2014-08-26 17:33:55 +02:00
#!/bin/sh
#################################################################################
#
# Lynis
# ------------------
#
2016-03-13 16:00:39 +01:00
# Copyright 2007-2013, Michael Boelen
# Copyright 2013-2016, CISOfy
#
# Website : https://cisofy.com
# Blog : http://linux-audit.com
# GitHub : https://github.com/CISOfy/lynis
2014-08-26 17:33:55 +02:00
#
# Lynis comes with ABSOLUTELY NO WARRANTY. This is free software, and you are
# welcome to redistribute it under the terms of the GNU General Public License.
# See LICENSE file for usage of this software.
#
#################################################################################
#
# Home directories
#
#################################################################################
#
InsertSection "Home directories"
#
#################################################################################
#
# Ignore some top level directories (not the sub directories below)
IGNORE_HOME_DIRS="/bin /boot /cdrom /dev /etc /home /lib /lib64 /media /mnt
/opt /proc /sbin /selinux /srv /sys /tmp /usr /var"
#
#################################################################################
#
# Test : HOME-9302
# Description : Create list with home directories
2016-07-24 17:22:00 +02:00
Register --test-no HOME-9302 --weight L --network NO --category security --description "Create list with home directories"
2014-08-26 17:33:55 +02:00
if [ ${SKIPTEST} -eq 0 ]; then
2014-09-15 12:01:09 +02:00
# Read sixth field of /etc/passwd
2015-12-21 21:17:15 +01:00
LogText "Test: query /etc/passwd to obtain home directories"
2016-08-25 15:31:33 +02:00
FIND=`${AWKBINARY} -F: '{ if ($1 !~ "#") print $6 }' /etc/passwd | ${SORTBINARY} -u`
2014-09-15 12:01:09 +02:00
for I in ${FIND}; do
if [ -d ${I} ]; then
2015-12-21 21:17:15 +01:00
LogText "Result: found home directory: ${I} (directory exists)"
Report "home_directory[]=${I}"
2014-09-15 12:01:09 +02:00
else
2015-12-21 21:17:15 +01:00
LogText "Result: found home directory: ${I} (directory does not exist)"
2014-09-15 12:01:09 +02:00
fi
done
fi
2014-08-26 17:33:55 +02:00
#
#################################################################################
#
# Test : HOME-9310
# Description : Check for suspicious shell history files
2016-07-24 17:22:00 +02:00
Register --test-no HOME-9310 --weight L --network NO --category security --description "Checking for suspicious shell history files"
2014-08-26 17:33:55 +02:00
if [ ${SKIPTEST} -eq 0 ]; then
2014-09-15 12:01:09 +02:00
if [ ! "${HOMEDIRS}" = "" ]; then
if [ "${OS}" = "Solaris" ]; then
# Solaris doesn't support -maxdepth
2015-10-14 10:28:27 +02:00
FIND=`find ${HOMEDIRS} -name ".*history" ! -type f -print`
2014-09-15 12:01:09 +02:00
else
2015-10-14 10:28:27 +02:00
FIND=`find ${HOMEDIRS} -maxdepth 1 -name ".*history" ! -type f -print`
2014-09-15 12:01:09 +02:00
fi
if [ "${FIND}" = "" ]; then
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking shell history files" --result "${STATUS_OK}" --color GREEN
2015-12-21 21:17:15 +01:00
LogText "Result: Ok, history files are type 'file'."
2014-09-15 12:01:09 +02:00
else
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking shell history files" --result "${STATUS_WARNING}" --color RED
2015-12-21 21:17:15 +01:00
LogText "Result: the following files seem to be of the wrong file type:"
LogText "Output: ${FIND}"
LogText "Info: above files could be redirected files to avoid logging and should be investigated"
2016-08-10 07:12:41 +02:00
ReportWarning ${TEST_NO} "Incorrect file type found for shell history file"
2014-09-15 12:01:09 +02:00
fi
2015-12-21 21:17:15 +01:00
LogText "Remarks: History files are normally of the type 'file'. Symbolic links and other types can be riskful."
2014-08-26 17:33:55 +02:00
else
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking shell history files" --result "${STATUS_SKIPPED}" --color WHITE
2015-12-21 21:17:15 +01:00
LogText "Result: Homedirs is empty, test will be skipped"
2014-09-15 12:01:09 +02:00
fi
2014-08-26 17:33:55 +02:00
fi
#
#################################################################################
#
# Test : HOME-9314
# Description : Check if non local paths are found in PATH, which can be a risk, but also bad for performance
# (like searching on a filer, instead of local disk)
2016-07-24 17:22:00 +02:00
#Register --test-no HOME-9314 --weight L --network NO --category security --description "Create list with home directories"
2014-08-26 17:33:55 +02:00
#
#################################################################################
#
# Test : HOME-9350
# Description : Scan home directories for specific files, used in different tests later
# Notes : For performance reasons we combine the scanning of different files, so inode caching is used
# as much as possible for every find command
# Profile opt : ignore_home_dir (multiple lines allowed), ignores home directory
if [ ! "${REPORTFILE}" = "" ]; then PREQS_MET="YES"; else PREQS_MET="NO"; fi
2016-07-24 17:22:00 +02:00
Register --test-no HOME-9350 --preqs-met ${PREQS_MET} --weight L --network NO --category security --description "Collecting information from home directories"
2014-08-26 17:33:55 +02:00
if [ ${SKIPTEST} -eq 0 ]; then
2016-08-25 15:31:33 +02:00
IGNORE_HOME_DIRS=`${GREPBINARY} "^config:ignore_home_dir:" ${PROFILE} | ${AWKBINARY} -F: '{ print $3 }'`
2014-08-26 17:33:55 +02:00
if [ "${IGNORE_HOME_DIRS}" = "" ]; then
2015-12-21 21:17:15 +01:00
LogText "Result: IGNORE_HOME_DIRS empty, no paths excluded"
2014-08-26 17:33:55 +02:00
else
2015-12-21 21:17:15 +01:00
LogText "Output: ${IGNORE_HOME_DIRS}"
2014-08-26 17:33:55 +02:00
fi
fi
#
#################################################################################
#
2016-04-28 12:31:57 +02:00
WaitForKeyPress
2014-08-26 17:33:55 +02:00
#
#================================================================================
2016-03-13 16:03:46 +01:00
# Lynis - Security Auditing and System Hardening for Linux and UNIX - https://cisofy.com