45a1d8ab0b Fix bug for 5.9 2018-11-21 16:22:29 -05:00
Samson-W 286434cff2 Fix bug for 8.1.3 2018-11-21 16:14:27 -05:00
Samson-W cfd82154af Merge branch 'master' of https://github.com/hardenedlinux/harbian-audit 2018-11-21 15:08:21 -05:00
Samson-W 068e40b68a Fix bug for 4.5 2018-11-21 15:07:57 -05:00
samson 9195187cbb Delete duplicate check item 10.1.13. 2018-11-21 17:44:11 +08:00
Samson-W f5f0aab2b1 Fix bug of add_option_to_fstab function. 2018-11-21 04:32:59 -05:00
Samson-W b5cff8047a Fix some bug 2018-11-21 02:45:33 -05:00
Samson-W 35b75f0779 Modify aide audit methods for debian 9 2018-11-20 03:02:44 -05:00
Samson-W 2b50f8ddf8 Rename file name 2018-11-19 06:10:08 -05:00
Samson-W 2d31c04684 Modify 8.3.1 8.3.2 2018-11-19 06:08:01 -05:00
Samson-W dabf90d48b Modify 8.3.1 2018-11-19 05:31:34 -05:00
samson 34deb79a0a Add audit and apply methods for 5.10 2018-11-19 17:50:06 +08:00
samson f4a28eddaa Modify apply method for 9.5 2018-11-19 17:25:34 +08:00
samson f50b4b1092 Delete postinstall dir 2018-11-19 12:14:18 +08:00
samson badd7160cb Fix bug 2018-11-19 02:29:03 +08:00
Samson-W 0b669e3307 Delete the line of duplicate function. 2018-11-18 00:04:21 +08:00
Samson-W dcd0e0947d Add Level info to 99.1 99.2 2018-11-17 23:54:45 +08:00
Samson-W 7986a83f50 Add audit and apply methods for 10.1.13 2018-11-16 19:27:08 +08:00
Samson-W 8beb81d99f Add audit and apply methods for 1.4 2018-11-16 03:23:02 +08:00
Samson-W 3759e22078 Add audit and apply methods for 1.1~1.3 2018-11-16 02:43:08 +08:00
Samson-W 739766c93f Add audit and apply methods for 2.27~2.29 2018-11-15 03:38:56 +08:00
Samson-W 977cb64e44 Fix activate AppArmor audit and apply methods 2018-11-14 04:48:39 +08:00
Samson-W 3c64cd6a7a Add audit and apply methods for 7.1.3 2018-11-14 03:33:40 +08:00
Samson-W 19d4b01ef8 Add audit and apply methods for 10.1.12 2018-11-13 18:35:40 +08:00
Samson-W dc823b820d Add audit and apply methods for 10.1.11 2018-11-13 17:35:10 +08:00
Samson-W 32de2245b6 Add audit and apply methods for 8.1.1.9 2018-11-13 14:10:10 +08:00
Samson-W da32330008 Fix spell error. 2018-11-13 04:46:20 +08:00
Samson-W 029e04ff7a Add audit and apply methods for 8.1.1.7 8.1.1.8 2018-11-13 04:45:11 +08:00
Samson-W 78182280d3 Add audit and apply methods for 8.1.1.6_ensure_set_encrypt_for_audit_remote 2018-11-12 20:16:23 +08:00
Samson-W 0a7616a39a Add audit and apply methods for 8.1.1.5 2018-11-12 18:05:36 +08:00
Samson-W f6d67de7df Add audit and apply methods for 8.1.1.4 2018-11-10 02:57:18 +08:00
Samson-W 7bfbc817ed Add audit and apply methods for 2.27 2018-11-11 23:53:47 +08:00
samson 13ce982de4 Modify description 2018-11-09 18:43:55 +08:00
Samson-W de3c2822aa Add a new feature: check items for services that do not exist in the current system are not scored. 2018-11-09 18:40:53 +08:00
Samson-W cf4c4d668a Add author discription 2018-11-09 17:07:35 +08:00
Samson-W dd499fd50b Add audit and apply methods for 2.10.1 2018-11-09 17:03:27 +08:00
Samson-W 22252f2e74 Modify description for 9.2.16 2018-11-08 04:05:58 +08:00
Samson-W 8e765be4cf Add audit and apply methods for enable even_deny_root with pam_tally2 2018-11-08 03:46:17 +08:00
Samson-W e0265d7517 Rename function name for human and modify associated file. 2018-11-06 04:31:36 +08:00
Samson-W 2fa1dd1287 Add audit and apply methods for unlock_time parameter with pam_tally2 2018-11-06 04:06:50 +08:00
Samson-W 54b7eb1a9b Add audit and apply methods for set deny with pam_tally2 2018-11-07 16:12:50 +08:00
Samson-W b44ad4fa8b Rename function name for human. 2018-11-07 12:25:57 +08:00
Samson-W 79e8bea65f Modify 9.2.11 2018-11-05 18:30:15 +08:00
Samson-W daaf9d8a24 Modify apply method for 9.2.11 2018-11-02 23:56:44 +08:00
Samson-W b06e8890e4 Add audit and apply methods for 5.9 2018-10-31 23:41:51 +08:00
samson 25cc2c12b5 Add description for 8.1.26 2018-10-30 04:18:56 +08:00
Samson-W 145de31c21 Fix bug: audit.rules file path error. 2018-10-30 04:14:47 +08:00
Samson-W 2c74d17d7a Add audit and apply methods for 8.1.26 2018-10-30 04:04:32 +08:00
Samson-W a1a45bb163 Modify 9.2.11 9.2.12 2018-10-30 03:13:25 +08:00
Samson-W 0c2f957152 Add audit and apply methods for 9.3.23 9.3.24 2018-10-29 04:33:23 +08:00
Samson-W 2ef7c49fde Modify description for 9.3.22 2018-10-28 23:44:55 +08:00
Samson-W dd72ce4e2c Add audit and apply methods for 9.3.22 2018-10-28 23:42:16 +08:00
Samson-W 72931d8844 Add audit and apply methods for 9.3.20 9.3.21 9.2.15, modify 9.2.13 for compatible. 2018-10-27 04:12:56 +08:00
Samson-W 7cc05a4ad6 Modify 9.3.17 2018-10-26 03:55:53 +08:00
Samson-W 1fdd1cb3d6 Add audit and apply methods for 9.3.16 9.3.17 9.3.18 9.3.19 2018-10-26 03:54:17 +08:00
Samson-W ece561b0c5 Add audit and apply methods for 9.3.15 2018-10-26 03:33:34 +08:00
Samson-W 29c1d4d8bd Add audit and apply methods for 5.8 2018-10-25 01:57:47 +08:00
Samson-W 1ae4348f41 Add audit and apply methods for 6.18 2018-10-24 02:55:56 +08:00
Samson-W 00cc8e4f67 Modify virul scan server:clamav-daemon server audit methods. 2018-10-23 02:17:52 +08:00
Samson-W 96a6fbb977 Add audit and apply methods for 6.17 2018-10-22 05:09:10 +08:00
Samson-W cb592a62fa Add syscall create_module and finit_module to audit.rules 2018-10-22 03:16:02 +08:00
Samson-W 1bce989b10 Add syscall rmdir to audit.rules 2018-10-22 03:03:21 +08:00
Samson-W de4712f55c Add audit and apply methods for 8.1.25 2018-10-22 02:59:10 +08:00
Samson-W 4e57de214c Add audit and apply methods for 8.1.24 2018-10-22 02:42:05 +08:00
Samson-W 768ab19448 Add audit and apply methods for 8.1.23 2018-10-22 02:21:17 +08:00
Samson-W c4dbd14ed8 Add umount syscall record to 8.1.13 2018-10-21 04:03:38 +08:00
Samson-W 2e24fd776e Add audit and apply methods for 8.1.22 2018-10-21 03:23:17 +08:00
Samson-W 08247701d3 Fix a bug when use does_pattern_exist_in_file function in 8.1.21. 2018-10-21 03:06:58 +08:00
Samson-W 395053deb9 Modify 8.1.21 for all privileged passwd events 2018-10-21 02:59:16 +08:00
Samson-W 4c2aeead84 Add audit and apply methods for 8.1.21 2018-10-21 02:32:56 +08:00
Samson-W 97e53b3e95 Fix a bug when use does_pattern_exist_in_file function. 2018-10-20 04:25:53 +08:00
Samson-W b6b9985510 Add audit and apply methods for 8.1.19 8.1.20 2018-10-20 04:07:58 +08:00
Samson-W eafb0e6ab9 Add audit and apply methods for 10.1.10 and modify 10.1.9 2018-10-18 03:17:01 +08:00
Samson-W da51ac2cda Fix issues #1 An error occurred when executing the su command after applying 10.1.9 2018-10-16 08:21:51 +08:00
Samson-W efd22bfbc6 Modify the compatibility of check_password_by_pam function. 2018-10-16 07:53:08 +08:00
Samson-W 28ae3cb88f Modify description 2018-10-09 21:33:56 +08:00
Samson-W caace05766 Fix 10.1.9 if value is greater 2018-10-09 21:27:57 +08:00
Samson-W 018766478d Add 10.1.9 for audit and apply set FAIL_DELAY 2018-10-09 20:08:59 +08:00
Samson-W 5669c59742 Add 10.1.8 for audit and apply not authenticate whether set in sudoers conf file. 2018-10-08 19:16:06 +08:00
Samson-W c7ad465d04 Add method fro check sudoers.d conf file whether is set NOPASSWD 2018-09-16 04:27:26 +08:00
Samson-W cfd091de88 Add 10.1.7 for audit and apply NOPASSWD whether set in sudoers conf file. 2018-09-16 03:33:48 +08:00
Samson-W 48ff3f972d Fix apply is not set to /etc/pam.d/login. 2018-09-13 17:51:37 +08:00
Samson-W bc76a18fbc Add 9.2.14 to check nullok option of auth pam_unix 2018-09-13 03:45:11 +08:00
Samson-W b3787fbc27 Fix spelling errors. 2018-09-12 04:35:11 +08:00
Samson-W 2434b6a1b5 Add 10.1.5 set min password lifetime to 1, 10.1.6 set max password lifetime to 60 2018-09-12 04:31:10 +08:00
Samson-W 94e531258b Add 10.1.4 for audit and apply ENCRYPT_METHOD in /etc/login.defs 2018-09-11 15:17:58 +08:00
Samson-W 8976282fd1 Add check_password_option_by_pam function and 9.2.13_enable_password_sha512.sh 2018-09-11 04:59:15 +08:00
Samson-W eb25a4011c Modify the parameters of the check_password_by_pam function call. 2018-09-11 04:29:38 +08:00
Samson-W 416415d78e Modify 9.2.12_limit_password_reuse to support audit and apply for don't conf and value is error 2018-09-11 04:18:07 +08:00
Samson-W f548ebc250 Add audit and apply methods for password options(difok. minclass, maxrepeat, maxclassrepeat) 9.2.7-9.2.10 2018-09-11 00:58:18 +08:00
Samson-W caba00e1d4 Add audit and apply methods for password option lcredit. 9.2.6 2018-09-10 05:09:10 +08:00
Samson-W c10ee0997e Add audit and apply methods for password option ocredit. 2018-09-10 05:04:43 +08:00
Samson-W 18df3691d0 Add audit and apply methods for password option ucredit. 2018-09-10 04:36:00 +08:00
Samson-W 0d3020a5de Add audit and apply methods for password option dcredit. 2018-09-10 04:27:07 +08:00
Samson-W 4772f4f4cc Rename 9.2.2 to 9.2.11, 9.2.3 to 9.2..12. Add 9.2.2_enable_minlen_cracklib.sh. 2018-09-10 04:18:51 +08:00
Samson-W a28c55758c Add reset_option_to_password_check method to reset option value when option value is not correct. 2018-09-10 03:12:27 +08:00
Samson-W a7e5614b75 Add add_option_to_password_check method to set no seted option to pampassword config 2018-09-09 23:13:16 +08:00
Samson-W b836cabdba Modify audit and apply methods for 9.2.1 2018-09-08 22:29:10 +08:00
Samson-W 7c7e4ed1c2 Add password check methods by PAM. 2018-09-08 15:04:54 +08:00
Samson-W c73dc1cd7b Fix a bug: Match is not unique when using the option --only <test_number>, example:
use --only 9.2.1 are match 2.1 and 9.2.1. .
2018-09-06 12:13:24 +08:00
samson fae9a6e6ce Rename 5.7_enable_screen.sh to 5.7_install_screen.sh. 2018-09-06 03:47:27 +08:00
samson 53e21bfaf5 Add audit and apply 5.7 document. 2018-09-06 03:44:28 +08:00
Samson-W 7a0c112334 Add audit and apply methods for screen. 2018-09-05 17:59:33 +08:00
Samson-W 11ea940951 Rename 8.5_verifies_integrity_all_packages.sh to short. 2018-09-04 23:23:21 +08:00
Samson-W a1459e7e41 Add verifies integrity all packages method, and doc. 2018-09-04 23:12:42 +08:00
Samson-W 72d0274f73 Modify audit and apply methods of 2.3, 2.4. 2018-08-25 11:02:57 +08:00
Samson-W b81b8d7e3a Modify the description. 2018-08-25 09:31:24 +08:00
Samson-W 0e20379c95 Modify apply method of 2.2, add add_option_to_systemd and remount_partition_by_systemd methods. 2018-08-25 05:09:03 +08:00
Samson-W 214c11a0cd Modify audit method of 2.2, and add has_mount_option_systemd method. 2018-08-24 03:25:46 +08:00
Samson-W 9f7c4d56f8 Modify the implementation of 2.1 to be compatible with the original version. 2018-08-24 02:28:25 +08:00
Samson-W 79c179f7c2 Modify the apply method of 2.1. 2018-08-23 16:12:12 +08:00
Samson-W d517075d64 Modify audit method of 2.1_tmp_partition.sh. 2018-08-21 17:12:15 -04:00
Samson-W a018dadcbd Merge OVH/debian-cis projects into this Repository. 2018-08-21 16:01:50 -04:00