| @@ -0,0 +1,447 @@ |
| 1 | #+title: Linux |
| 2 | |
| 3 | * =ssh_root_login.sh= |
| 4 | |
| 5 | #+begin_src shell |
| 6 | ./ssh_root_login.sh |
| 7 | #+end_src |
| 8 | |
| 9 | #+begin_src |
| 10 | PermitRootLogin no |
| 11 | #+end_src |
| 12 | |
| 13 | * =passwords.sh= |
| 14 | |
| 15 | #+begin_src shell |
| 16 | ./passwords.sh |
| 17 | #+end_src |
| 18 | |
| 19 | #+begin_src |
| 20 | Starting analysis of authentication and login parameters... |
| 21 | Checking /etc/pam.d/system-auth for password parameters... |
| 22 | /etc/pam.d/system-auth file not found. |
| 23 | Analyzing /etc/login.defs... |
| 24 | Contents of /etc/login.defs: |
| 25 | # |
| 26 | # /etc/login.defs - Configuration control definitions for the login package. |
| 27 | # |
| 28 | # Three items must be defined: MAIL_DIR, ENV_SUPATH, and ENV_PATH. |
| 29 | # If unspecified, some arbitrary (and possibly incorrect) value will |
| 30 | # be assumed. All other items are optional - if not specified then |
| 31 | # the described action or option will be inhibited. |
| 32 | # |
| 33 | # Comment lines (lines beginning with "#") and blank lines are ignored. |
| 34 | # |
| 35 | # Modified for Linux. --marekm |
| 36 | |
| 37 | # REQUIRED for useradd/userdel/usermod |
| 38 | # Directory where mailboxes reside, _or_ name of file, relative to the |
| 39 | # home directory. If you _do_ define MAIL_DIR and MAIL_FILE, |
| 40 | # MAIL_DIR takes precedence. |
| 41 | # |
| 42 | # Essentially: |
| 43 | # - MAIL_DIR defines the location of users mail spool files |
| 44 | # (for mbox use) by appending the username to MAIL_DIR as defined |
| 45 | # below. |
| 46 | # - MAIL_FILE defines the location of the users mail spool files as the |
| 47 | # fully-qualified filename obtained by prepending the user home |
| 48 | # directory before $MAIL_FILE |
| 49 | # |
| 50 | # NOTE: This is no more used for setting up users MAIL environment variable |
| 51 | # which is, starting from shadow 4.0.12-1 in Debian, entirely the |
| 52 | # job of the pam_mail PAM modules |
| 53 | # See default PAM configuration files provided for |
| 54 | # login, su, etc. |
| 55 | # |
| 56 | # This is a temporary situation: setting these variables will soon |
| 57 | # move to /etc/default/useradd and the variables will then be |
| 58 | # no more supported |
| 59 | MAIL_DIR /var/mail |
| 60 | #MAIL_FILE .mail |
| 61 | |
| 62 | # |
| 63 | # Enable logging and display of /var/log/faillog login failure info. |
| 64 | # This option conflicts with the pam_tally PAM module. |
| 65 | # |
| 66 | FAILLOG_ENAB yes |
| 67 | |
| 68 | # |
| 69 | # Enable display of unknown usernames when login failures are recorded. |
| 70 | # |
| 71 | # WARNING: Unknown usernames may become world readable. |
| 72 | # See #290803 and #298773 for details about how this could become a security |
| 73 | # concern |
| 74 | LOG_UNKFAIL_ENAB no |
| 75 | |
| 76 | # |
| 77 | # Enable logging of successful logins |
| 78 | # |
| 79 | LOG_OK_LOGINS no |
| 80 | |
| 81 | # |
| 82 | # Enable "syslog" logging of su activity - in addition to sulog file logging. |
| 83 | # SYSLOG_SG_ENAB does the same for newgrp and sg. |
| 84 | # |
| 85 | SYSLOG_SU_ENAB yes |
| 86 | SYSLOG_SG_ENAB yes |
| 87 | |
| 88 | # |
| 89 | # If defined, all su activity is logged to this file. |
| 90 | # |
| 91 | #SULOG_FILE /var/log/sulog |
| 92 | |
| 93 | # |
| 94 | # If defined, file which maps tty line to TERM environment parameter. |
| 95 | # Each line of the file is in a format something like "vt100 tty01". |
| 96 | # |
| 97 | #TTYTYPE_FILE /etc/ttytype |
| 98 | |
| 99 | # |
| 100 | # If defined, login failures will be logged here in a utmp format |
| 101 | # last, when invoked as lastb, will read /var/log/btmp, so... |
| 102 | # |
| 103 | FTMP_FILE /var/log/btmp |
| 104 | |
| 105 | # |
| 106 | # If defined, the command name to display when running "su -". For |
| 107 | # example, if this is defined as "su" then a "ps" will display the |
| 108 | # command is "-su". If not defined, then "ps" would display the |
| 109 | # name of the shell actually being run, e.g. something like "-sh". |
| 110 | # |
| 111 | SU_NAME su |
| 112 | |
| 113 | # |
| 114 | # If defined, file which inhibits all the usual chatter during the login |
| 115 | # sequence. If a full pathname, then hushed mode will be enabled if the |
| 116 | # user's name or shell are found in the file. If not a full pathname, then |
| 117 | # hushed mode will be enabled if the file exists in the user's home directory. |
| 118 | # |
| 119 | HUSHLOGIN_FILE .hushlogin |
| 120 | #HUSHLOGIN_FILE /etc/hushlogins |
| 121 | |
| 122 | # |
| 123 | # *REQUIRED* The default PATH settings, for superuser and normal users. |
| 124 | # |
| 125 | # (they are minimal, add the rest in the shell startup files) |
| 126 | ENV_SUPATH PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin |
| 127 | ENV_PATH PATH=/usr/local/bin:/usr/bin:/bin:/usr/local/games:/usr/games |
| 128 | |
| 129 | # |
| 130 | # Terminal permissions |
| 131 | # |
| 132 | # TTYGROUP Login tty will be assigned this group ownership. |
| 133 | # TTYPERM Login tty will be set to this permission. |
| 134 | # |
| 135 | # If you have a "write" program which is "setgid" to a special group |
| 136 | # which owns the terminals, define TTYGROUP to the group number and |
| 137 | # TTYPERM to 0620. Otherwise leave TTYGROUP commented out and assign |
| 138 | # TTYPERM to either 622 or 600. |
| 139 | # |
| 140 | # In Debian /usr/bin/bsd-write or similar programs are setgid tty |
| 141 | # However, the default and recommended value for TTYPERM is still 0600 |
| 142 | # to not allow anyone to write to anyone else console or terminal |
| 143 | |
| 144 | # Users can still allow other people to write them by issuing |
| 145 | # the "mesg y" command. |
| 146 | |
| 147 | TTYGROUP tty |
| 148 | TTYPERM 0600 |
| 149 | |
| 150 | # |
| 151 | # Login configuration initializations: |
| 152 | # |
| 153 | # ERASECHAR Terminal ERASE character ('\010' = backspace). |
| 154 | # KILLCHAR Terminal KILL character ('\025' = CTRL/U). |
| 155 | # UMASK Default "umask" value. |
| 156 | # |
| 157 | # The ERASECHAR and KILLCHAR are used only on System V machines. |
| 158 | # |
| 159 | # UMASK is the default umask value for pam_umask and is used by |
| 160 | # useradd and newusers to set the mode of the new home directories. |
| 161 | # 022 is the "historical" value in Debian for UMASK |
| 162 | # 027, or even 077, could be considered better for privacy |
| 163 | # There is no One True Answer here : each sysadmin must make up his/her |
| 164 | # mind. |
| 165 | # |
| 166 | # If USERGROUPS_ENAB is set to "yes", that will modify this UMASK default value |
| 167 | # for private user groups, i. e. the uid is the same as gid, and username is |
| 168 | # the same as the primary group name: for these, the user permissions will be |
| 169 | # used as group permissions, e. g. 022 will become 002. |
| 170 | # |
| 171 | # Prefix these values with "0" to get octal, "0x" to get hexadecimal. |
| 172 | # |
| 173 | ERASECHAR 0177 |
| 174 | KILLCHAR 025 |
| 175 | UMASK 022 |
| 176 | |
| 177 | # HOME_MODE is used by useradd(8) and newusers(8) to set the mode for new |
| 178 | # home directories. |
| 179 | # If HOME_MODE is not set, the value of UMASK is used to create the mode. |
| 180 | HOME_MODE 0750 |
| 181 | |
| 182 | # |
| 183 | # Password aging controls: |
| 184 | # |
| 185 | # PASS_MAX_DAYS Maximum number of days a password may be used. |
| 186 | # PASS_MIN_DAYS Minimum number of days allowed between password changes. |
| 187 | # PASS_WARN_AGE Number of days warning given before a password expires. |
| 188 | # |
| 189 | PASS_MAX_DAYS 99999 |
| 190 | PASS_MIN_DAYS 0 |
| 191 | PASS_WARN_AGE 7 |
| 192 | |
| 193 | # |
| 194 | # Min/max values for automatic uid selection in useradd |
| 195 | # |
| 196 | UID_MIN 1000 |
| 197 | UID_MAX 60000 |
| 198 | # System accounts |
| 199 | #SYS_UID_MIN 100 |
| 200 | #SYS_UID_MAX 999 |
| 201 | # Extra per user uids |
| 202 | SUB_UID_MIN 100000 |
| 203 | SUB_UID_MAX 600100000 |
| 204 | SUB_UID_COUNT 65536 |
| 205 | |
| 206 | # |
| 207 | # Min/max values for automatic gid selection in groupadd |
| 208 | # |
| 209 | GID_MIN 1000 |
| 210 | GID_MAX 60000 |
| 211 | # System accounts |
| 212 | #SYS_GID_MIN 100 |
| 213 | #SYS_GID_MAX 999 |
| 214 | # Extra per user group ids |
| 215 | SUB_GID_MIN 100000 |
| 216 | SUB_GID_MAX 600100000 |
| 217 | SUB_GID_COUNT 65536 |
| 218 | |
| 219 | # |
| 220 | # Max number of login retries if password is bad. This will most likely be |
| 221 | # overriden by PAM, since the default pam_unix module has it's own built |
| 222 | # in of 3 retries. However, this is a safe fallback in case you are using |
| 223 | # an authentication module that does not enforce PAM_MAXTRIES. |
| 224 | # |
| 225 | LOGIN_RETRIES 5 |
| 226 | |
| 227 | # |
| 228 | # Max time in seconds for login |
| 229 | # |
| 230 | LOGIN_TIMEOUT 60 |
| 231 | |
| 232 | # |
| 233 | # Which fields may be changed by regular users using chfn - use |
| 234 | # any combination of letters "frwh" (full name, room number, work |
| 235 | # phone, home phone). If not defined, no changes are allowed. |
| 236 | # For backward compatibility, "yes" = "rwh" and "no" = "frwh". |
| 237 | # |
| 238 | CHFN_RESTRICT rwh |
| 239 | |
| 240 | # |
| 241 | # Should login be allowed if we can't cd to the home directory? |
| 242 | # Default is no. |
| 243 | # |
| 244 | DEFAULT_HOME yes |
| 245 | |
| 246 | # |
| 247 | # If defined, this command is run when removing a user. |
| 248 | # It should remove any at/cron/print jobs etc. owned by |
| 249 | # the user to be removed (passed as the first argument). |
| 250 | # |
| 251 | #USERDEL_CMD /usr/sbin/userdel_local |
| 252 | |
| 253 | # |
| 254 | # Enable setting of the umask group bits to be the same as owner bits |
| 255 | # (examples: 022 -> 002, 077 -> 007) for non-root users, if the uid is |
| 256 | # the same as gid, and username is the same as the primary group name. |
| 257 | # |
| 258 | # If set to yes, userdel will remove the user's group if it contains no |
| 259 | # more members, and useradd will create by default a group with the name |
| 260 | # of the user. |
| 261 | # |
| 262 | USERGROUPS_ENAB yes |
| 263 | |
| 264 | # |
| 265 | # Instead of the real user shell, the program specified by this parameter |
| 266 | # will be launched, although its visible name (argv[0]) will be the shell's. |
| 267 | # The program may do whatever it wants (logging, additional authentification, |
| 268 | # banner, ...) before running the actual shell. |
| 269 | # |
| 270 | # FAKE_SHELL /bin/fakeshell |
| 271 | |
| 272 | # |
| 273 | # If defined, either full pathname of a file containing device names or |
| 274 | # a ":" delimited list of device names. Root logins will be allowed only |
| 275 | # upon these devices. |
| 276 | # |
| 277 | # This variable is used by login and su. |
| 278 | # |
| 279 | #CONSOLE /etc/consoles |
| 280 | #CONSOLE console:tty01:tty02:tty03:tty04 |
| 281 | |
| 282 | # |
| 283 | # List of groups to add to the user's supplementary group set |
| 284 | # when logging in on the console (as determined by the CONSOLE |
| 285 | # setting). Default is none. |
| 286 | # |
| 287 | # Use with caution - it is possible for users to gain permanent |
| 288 | # access to these groups, even when not logged in on the console. |
| 289 | # How to do it is left as an exercise for the reader... |
| 290 | # |
| 291 | # This variable is used by login and su. |
| 292 | # |
| 293 | #CONSOLE_GROUPS floppy:audio:cdrom |
| 294 | |
| 295 | # |
| 296 | # If set to "yes", new passwords will be encrypted using the MD5-based |
| 297 | # algorithm compatible with the one used by recent releases of FreeBSD. |
| 298 | # It supports passwords of unlimited length and longer salt strings. |
| 299 | # Set to "no" if you need to copy encrypted passwords to other systems |
| 300 | # which don't understand the new algorithm. Default is "no". |
| 301 | # |
| 302 | # This variable is deprecated. You should use ENCRYPT_METHOD. |
| 303 | # |
| 304 | #MD5_CRYPT_ENAB no |
| 305 | |
| 306 | # |
| 307 | # If set to MD5, MD5-based algorithm will be used for encrypting password |
| 308 | # If set to SHA256, SHA256-based algorithm will be used for encrypting password |
| 309 | # If set to SHA512, SHA512-based algorithm will be used for encrypting password |
| 310 | # If set to BCRYPT, BCRYPT-based algorithm will be used for encrypting password |
| 311 | # If set to YESCRYPT, YESCRYPT-based algorithm will be used for encrypting password |
| 312 | # If set to DES, DES-based algorithm will be used for encrypting password (default) |
| 313 | # MD5 and DES should not be used for new hashes, see crypt(5) for recommendations. |
| 314 | # Overrides the MD5_CRYPT_ENAB option |
| 315 | # |
| 316 | # Note: It is recommended to use a value consistent with |
| 317 | # the PAM modules configuration. |
| 318 | # |
| 319 | ENCRYPT_METHOD SHA512 |
| 320 | |
| 321 | # |
| 322 | # Only works if ENCRYPT_METHOD is set to SHA256 or SHA512. |
| 323 | # |
| 324 | # Define the number of SHA rounds. |
| 325 | # With a lot of rounds, it is more difficult to brute-force the password. |
| 326 | # However, more CPU resources will be needed to authenticate users if |
| 327 | # this value is increased. |
| 328 | # |
| 329 | # If not specified, the libc will choose the default number of rounds (5000), |
| 330 | # which is orders of magnitude too low for modern hardware. |
| 331 | # The values must be within the 1000-999999999 range. |
| 332 | # If only one of the MIN or MAX values is set, then this value will be used. |
| 333 | # If MIN > MAX, the highest value will be used. |
| 334 | # |
| 335 | #SHA_CRYPT_MIN_ROUNDS 5000 |
| 336 | #SHA_CRYPT_MAX_ROUNDS 5000 |
| 337 | |
| 338 | # |
| 339 | # Only works if ENCRYPT_METHOD is set to YESCRYPT. |
| 340 | # |
| 341 | # Define the YESCRYPT cost factor. |
| 342 | # With a higher cost factor, it is more difficult to brute-force the password. |
| 343 | # However, more CPU time and more memory will be needed to authenticate users |
| 344 | # if this value is increased. |
| 345 | # |
| 346 | # If not specified, a cost factor of 5 will be used. |
| 347 | # The value must be within the 1-11 range. |
| 348 | # |
| 349 | #YESCRYPT_COST_FACTOR 5 |
| 350 | |
| 351 | # |
| 352 | # The pwck(8) utility emits a warning for any system account with a home |
| 353 | # directory that does not exist. Some system accounts intentionally do |
| 354 | # not have a home directory. Such accounts may have this string as |
| 355 | # their home directory in /etc/passwd to avoid a spurious warning. |
| 356 | # |
| 357 | NONEXISTENT /nonexistent |
| 358 | |
| 359 | # |
| 360 | # Allow newuidmap and newgidmap when running under an alternative |
| 361 | # primary group. |
| 362 | # |
| 363 | #GRANT_AUX_GROUP_SUBIDS yes |
| 364 | |
| 365 | # |
| 366 | # Select the HMAC cryptography algorithm. |
| 367 | # Used in pam_timestamp module to calculate the keyed-hash message |
| 368 | # authentication code. |
| 369 | # |
| 370 | # Note: It is recommended to check hmac(3) to see the possible algorithms |
| 371 | # that are available in your system. |
| 372 | # |
| 373 | #HMAC_CRYPTO_ALGO SHA512 |
| 374 | |
| 375 | ################# OBSOLETED BY PAM ############## |
| 376 | # # |
| 377 | # These options are now handled by PAM. Please # |
| 378 | # edit the appropriate file in /etc/pam.d/ to # |
| 379 | # enable the equivelants of them. |
| 380 | # |
| 381 | ############### |
| 382 | |
| 383 | #MOTD_FILE |
| 384 | #DIALUPS_CHECK_ENAB |
| 385 | #LASTLOG_ENAB |
| 386 | #MAIL_CHECK_ENAB |
| 387 | #OBSCURE_CHECKS_ENAB |
| 388 | #PORTTIME_CHECKS_ENAB |
| 389 | #SU_WHEEL_ONLY |
| 390 | #CRACKLIB_DICTPATH |
| 391 | #PASS_CHANGE_TRIES |
| 392 | #PASS_ALWAYS_WARN |
| 393 | #ENVIRON_FILE |
| 394 | #NOLOGINS_FILE |
| 395 | #ISSUE_FILE |
| 396 | #PASS_MIN_LEN |
| 397 | #PASS_MAX_LEN |
| 398 | #ULIMIT |
| 399 | #ENV_HZ |
| 400 | #CHFN_AUTH |
| 401 | #CHSH_AUTH |
| 402 | #FAIL_DELAY |
| 403 | |
| 404 | ################# OBSOLETED ####################### |
| 405 | # # |
| 406 | # These options are no more handled by shadow. # |
| 407 | # # |
| 408 | # Shadow utilities will display a warning if they # |
| 409 | # still appear. # |
| 410 | # # |
| 411 | ################################################### |
| 412 | |
| 413 | # CLOSE_SESSIONS |
| 414 | # LOGIN_STRING |
| 415 | # NO_PASSWORD_CONSOLE |
| 416 | # QMAIL_DIR |
| 417 | |
| 418 | |
| 419 | |
| 420 | |
| 421 | Login restrictions and parameters in /etc/login.defs: |
| 422 | # PASS_MAX_DAYS Maximum number of days a password may be used. |
| 423 | # PASS_MIN_DAYS Minimum number of days allowed between password changes. |
| 424 | # PASS_WARN_AGE Number of days warning given before a password expires. |
| 425 | PASS_MAX_DAYS 99999 |
| 426 | PASS_MIN_DAYS 0 |
| 427 | PASS_WARN_AGE 7 |
| 428 | UID_MIN 1000 |
| 429 | UID_MAX 60000 |
| 430 | #SYS_UID_MIN 100 |
| 431 | #SYS_UID_MAX 999 |
| 432 | SUB_UID_MIN 100000 |
| 433 | SUB_UID_MAX 600100000 |
| 434 | SUB_UID_COUNT 65536 |
| 435 | GID_MIN 1000 |
| 436 | GID_MAX 60000 |
| 437 | #SYS_GID_MIN 100 |
| 438 | #SYS_GID_MAX 999 |
| 439 | SUB_GID_MIN 100000 |
| 440 | SUB_GID_MAX 600100000 |
| 441 | SUB_GID_COUNT 65536 |
| 442 | LOGIN_RETRIES 5 |
| 443 | LOGIN_TIMEOUT 60 |
| 444 | #PASS_MIN_LEN |
| 445 | |
| 446 | Analysis complete. |
| 447 | #+end_src |