| @@ -0,0 +1,447 @@ |
| |
1 | #+title: Linux |
| |
2 | |
| |
3 | * =ssh_root_login.sh= |
| |
4 | |
| |
5 | #+begin_src shell |
| |
6 | ./ssh_root_login.sh |
| |
7 | #+end_src |
| |
8 | |
| |
9 | #+begin_src |
| |
10 | PermitRootLogin no |
| |
11 | #+end_src |
| |
12 | |
| |
13 | * =passwords.sh= |
| |
14 | |
| |
15 | #+begin_src shell |
| |
16 | ./passwords.sh |
| |
17 | #+end_src |
| |
18 | |
| |
19 | #+begin_src |
| |
20 | Starting analysis of authentication and login parameters... |
| |
21 | Checking /etc/pam.d/system-auth for password parameters... |
| |
22 | /etc/pam.d/system-auth file not found. |
| |
23 | Analyzing /etc/login.defs... |
| |
24 | Contents of /etc/login.defs: |
| |
25 | # |
| |
26 | # /etc/login.defs - Configuration control definitions for the login package. |
| |
27 | # |
| |
28 | # Three items must be defined: MAIL_DIR, ENV_SUPATH, and ENV_PATH. |
| |
29 | # If unspecified, some arbitrary (and possibly incorrect) value will |
| |
30 | # be assumed. All other items are optional - if not specified then |
| |
31 | # the described action or option will be inhibited. |
| |
32 | # |
| |
33 | # Comment lines (lines beginning with "#") and blank lines are ignored. |
| |
34 | # |
| |
35 | # Modified for Linux. --marekm |
| |
36 | |
| |
37 | # REQUIRED for useradd/userdel/usermod |
| |
38 | # Directory where mailboxes reside, _or_ name of file, relative to the |
| |
39 | # home directory. If you _do_ define MAIL_DIR and MAIL_FILE, |
| |
40 | # MAIL_DIR takes precedence. |
| |
41 | # |
| |
42 | # Essentially: |
| |
43 | # - MAIL_DIR defines the location of users mail spool files |
| |
44 | # (for mbox use) by appending the username to MAIL_DIR as defined |
| |
45 | # below. |
| |
46 | # - MAIL_FILE defines the location of the users mail spool files as the |
| |
47 | # fully-qualified filename obtained by prepending the user home |
| |
48 | # directory before $MAIL_FILE |
| |
49 | # |
| |
50 | # NOTE: This is no more used for setting up users MAIL environment variable |
| |
51 | # which is, starting from shadow 4.0.12-1 in Debian, entirely the |
| |
52 | # job of the pam_mail PAM modules |
| |
53 | # See default PAM configuration files provided for |
| |
54 | # login, su, etc. |
| |
55 | # |
| |
56 | # This is a temporary situation: setting these variables will soon |
| |
57 | # move to /etc/default/useradd and the variables will then be |
| |
58 | # no more supported |
| |
59 | MAIL_DIR /var/mail |
| |
60 | #MAIL_FILE .mail |
| |
61 | |
| |
62 | # |
| |
63 | # Enable logging and display of /var/log/faillog login failure info. |
| |
64 | # This option conflicts with the pam_tally PAM module. |
| |
65 | # |
| |
66 | FAILLOG_ENAB yes |
| |
67 | |
| |
68 | # |
| |
69 | # Enable display of unknown usernames when login failures are recorded. |
| |
70 | # |
| |
71 | # WARNING: Unknown usernames may become world readable. |
| |
72 | # See #290803 and #298773 for details about how this could become a security |
| |
73 | # concern |
| |
74 | LOG_UNKFAIL_ENAB no |
| |
75 | |
| |
76 | # |
| |
77 | # Enable logging of successful logins |
| |
78 | # |
| |
79 | LOG_OK_LOGINS no |
| |
80 | |
| |
81 | # |
| |
82 | # Enable "syslog" logging of su activity - in addition to sulog file logging. |
| |
83 | # SYSLOG_SG_ENAB does the same for newgrp and sg. |
| |
84 | # |
| |
85 | SYSLOG_SU_ENAB yes |
| |
86 | SYSLOG_SG_ENAB yes |
| |
87 | |
| |
88 | # |
| |
89 | # If defined, all su activity is logged to this file. |
| |
90 | # |
| |
91 | #SULOG_FILE /var/log/sulog |
| |
92 | |
| |
93 | # |
| |
94 | # If defined, file which maps tty line to TERM environment parameter. |
| |
95 | # Each line of the file is in a format something like "vt100 tty01". |
| |
96 | # |
| |
97 | #TTYTYPE_FILE /etc/ttytype |
| |
98 | |
| |
99 | # |
| |
100 | # If defined, login failures will be logged here in a utmp format |
| |
101 | # last, when invoked as lastb, will read /var/log/btmp, so... |
| |
102 | # |
| |
103 | FTMP_FILE /var/log/btmp |
| |
104 | |
| |
105 | # |
| |
106 | # If defined, the command name to display when running "su -". For |
| |
107 | # example, if this is defined as "su" then a "ps" will display the |
| |
108 | # command is "-su". If not defined, then "ps" would display the |
| |
109 | # name of the shell actually being run, e.g. something like "-sh". |
| |
110 | # |
| |
111 | SU_NAME su |
| |
112 | |
| |
113 | # |
| |
114 | # If defined, file which inhibits all the usual chatter during the login |
| |
115 | # sequence. If a full pathname, then hushed mode will be enabled if the |
| |
116 | # user's name or shell are found in the file. If not a full pathname, then |
| |
117 | # hushed mode will be enabled if the file exists in the user's home directory. |
| |
118 | # |
| |
119 | HUSHLOGIN_FILE .hushlogin |
| |
120 | #HUSHLOGIN_FILE /etc/hushlogins |
| |
121 | |
| |
122 | # |
| |
123 | # *REQUIRED* The default PATH settings, for superuser and normal users. |
| |
124 | # |
| |
125 | # (they are minimal, add the rest in the shell startup files) |
| |
126 | ENV_SUPATH PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin |
| |
127 | ENV_PATH PATH=/usr/local/bin:/usr/bin:/bin:/usr/local/games:/usr/games |
| |
128 | |
| |
129 | # |
| |
130 | # Terminal permissions |
| |
131 | # |
| |
132 | # TTYGROUP Login tty will be assigned this group ownership. |
| |
133 | # TTYPERM Login tty will be set to this permission. |
| |
134 | # |
| |
135 | # If you have a "write" program which is "setgid" to a special group |
| |
136 | # which owns the terminals, define TTYGROUP to the group number and |
| |
137 | # TTYPERM to 0620. Otherwise leave TTYGROUP commented out and assign |
| |
138 | # TTYPERM to either 622 or 600. |
| |
139 | # |
| |
140 | # In Debian /usr/bin/bsd-write or similar programs are setgid tty |
| |
141 | # However, the default and recommended value for TTYPERM is still 0600 |
| |
142 | # to not allow anyone to write to anyone else console or terminal |
| |
143 | |
| |
144 | # Users can still allow other people to write them by issuing |
| |
145 | # the "mesg y" command. |
| |
146 | |
| |
147 | TTYGROUP tty |
| |
148 | TTYPERM 0600 |
| |
149 | |
| |
150 | # |
| |
151 | # Login configuration initializations: |
| |
152 | # |
| |
153 | # ERASECHAR Terminal ERASE character ('\010' = backspace). |
| |
154 | # KILLCHAR Terminal KILL character ('\025' = CTRL/U). |
| |
155 | # UMASK Default "umask" value. |
| |
156 | # |
| |
157 | # The ERASECHAR and KILLCHAR are used only on System V machines. |
| |
158 | # |
| |
159 | # UMASK is the default umask value for pam_umask and is used by |
| |
160 | # useradd and newusers to set the mode of the new home directories. |
| |
161 | # 022 is the "historical" value in Debian for UMASK |
| |
162 | # 027, or even 077, could be considered better for privacy |
| |
163 | # There is no One True Answer here : each sysadmin must make up his/her |
| |
164 | # mind. |
| |
165 | # |
| |
166 | # If USERGROUPS_ENAB is set to "yes", that will modify this UMASK default value |
| |
167 | # for private user groups, i. e. the uid is the same as gid, and username is |
| |
168 | # the same as the primary group name: for these, the user permissions will be |
| |
169 | # used as group permissions, e. g. 022 will become 002. |
| |
170 | # |
| |
171 | # Prefix these values with "0" to get octal, "0x" to get hexadecimal. |
| |
172 | # |
| |
173 | ERASECHAR 0177 |
| |
174 | KILLCHAR 025 |
| |
175 | UMASK 022 |
| |
176 | |
| |
177 | # HOME_MODE is used by useradd(8) and newusers(8) to set the mode for new |
| |
178 | # home directories. |
| |
179 | # If HOME_MODE is not set, the value of UMASK is used to create the mode. |
| |
180 | HOME_MODE 0750 |
| |
181 | |
| |
182 | # |
| |
183 | # Password aging controls: |
| |
184 | # |
| |
185 | # PASS_MAX_DAYS Maximum number of days a password may be used. |
| |
186 | # PASS_MIN_DAYS Minimum number of days allowed between password changes. |
| |
187 | # PASS_WARN_AGE Number of days warning given before a password expires. |
| |
188 | # |
| |
189 | PASS_MAX_DAYS 99999 |
| |
190 | PASS_MIN_DAYS 0 |
| |
191 | PASS_WARN_AGE 7 |
| |
192 | |
| |
193 | # |
| |
194 | # Min/max values for automatic uid selection in useradd |
| |
195 | # |
| |
196 | UID_MIN 1000 |
| |
197 | UID_MAX 60000 |
| |
198 | # System accounts |
| |
199 | #SYS_UID_MIN 100 |
| |
200 | #SYS_UID_MAX 999 |
| |
201 | # Extra per user uids |
| |
202 | SUB_UID_MIN 100000 |
| |
203 | SUB_UID_MAX 600100000 |
| |
204 | SUB_UID_COUNT 65536 |
| |
205 | |
| |
206 | # |
| |
207 | # Min/max values for automatic gid selection in groupadd |
| |
208 | # |
| |
209 | GID_MIN 1000 |
| |
210 | GID_MAX 60000 |
| |
211 | # System accounts |
| |
212 | #SYS_GID_MIN 100 |
| |
213 | #SYS_GID_MAX 999 |
| |
214 | # Extra per user group ids |
| |
215 | SUB_GID_MIN 100000 |
| |
216 | SUB_GID_MAX 600100000 |
| |
217 | SUB_GID_COUNT 65536 |
| |
218 | |
| |
219 | # |
| |
220 | # Max number of login retries if password is bad. This will most likely be |
| |
221 | # overriden by PAM, since the default pam_unix module has it's own built |
| |
222 | # in of 3 retries. However, this is a safe fallback in case you are using |
| |
223 | # an authentication module that does not enforce PAM_MAXTRIES. |
| |
224 | # |
| |
225 | LOGIN_RETRIES 5 |
| |
226 | |
| |
227 | # |
| |
228 | # Max time in seconds for login |
| |
229 | # |
| |
230 | LOGIN_TIMEOUT 60 |
| |
231 | |
| |
232 | # |
| |
233 | # Which fields may be changed by regular users using chfn - use |
| |
234 | # any combination of letters "frwh" (full name, room number, work |
| |
235 | # phone, home phone). If not defined, no changes are allowed. |
| |
236 | # For backward compatibility, "yes" = "rwh" and "no" = "frwh". |
| |
237 | # |
| |
238 | CHFN_RESTRICT rwh |
| |
239 | |
| |
240 | # |
| |
241 | # Should login be allowed if we can't cd to the home directory? |
| |
242 | # Default is no. |
| |
243 | # |
| |
244 | DEFAULT_HOME yes |
| |
245 | |
| |
246 | # |
| |
247 | # If defined, this command is run when removing a user. |
| |
248 | # It should remove any at/cron/print jobs etc. owned by |
| |
249 | # the user to be removed (passed as the first argument). |
| |
250 | # |
| |
251 | #USERDEL_CMD /usr/sbin/userdel_local |
| |
252 | |
| |
253 | # |
| |
254 | # Enable setting of the umask group bits to be the same as owner bits |
| |
255 | # (examples: 022 -> 002, 077 -> 007) for non-root users, if the uid is |
| |
256 | # the same as gid, and username is the same as the primary group name. |
| |
257 | # |
| |
258 | # If set to yes, userdel will remove the user's group if it contains no |
| |
259 | # more members, and useradd will create by default a group with the name |
| |
260 | # of the user. |
| |
261 | # |
| |
262 | USERGROUPS_ENAB yes |
| |
263 | |
| |
264 | # |
| |
265 | # Instead of the real user shell, the program specified by this parameter |
| |
266 | # will be launched, although its visible name (argv[0]) will be the shell's. |
| |
267 | # The program may do whatever it wants (logging, additional authentification, |
| |
268 | # banner, ...) before running the actual shell. |
| |
269 | # |
| |
270 | # FAKE_SHELL /bin/fakeshell |
| |
271 | |
| |
272 | # |
| |
273 | # If defined, either full pathname of a file containing device names or |
| |
274 | # a ":" delimited list of device names. Root logins will be allowed only |
| |
275 | # upon these devices. |
| |
276 | # |
| |
277 | # This variable is used by login and su. |
| |
278 | # |
| |
279 | #CONSOLE /etc/consoles |
| |
280 | #CONSOLE console:tty01:tty02:tty03:tty04 |
| |
281 | |
| |
282 | # |
| |
283 | # List of groups to add to the user's supplementary group set |
| |
284 | # when logging in on the console (as determined by the CONSOLE |
| |
285 | # setting). Default is none. |
| |
286 | # |
| |
287 | # Use with caution - it is possible for users to gain permanent |
| |
288 | # access to these groups, even when not logged in on the console. |
| |
289 | # How to do it is left as an exercise for the reader... |
| |
290 | # |
| |
291 | # This variable is used by login and su. |
| |
292 | # |
| |
293 | #CONSOLE_GROUPS floppy:audio:cdrom |
| |
294 | |
| |
295 | # |
| |
296 | # If set to "yes", new passwords will be encrypted using the MD5-based |
| |
297 | # algorithm compatible with the one used by recent releases of FreeBSD. |
| |
298 | # It supports passwords of unlimited length and longer salt strings. |
| |
299 | # Set to "no" if you need to copy encrypted passwords to other systems |
| |
300 | # which don't understand the new algorithm. Default is "no". |
| |
301 | # |
| |
302 | # This variable is deprecated. You should use ENCRYPT_METHOD. |
| |
303 | # |
| |
304 | #MD5_CRYPT_ENAB no |
| |
305 | |
| |
306 | # |
| |
307 | # If set to MD5, MD5-based algorithm will be used for encrypting password |
| |
308 | # If set to SHA256, SHA256-based algorithm will be used for encrypting password |
| |
309 | # If set to SHA512, SHA512-based algorithm will be used for encrypting password |
| |
310 | # If set to BCRYPT, BCRYPT-based algorithm will be used for encrypting password |
| |
311 | # If set to YESCRYPT, YESCRYPT-based algorithm will be used for encrypting password |
| |
312 | # If set to DES, DES-based algorithm will be used for encrypting password (default) |
| |
313 | # MD5 and DES should not be used for new hashes, see crypt(5) for recommendations. |
| |
314 | # Overrides the MD5_CRYPT_ENAB option |
| |
315 | # |
| |
316 | # Note: It is recommended to use a value consistent with |
| |
317 | # the PAM modules configuration. |
| |
318 | # |
| |
319 | ENCRYPT_METHOD SHA512 |
| |
320 | |
| |
321 | # |
| |
322 | # Only works if ENCRYPT_METHOD is set to SHA256 or SHA512. |
| |
323 | # |
| |
324 | # Define the number of SHA rounds. |
| |
325 | # With a lot of rounds, it is more difficult to brute-force the password. |
| |
326 | # However, more CPU resources will be needed to authenticate users if |
| |
327 | # this value is increased. |
| |
328 | # |
| |
329 | # If not specified, the libc will choose the default number of rounds (5000), |
| |
330 | # which is orders of magnitude too low for modern hardware. |
| |
331 | # The values must be within the 1000-999999999 range. |
| |
332 | # If only one of the MIN or MAX values is set, then this value will be used. |
| |
333 | # If MIN > MAX, the highest value will be used. |
| |
334 | # |
| |
335 | #SHA_CRYPT_MIN_ROUNDS 5000 |
| |
336 | #SHA_CRYPT_MAX_ROUNDS 5000 |
| |
337 | |
| |
338 | # |
| |
339 | # Only works if ENCRYPT_METHOD is set to YESCRYPT. |
| |
340 | # |
| |
341 | # Define the YESCRYPT cost factor. |
| |
342 | # With a higher cost factor, it is more difficult to brute-force the password. |
| |
343 | # However, more CPU time and more memory will be needed to authenticate users |
| |
344 | # if this value is increased. |
| |
345 | # |
| |
346 | # If not specified, a cost factor of 5 will be used. |
| |
347 | # The value must be within the 1-11 range. |
| |
348 | # |
| |
349 | #YESCRYPT_COST_FACTOR 5 |
| |
350 | |
| |
351 | # |
| |
352 | # The pwck(8) utility emits a warning for any system account with a home |
| |
353 | # directory that does not exist. Some system accounts intentionally do |
| |
354 | # not have a home directory. Such accounts may have this string as |
| |
355 | # their home directory in /etc/passwd to avoid a spurious warning. |
| |
356 | # |
| |
357 | NONEXISTENT /nonexistent |
| |
358 | |
| |
359 | # |
| |
360 | # Allow newuidmap and newgidmap when running under an alternative |
| |
361 | # primary group. |
| |
362 | # |
| |
363 | #GRANT_AUX_GROUP_SUBIDS yes |
| |
364 | |
| |
365 | # |
| |
366 | # Select the HMAC cryptography algorithm. |
| |
367 | # Used in pam_timestamp module to calculate the keyed-hash message |
| |
368 | # authentication code. |
| |
369 | # |
| |
370 | # Note: It is recommended to check hmac(3) to see the possible algorithms |
| |
371 | # that are available in your system. |
| |
372 | # |
| |
373 | #HMAC_CRYPTO_ALGO SHA512 |
| |
374 | |
| |
375 | ################# OBSOLETED BY PAM ############## |
| |
376 | # # |
| |
377 | # These options are now handled by PAM. Please # |
| |
378 | # edit the appropriate file in /etc/pam.d/ to # |
| |
379 | # enable the equivelants of them. |
| |
380 | # |
| |
381 | ############### |
| |
382 | |
| |
383 | #MOTD_FILE |
| |
384 | #DIALUPS_CHECK_ENAB |
| |
385 | #LASTLOG_ENAB |
| |
386 | #MAIL_CHECK_ENAB |
| |
387 | #OBSCURE_CHECKS_ENAB |
| |
388 | #PORTTIME_CHECKS_ENAB |
| |
389 | #SU_WHEEL_ONLY |
| |
390 | #CRACKLIB_DICTPATH |
| |
391 | #PASS_CHANGE_TRIES |
| |
392 | #PASS_ALWAYS_WARN |
| |
393 | #ENVIRON_FILE |
| |
394 | #NOLOGINS_FILE |
| |
395 | #ISSUE_FILE |
| |
396 | #PASS_MIN_LEN |
| |
397 | #PASS_MAX_LEN |
| |
398 | #ULIMIT |
| |
399 | #ENV_HZ |
| |
400 | #CHFN_AUTH |
| |
401 | #CHSH_AUTH |
| |
402 | #FAIL_DELAY |
| |
403 | |
| |
404 | ################# OBSOLETED ####################### |
| |
405 | # # |
| |
406 | # These options are no more handled by shadow. # |
| |
407 | # # |
| |
408 | # Shadow utilities will display a warning if they # |
| |
409 | # still appear. # |
| |
410 | # # |
| |
411 | ################################################### |
| |
412 | |
| |
413 | # CLOSE_SESSIONS |
| |
414 | # LOGIN_STRING |
| |
415 | # NO_PASSWORD_CONSOLE |
| |
416 | # QMAIL_DIR |
| |
417 | |
| |
418 | |
| |
419 | |
| |
420 | |
| |
421 | Login restrictions and parameters in /etc/login.defs: |
| |
422 | # PASS_MAX_DAYS Maximum number of days a password may be used. |
| |
423 | # PASS_MIN_DAYS Minimum number of days allowed between password changes. |
| |
424 | # PASS_WARN_AGE Number of days warning given before a password expires. |
| |
425 | PASS_MAX_DAYS 99999 |
| |
426 | PASS_MIN_DAYS 0 |
| |
427 | PASS_WARN_AGE 7 |
| |
428 | UID_MIN 1000 |
| |
429 | UID_MAX 60000 |
| |
430 | #SYS_UID_MIN 100 |
| |
431 | #SYS_UID_MAX 999 |
| |
432 | SUB_UID_MIN 100000 |
| |
433 | SUB_UID_MAX 600100000 |
| |
434 | SUB_UID_COUNT 65536 |
| |
435 | GID_MIN 1000 |
| |
436 | GID_MAX 60000 |
| |
437 | #SYS_GID_MIN 100 |
| |
438 | #SYS_GID_MAX 999 |
| |
439 | SUB_GID_MIN 100000 |
| |
440 | SUB_GID_MAX 600100000 |
| |
441 | SUB_GID_COUNT 65536 |
| |
442 | LOGIN_RETRIES 5 |
| |
443 | LOGIN_TIMEOUT 60 |
| |
444 | #PASS_MIN_LEN |
| |
445 | |
| |
446 | Analysis complete. |
| |
447 | #+end_src |