audit-labs/audit-tools

A collection of scripts, queries, and other goodies you can use in an audit. audit automation compliance evidence scripts

Commit 5caad24f4f

5caad24f4ff5ea2b7adad19aefd89a12030c38b0

parent: d9a14ddd14

Unsigned

cmc <hello@cleberg.net> ยท 2025-08-02 18:02 UTC

fix: convert README.org to README.md

Layout: unified ยท split

README.md added +112
@@ -0,0 +1,112 @@
1# ๐Ÿ“Š Audit Tools by Christian Cleberg
2
3Welcome to **Audit Tools** โ€” a collection of open-source Python scripts
4and resources designed to help auditors, risk professionals, and data
5analysts automate common audit tasks and analytics.
6
7Whether you're new to audit automation or an experienced tech-enabled
8auditor, this toolkit offers practical, real-world examples you can use,
9customize, and build upon.
10
11# ๐Ÿ“ฆ What's Inside
12
13This repository contains Python scripts and templates for common audit
14procedures and control testing activities, including:
15
16- โœ… **Pseudo-Random Sampling**
17- โœ… **GITC Extractions and Analysis**
18- โœ… **Project Management Tracking & Visualizations**
19- โœ… **Cloud Platform Analysis (planned)**
20- โœ… **Audit AI Prompts & Guides (planned)**
21
22The goal is to provide practical, easy-to-understand tools that auditors
23and analysts can quickly deploy in their environments.
24
25# ๐Ÿš€ Getting Started
26
27****Clone the Repository****
28
29``` bash
30git clone https://git.sr.ht/~cxc/audit-tools
31cd audit-tools
32```
33
34****Install Dependencies****
35
36*Required for Python scripts*
37
38``` bash
39pip install -r requirements.txt
40```
41
42****Run a Sample Script****
43
44Example: Run the **Linux OS Report** tool.
45
46``` bash
47./os/linux/report/linux.sh
48```
49
50View the results in your terminal or within the file created by the
51script.
52
53# ๐Ÿ“– Learn More
54
55If you're new to audit analytics or Python scripting, start here:
56
57- [Python for Auditors](https://realpython.com)
58- [Audit Analytics 101](https://audit-analytics.com)
59- [Intro to Pandas
60 Documentation](https://pandas.pydata.org/docs/getting_started/)
61
62Also, check out the `notebooks/` folder for interactive tutorials and
63use cases.
64
65# ๐Ÿค How to Contribute
66
67Want to add your own audit scripts or improve existing ones?
68Contributions are welcome!
69
70****Ways to Help****
71
72- Submit new Python scripts for audit use cases.
73- Suggest enhancements or new features.
74- Improve documentation or write beginner-friendly tutorials.
75- Test existing tools on new datasets and report issues.
76
77****To Contribute****
78
791. Fork this repo
80
812. Create a new branch:
82
83 ``` bash
84 git checkout -b my-feature
85 ```
86
873. Commit your changes:
88
89 ``` bash
90 git commit -m 'Added new audit test'
91 ```
92
934. Push to the branch:
94
95 ``` bash
96 git push origin my-feature
97 ```
98
995. Open a Pull Request
100
101# ๐Ÿ‘ค About the Creator
102
103Made with โค๏ธ by [Christian Cleberg](https://cleberg.net/).
104
105I'm a technology assurance leader passionate about audit innovation, AI
106in audit, and building practical tools for auditors and risk
107professionals.
108
109# ๐Ÿ“œ License
110
111This project is licensed under the **GNU General Public License v3.0** โ€”
112see the [LICENSE](LICENSE) file for details.
README.org deleted โˆ’102
@@ -1,102 +0,0 @@
1#+TITLE: Audit Tools by Christian Cleberg
2#+AUTHOR: Christian Cleberg
3#+OPTIONS: toc:nil
4
5* ๐Ÿ“Š Audit Tools by Christian Cleberg
6
7Welcome to *Audit Tools* โ€” a collection of open-source Python scripts and
8resources designed to help auditors, risk professionals, and data analysts
9automate common audit tasks and analytics.
10
11Whether you're new to audit automation or an experienced tech-enabled auditor,
12this toolkit offers practical, real-world examples you can use, customize, and
13build upon.
14
15* ๐Ÿ“ฆ What's Inside
16
17This repository contains Python scripts and templates for common audit
18procedures and control testing activities, including:
19
20- โœ… *Pseudo-Random Sampling*
21- โœ… *GITC Extractions and Analysis*
22- โœ… *Project Management Tracking & Visualizations*
23- โœ… *Cloud Platform Analysis (planned)*
24- โœ… *Audit AI Prompts & Guides (planned)*
25
26The goal is to provide practical, easy-to-understand tools that auditors and
27analysts can quickly deploy in their environments.
28
29* ๐Ÿš€ Getting Started
30
31**Clone the Repository**
32
33#+begin_src bash
34git clone https://git.sr.ht/~cxc/audit-tools
35cd audit-tools
36#+end_src
37
38**Install Dependencies**
39
40/Required for Python scripts/
41
42#+begin_src bash
43pip install -r requirements.txt
44#+end_src
45
46**Run a Sample Script**
47
48Example: Run the *Linux OS Report* tool.
49
50#+begin_src bash
51./os/linux/report/linux.sh
52#+end_src
53
54View the results in your terminal or within the file created by the script.
55
56* ๐Ÿ“– Learn More
57
58If you're new to audit analytics or Python scripting, start here:
59- [[https://realpython.com][Python for Auditors]]
60- [[https://audit-analytics.com][Audit Analytics 101]]
61- [[https://pandas.pydata.org/docs/getting_started/][Intro to Pandas Documentation]]
62
63Also, check out the =notebooks/= folder for interactive tutorials and use cases.
64
65* ๐Ÿค How to Contribute
66
67Want to add your own audit scripts or improve existing ones? Contributions are
68welcome!
69
70**Ways to Help**
71- Submit new Python scripts for audit use cases.
72- Suggest enhancements or new features.
73- Improve documentation or write beginner-friendly tutorials.
74- Test existing tools on new datasets and report issues.
75
76**To Contribute**
771. Fork this repo
782. Create a new branch:
79 #+begin_src bash
80 git checkout -b my-feature
81 #+end_src
823. Commit your changes:
83 #+begin_src bash
84 git commit -m 'Added new audit test'
85 #+end_src
864. Push to the branch:
87 #+begin_src bash
88 git push origin my-feature
89 #+end_src
905. Open a Pull Request
91
92* ๐Ÿ‘ค About the Creator
93
94Made with โค๏ธ by [[https://cleberg.net/][Christian Cleberg]].
95
96I'm a technology assurance leader passionate about audit innovation, AI in
97audit, and building practical tools for auditors and risk professionals.
98
99* ๐Ÿ“œ License
100
101This project is licensed under the *GNU General Public License v3.0* โ€” see the
102[[file:LICENSE][LICENSE]] file for details.
applications/github/README.org โ†’ applications/github/README.md renamed +33 โˆ’32
@@ -1,23 +1,25 @@
1#+title: GitHub Scripts
2
3*NOTE*: I used the same [[https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens][PAT]] for all scripts within this folder. Note that you can likely reduce permissions for certain scripts - it's best practice to define a PAT for a specific purpose and avoid using a single PAT with broad permissions.
1**NOTE**: I used the same
2[PAT](https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens)
3for all scripts within this folder. Note that you can likely reduce
4permissions for certain scripts - it's best practice to define a PAT for
5a specific purpose and avoid using a single PAT with broad permissions.
46
57- Personal Access Token:
6 - [x] Repository Permissions
7 - [x] Actions: read-only
8 - [x] Contents: read-only
9 - [x] Metadata: read-only
10 - [x] Workflows: read-only
11 - [x] Organization Permissions
12 - [x] Administration: read-only
8 - \[x\] Repository Permissions
9 - \[x\] Actions: read-only
10 - \[x\] Contents: read-only
11 - \[x\] Metadata: read-only
12 - \[x\] Workflows: read-only
13 - \[x\] Organization Permissions
14 - \[x\] Administration: read-only
1315
14* =github_admins.py=
16# `github_admins.py`
1517
16#+begin_src sh
18``` bash
1719python ./github_admins.py
18#+end_src
20```
1921
20#+begin_src text
22``` text
2123Members of the organization 'your_organization':
2224
2325Repositories in the organization 'your_organization':
@@ -25,28 +27,27 @@ Repositories in the organization 'your_organization':
2527
2628Collaborators for the repository 'demo-repository':
2729- user1: admin
28#+end_src
30```
2931
30* =github_audit_log.py=
32# `github_audit_log.py`
3133
32*NOTE*: Requires an active GitHub Enterprise subscription.
34**NOTE**: Requires an active GitHub Enterprise subscription.
3335
34#+begin_src sh
36``` bash
3537python ./github_audit_log.py
36#+end_src
38```
3739
38#+begin_src text
40``` text
3941TODO: Need to get an Enterprise subscription to test this script.
40#+end_src
41
42* =github_branch_protections.py=
42```
4343
44# `github_branch_protections.py`
4445
45#+begin_src sh
46``` bash
4647python ./github_branch_protections.py
47#+end_src
48```
4849
49#+begin_src text
50``` text
5051Total branches in the repository 'demo-repository': 1
5152
5253Branch: main
@@ -54,15 +55,15 @@ No protection settings
5455
5556Repository rulesets for 'demo-repository':
5657[{'id': 2311373, 'name': 'default', 'target': 'branch', 'source_type': 'Repository', 'source': 'phryq/demo-repository', 'enforcement': 'active', 'node_id': 'RRS_lACqUmVwb3NpdG9yec40LV1PzgAjRM0', '_links': {'self': {'href': 'https://api.github.com/repos/phryq/demo-repository/rulesets/2311373'}, 'html': {'href': 'https://github.com/phryq/demo-repository/rules/2311373'}}, 'created_at': '2024-10-19T15:59:35.200-05:00', 'updated_at': '2024-10-19T15:59:35.200-05:00'}]
57#+end_src
58```
5859
59* =github_commits.py=
60# `github_commits.py`
6061
61#+begin_src sh
62``` bash
6263python ./github_commits.py
63#+end_src
64```
6465
65#+begin_src text
66``` text
6667Total commits in the repository 'demo-repository' on branch 'main': 3
6768
6869Commit SHA: 13c488a2cdda08e4043f8ef36ced5fdd429e9718
@@ -109,4 +110,4 @@ Files changed:
109110 Additions: 1, Deletions: 0, Changes: 1
110111 - package.json (added)
111112 Additions: 9, Deletions: 0, Changes: 9
112#+end_src
113```
applications/gitlab/README.org โ†’ applications/gitlab/README.md renamed +39 โˆ’40
@@ -1,14 +1,12 @@
1#+title: GitLab Scripts
1# `approvals.py`
22
3* =approvals.py=
3\\This script requires an active Premium or Ultimate subscription.\*\\
44
5\*This script requires an active Premium or Ultimate subscription.*\
6
7#+begin_src sh
5``` bash
86python ./approvals.py
9#+end_src
7```
108
11#+begin_src text
9``` text
1210Rule: All Members
1311 Approvals Required: 1
1412 Rule type: any_approver
@@ -17,15 +15,15 @@ Rule: Default
1715 Rule type: regular
1816 Protected Branch: master
1917 Eligible Approver: Christian Cleberg
20#+end_src
18```
2119
22* =branch_protections.py=
20# `branch_protections.py`
2321
24#+begin_src sh
22``` bash
2523python ./branch_protections.py
26#+end_src
24```
2725
28#+begin_src json
26``` json
2927[
3028 {
3129 "id": 148448212,
@@ -55,27 +53,28 @@ python ./branch_protections.py
5553 "inherited": false
5654 }
5755]
58#+end_src
56```
5957
60* =passwords.py=
58# `passwords.py`
6159
62*This script does not apply to GitLab.com. This is for self-hosted instances only.*
60**This script does not apply to GitLab.com. This is for self-hosted
61instances only.**
6362
64#+begin_src sh
63``` bash
6564python ./passwords.py
66#+end_src
65```
6766
68#+begin_src text
67``` text
6968# TODO: Need access to a self-hosted version of GitLab to test this out.
70#+end_src
69```
7170
72* =pipelines.py=
71# `pipelines.py`
7372
74#+begin_src sh
73``` bash
7574python ./pipelines.py
76#+end_src
75```
7776
78#+begin_src text
77``` text
7978Pipeline ID: 1754222228
8079 Status: failed
8180 Ref: master
@@ -100,28 +99,28 @@ Pipeline ID: 1754214637
10099 Created At: 2025-04-06T03:21:39.902Z
101100 Duration: N/A seconds
102101 Configuration: N/A
103#+end_src
102```
104103
105* =provisioning.py=
104# `provisioning.py`
106105
107\*This script requires an active Premium or Ultimate subscription.*\
106\\This script requires an active Premium or Ultimate subscription.\*\\
108107
109#+begin_src sh
108``` bash
110109python ./provisioning.py
111#+end_src
110```
112111
113#+begin_src text
112``` text
114113Group: 105300140
115114 2025-04-08T03:33:17.055Z : Action: member_created, Member: 128029250, Author: 24608590
116#+end_src
115```
117116
118* =repositories.py=
117# `repositories.py`
119118
120#+begin_src shell
119``` shell
121120python ./repositories.py
122#+end_src
121```
123122
124#+begin_src text
123``` text
125124# User ID Example
126125Projects under ID: ccleberg:
127126- audit-tools (ID: 68757698)
@@ -131,15 +130,15 @@ Projects under ID: ccleberg:
131130Projects under ID: phryq:
132131- Yoshi Cli (ID: 68757750)
133132- pages-demo (ID: 68757186)
134#+end_src
133```
135134
136* =users.py=
135# `users.py`
137136
138#+begin_src sh
137``` bash
139138python ./users.py
140#+end_src
139```
141140
142#+begin_src text
141``` text
143142Access Level Roles:
144143 0 : No access
145144 5 : Minimal access
@@ -158,4 +157,4 @@ Username: ccleberg, Access Level: 50
158157Project 68701468 Members:
159158Username: ccleberg, Access Level: 50
160159Username: project_68701468_bot_2c7ee010a479c0e48cdb4c7c5cfae886, Access Level: 40
161#+end_src
160```
databases/mongo/README.org โ†’ databases/mongo/README.md renamed +102 โˆ’104
@@ -1,104 +1,102 @@
1#+title: MongoDB Scripts
2
3* =admins.py=
4
5Dependency:
6
7#+begin_src shell
8pip install pymongo
9#+end_src
10
11#+begin_src python
12python ./admins.py
13#+end_src
14
15Example output:
16
17#+begin_src json
18[
19 {
20 "_id": "admin.admin",
21 "user": "admin",
22 "db": "admin",
23 "roles": [
24 {
25 "role": "userAdminAnyDatabase",
26 "db": "admin"
27 },
28 {
29 "role": "readWriteAnyDatabase",
30 "db": "admin"
31 },
32 {
33 "role": "dbAdminAnyDatabase",
34 "db": "admin"
35 },
36 {
37 "role": "clusterAdmin",
38 "db": "admin"
39 }
40 ],
41 "credentials": {
42 "SCRAM-SHA-1": {
43 "iterationCount": 10000,
44 "salt": "abc123",
45 "storedKey": "storedKeyHash",
46 "serverKey": "serverKeyHash"
47 },
48 "SCRAM-SHA-256": {
49 "iterationCount": 15000,
50 "salt": "def456",
51 "storedKey": "storedKeyHash256",
52 "serverKey": "serverKeyHash256"
53 }
54 }
55 },
56 {
57 "_id": "test.user1",
58 "user": "user1",
59 "db": "test",
60 "roles": [
61 {
62 "role": "readWrite",
63 "db": "test"
64 }
65 ],
66 "credentials": {
67 "SCRAM-SHA-1": {
68 "iterationCount": 10000,
69 "salt": "ghi789",
70 "storedKey": "storedKeyHashUser1",
71 "serverKey": "serverKeyHashUser1"
72 }
73 }
74 },
75 {
76 "_id": "test.ldapUser",
77 "user": "ldapUser",
78 "db": "test",
79 "roles": [
80 {
81 "role": "read",
82 "db": "test"
83 }
84 ],
85 "userSource": "ldap"
86 },
87 {
88 "_id": "admin.x509User",
89 "user": "x509User",
90 "db": "$external",
91 "roles": [
92 {
93 "role": "readWrite",
94 "db": "admin"
95 }
96 ],
97 "credentials": {
98 "MONGODB-X509": {
99 "subject": "CN=x509User,OU=OrgUnit,O=Org,L=City,ST=State,C=Country"
100 }
101 }
102 }
103]
104#+end_src
1# `admins.py`
2
3Dependency:
4
5``` shell
6pip install pymongo
7```
8
9``` python
10python ./admins.py
11```
12
13Example output:
14
15``` json
16[
17 {
18 "_id": "admin.admin",
19 "user": "admin",
20 "db": "admin",
21 "roles": [
22 {
23 "role": "userAdminAnyDatabase",
24 "db": "admin"
25 },
26 {
27 "role": "readWriteAnyDatabase",
28 "db": "admin"
29 },
30 {
31 "role": "dbAdminAnyDatabase",
32 "db": "admin"
33 },
34 {
35 "role": "clusterAdmin",
36 "db": "admin"
37 }
38 ],
39 "credentials": {
40 "SCRAM-SHA-1": {
41 "iterationCount": 10000,
42 "salt": "abc123",
43 "storedKey": "storedKeyHash",
44 "serverKey": "serverKeyHash"
45 },
46 "SCRAM-SHA-256": {
47 "iterationCount": 15000,
48 "salt": "def456",
49 "storedKey": "storedKeyHash256",
50 "serverKey": "serverKeyHash256"
51 }
52 }
53 },
54 {
55 "_id": "test.user1",
56 "user": "user1",
57 "db": "test",
58 "roles": [
59 {
60 "role": "readWrite",
61 "db": "test"
62 }
63 ],
64 "credentials": {
65 "SCRAM-SHA-1": {
66 "iterationCount": 10000,
67 "salt": "ghi789",
68 "storedKey": "storedKeyHashUser1",
69 "serverKey": "serverKeyHashUser1"
70 }
71 }
72 },
73 {
74 "_id": "test.ldapUser",
75 "user": "ldapUser",
76 "db": "test",
77 "roles": [
78 {
79 "role": "read",
80 "db": "test"
81 }
82 ],
83 "userSource": "ldap"
84 },
85 {
86 "_id": "admin.x509User",
87 "user": "x509User",
88 "db": "$external",
89 "roles": [
90 {
91 "role": "readWrite",
92 "db": "admin"
93 }
94 ],
95 "credentials": {
96 "MONGODB-X509": {
97 "subject": "CN=x509User,OU=OrgUnit,O=Org,L=City,ST=State,C=Country"
98 }
99 }
100 }
101]
102```
databases/mysql/README.md added +173
@@ -0,0 +1,173 @@
1# `mysql_admins.sql`
2
3``` sql
4SELECT * FROM information_schema.user_privileges;
5```
6
7 MySQL [(none)]> SELECT * FROM information_schema.user_privileges;
8 +--------------------------------+---------------+---------------------------------+--------------+
9 | GRANTEE | TABLE_CATALOG | PRIVILEGE_TYPE | IS_GRANTABLE |
10 +--------------------------------+---------------+---------------------------------+--------------+
11 | 'mysql.infoschema'@'localhost' | def | SELECT | NO |
12 | 'mysql.infoschema'@'localhost' | def | AUDIT_ABORT_EXEMPT | NO |
13 | 'mysql.infoschema'@'localhost' | def | FIREWALL_EXEMPT | NO |
14 | 'mysql.infoschema'@'localhost' | def | SYSTEM_USER | NO |
15 | 'mysql.session'@'localhost' | def | SHUTDOWN | NO |
16 | 'mysql.session'@'localhost' | def | SUPER | NO |
17 | 'mysql.session'@'localhost' | def | AUDIT_ABORT_EXEMPT | NO |
18 | 'mysql.session'@'localhost' | def | AUTHENTICATION_POLICY_ADMIN | NO |
19 | 'mysql.session'@'localhost' | def | BACKUP_ADMIN | NO |
20 | 'mysql.session'@'localhost' | def | CLONE_ADMIN | NO |
21 | 'mysql.session'@'localhost' | def | CONNECTION_ADMIN | NO |
22 | 'mysql.session'@'localhost' | def | FIREWALL_EXEMPT | NO |
23 | 'mysql.session'@'localhost' | def | PERSIST_RO_VARIABLES_ADMIN | NO |
24 | 'mysql.session'@'localhost' | def | SESSION_VARIABLES_ADMIN | NO |
25 | 'mysql.session'@'localhost' | def | SYSTEM_USER | NO |
26 | 'mysql.session'@'localhost' | def | SYSTEM_VARIABLES_ADMIN | NO |
27 | 'mysql.sys'@'localhost' | def | USAGE | NO |
28 | 'mysql.sys'@'localhost' | def | AUDIT_ABORT_EXEMPT | NO |
29 | 'mysql.sys'@'localhost' | def | FIREWALL_EXEMPT | NO |
30 | 'mysql.sys'@'localhost' | def | SYSTEM_USER | NO |
31 | 'root'@'localhost' | def | SELECT | YES |
32 | 'root'@'localhost' | def | INSERT | YES |
33 | 'root'@'localhost' | def | UPDATE | YES |
34 | 'root'@'localhost' | def | DELETE | YES |
35 | 'root'@'localhost' | def | CREATE | YES |
36 | 'root'@'localhost' | def | DROP | YES |
37 | 'root'@'localhost' | def | RELOAD | YES |
38 | 'root'@'localhost' | def | SHUTDOWN | YES |
39 | 'root'@'localhost' | def | PROCESS | YES |
40 | 'root'@'localhost' | def | FILE | YES |
41 | 'root'@'localhost' | def | REFERENCES | YES |
42 | 'root'@'localhost' | def | INDEX | YES |
43 | 'root'@'localhost' | def | ALTER | YES |
44 | 'root'@'localhost' | def | SHOW DATABASES | YES |
45 | 'root'@'localhost' | def | SUPER | YES |
46 | 'root'@'localhost' | def | CREATE TEMPORARY TABLES | YES |
47 | 'root'@'localhost' | def | LOCK TABLES | YES |
48 | 'root'@'localhost' | def | EXECUTE | YES |
49 | 'root'@'localhost' | def | REPLICATION SLAVE | YES |
50 | 'root'@'localhost' | def | REPLICATION CLIENT | YES |
51 | 'root'@'localhost' | def | CREATE VIEW | YES |
52 | 'root'@'localhost' | def | SHOW VIEW | YES |
53 | 'root'@'localhost' | def | CREATE ROUTINE | YES |
54 | 'root'@'localhost' | def | ALTER ROUTINE | YES |
55 | 'root'@'localhost' | def | CREATE USER | YES |
56 | 'root'@'localhost' | def | EVENT | YES |
57 | 'root'@'localhost' | def | TRIGGER | YES |
58 | 'root'@'localhost' | def | CREATE TABLESPACE | YES |
59 | 'root'@'localhost' | def | CREATE ROLE | YES |
60 | 'root'@'localhost' | def | DROP ROLE | YES |
61 | 'root'@'localhost' | def | ALLOW_NONEXISTENT_DEFINER | YES |
62 | 'root'@'localhost' | def | APPLICATION_PASSWORD_ADMIN | YES |
63 | 'root'@'localhost' | def | AUDIT_ABORT_EXEMPT | YES |
64 | 'root'@'localhost' | def | AUDIT_ADMIN | YES |
65 | 'root'@'localhost' | def | AUTHENTICATION_POLICY_ADMIN | YES |
66 | 'root'@'localhost' | def | BACKUP_ADMIN | YES |
67 | 'root'@'localhost' | def | BINLOG_ADMIN | YES |
68 | 'root'@'localhost' | def | BINLOG_ENCRYPTION_ADMIN | YES |
69 | 'root'@'localhost' | def | CLONE_ADMIN | YES |
70 | 'root'@'localhost' | def | CONNECTION_ADMIN | YES |
71 | 'root'@'localhost' | def | CREATE_SPATIAL_REFERENCE_SYSTEM | YES |
72 | 'root'@'localhost' | def | ENCRYPTION_KEY_ADMIN | YES |
73 | 'root'@'localhost' | def | FIREWALL_EXEMPT | YES |
74 | 'root'@'localhost' | def | FLUSH_OPTIMIZER_COSTS | YES |
75 | 'root'@'localhost' | def | FLUSH_PRIVILEGES | YES |
76 | 'root'@'localhost' | def | FLUSH_STATUS | YES |
77 | 'root'@'localhost' | def | FLUSH_TABLES | YES |
78 | 'root'@'localhost' | def | FLUSH_USER_RESOURCES | YES |
79 | 'root'@'localhost' | def | GROUP_REPLICATION_ADMIN | YES |
80 | 'root'@'localhost' | def | GROUP_REPLICATION_STREAM | YES |
81 | 'root'@'localhost' | def | INNODB_REDO_LOG_ARCHIVE | YES |
82 | 'root'@'localhost' | def | INNODB_REDO_LOG_ENABLE | YES |
83 | 'root'@'localhost' | def | OPTIMIZE_LOCAL_TABLE | YES |
84 | 'root'@'localhost' | def | PASSWORDLESS_USER_ADMIN | YES |
85 | 'root'@'localhost' | def | PERSIST_RO_VARIABLES_ADMIN | YES |
86 | 'root'@'localhost' | def | REPLICATION_APPLIER | YES |
87 | 'root'@'localhost' | def | REPLICATION_SLAVE_ADMIN | YES |
88 | 'root'@'localhost' | def | RESOURCE_GROUP_ADMIN | YES |
89 | 'root'@'localhost' | def | RESOURCE_GROUP_USER | YES |
90 | 'root'@'localhost' | def | ROLE_ADMIN | YES |
91 | 'root'@'localhost' | def | SENSITIVE_VARIABLES_OBSERVER | YES |
92 | 'root'@'localhost' | def | SERVICE_CONNECTION_ADMIN | YES |
93 | 'root'@'localhost' | def | SESSION_VARIABLES_ADMIN | YES |
94 | 'root'@'localhost' | def | SET_ANY_DEFINER | YES |
95 | 'root'@'localhost' | def | SHOW_ROUTINE | YES |
96 | 'root'@'localhost' | def | SYSTEM_USER | YES |
97 | 'root'@'localhost' | def | SYSTEM_VARIABLES_ADMIN | YES |
98 | 'root'@'localhost' | def | TABLE_ENCRYPTION_ADMIN | YES |
99 | 'root'@'localhost' | def | TELEMETRY_LOG_ADMIN | YES |
100 | 'root'@'localhost' | def | TRANSACTION_GTID_TAG | YES |
101 | 'root'@'localhost' | def | XA_RECOVER_ADMIN | YES |
102 | 'cmc'@'%' | def | USAGE | NO |
103 +--------------------------------+---------------+---------------------------------+--------------+
104 92 rows in set (0.001 sec)
105
106# `passwords.sql`
107
108``` sql
109SELECT user, host, plugin FROM mysql.user;
110```
111
112 mysql> SELECT user, host, plugin FROM mysql.user;
113 +------------------+-----------+-----------------------+
114 | user | host | plugin |
115 +------------------+-----------+-----------------------+
116 | cmc | % | caching_sha2_password |
117 | mysql.infoschema | localhost | caching_sha2_password |
118 | mysql.session | localhost | caching_sha2_password |
119 | mysql.sys | localhost | caching_sha2_password |
120 | root | localhost | caching_sha2_password |
121 +------------------+-----------+-----------------------+
122 5 rows in set (0.001 sec)
123
124``` sql
125SHOW GLOBAL VARIABLES LIKE 'validate_password%';
126SHOW VARIABLES LIKE 'validate_password%';
127```
128
129 mysql> SHOW GLOBAL VARIABLES LIKE 'validate_password%';
130 +-------------------------------------------------+--------+
131 | Variable_name | Value |
132 +-------------------------------------------------+--------+
133 | validate_password.changed_characters_percentage | 0 |
134 | validate_password.check_user_name | ON |
135 | validate_password.dictionary_file | |
136 | validate_password.length | 8 |
137 | validate_password.mixed_case_count | 1 |
138 | validate_password.number_count | 1 |
139 | validate_password.policy | MEDIUM |
140 | validate_password.special_char_count | 1 |
141 +-------------------------------------------------+--------+
142 8 rows in set (0.004 sec)
143
144 mysql> SHOW VARIABLES LIKE 'validate_password%';
145 +-------------------------------------------------+--------+
146 | Variable_name | Value |
147 +-------------------------------------------------+--------+
148 | validate_password.changed_characters_percentage | 0 |
149 | validate_password.check_user_name | ON |
150 | validate_password.dictionary_file | |
151 | validate_password.length | 8 |
152 | validate_password.mixed_case_count | 1 |
153 | validate_password.number_count | 1 |
154 | validate_password.policy | MEDIUM |
155 | validate_password.special_char_count | 1 |
156 +-------------------------------------------------+--------+
157 8 rows in set (0.004 sec)
158
159``` sql
160SELECT * FROM mysql.user
161```
162
163 MySQL [(none)]> SELECT * FROM mysql.user;
164 +-----------+------------------+-------------+-------------+-------------+-------------+-------------+-----------+-------------+---------------+--------------+-----------+------------+-----------------+------------+------------+--------------+------------+-----------------------+------------------+--------------+-----------------+------------------+------------------+----------------+---------------------+--------------------+------------------+------------+--------------+------------------------+----------+------------+-------------+--------------+---------------+-------------+-----------------+----------------------+-----------------------+------------------------------------------------------------------------+------------------+-----------------------+-------------------+----------------+------------------+----------------+------------------------+---------------------+--------------------------+-----------------+
165 | Host | User | Select_priv | Insert_priv | Update_priv | Delete_priv | Create_priv | Drop_priv | Reload_priv | Shutdown_priv | Process_priv | File_priv | Grant_priv | References_priv | Index_priv | Alter_priv | Show_db_priv | Super_priv | Create_tmp_table_priv | Lock_tables_priv | Execute_priv | Repl_slave_priv | Repl_client_priv | Create_view_priv | Show_view_priv | Create_routine_priv | Alter_routine_priv | Create_user_priv | Event_priv | Trigger_priv | Create_tablespace_priv | ssl_type | ssl_cipher | x509_issuer | x509_subject | max_questions | max_updates | max_connections | max_user_connections | plugin | authentication_string | password_expired | password_last_changed | password_lifetime | account_locked | Create_role_priv | Drop_role_priv | Password_reuse_history | Password_reuse_time | Password_require_current | User_attributes |
166 +-----------+------------------+-------------+-------------+-------------+-------------+-------------+-----------+-------------+---------------+--------------+-----------+------------+-----------------+------------+------------+--------------+------------+-----------------------+------------------+--------------+-----------------+------------------+------------------+----------------+---------------------+--------------------+------------------+------------+--------------+------------------------+----------+------------+-------------+--------------+---------------+-------------+-----------------+----------------------+-----------------------+------------------------------------------------------------------------+------------------+-----------------------+-------------------+----------------+------------------+----------------+------------------------+---------------------+--------------------------+-----------------+
167 | % | cmc | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | | | | | 0 | 0 | 0 | 0 | caching_sha2_password | | N | 2025-04-25 16:28:52 | NULL | N | N | N | NULL | NULL | NULL | NULL |
168 | localhost | mysql.infoschema | Y | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | | | | | 0 | 0 | 0 | 0 | caching_sha2_password | $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED | N | 2025-04-25 15:51:53 | NULL | Y | N | N | NULL | NULL | NULL | NULL |
169 | localhost | mysql.session | N | N | N | N | N | N | N | Y | N | N | N | N | N | N | N | Y | N | N | N | N | N | N | N | N | N | N | N | N | N | | | | | 0 | 0 | 0 | 0 | caching_sha2_password | $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED | N | 2025-04-25 15:51:53 | NULL | Y | N | N | NULL | NULL | NULL | NULL |
170 | localhost | mysql.sys | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | | | | | 0 | 0 | 0 | 0 | caching_sha2_password | $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED | N | 2025-04-25 15:51:53 | NULL | Y | N | N | NULL | NULL | NULL | NULL |
171 | localhost | root | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | | | | | 0 | 0 | 0 | 0 | caching_sha2_password | | N | 2025-04-25 15:51:53 | NULL | N | Y | Y | NULL | NULL | NULL | NULL |
172 +-----------+------------------+-------------+-------------+-------------+-------------+-------------+-----------+-------------+---------------+--------------+-----------+------------+-----------------+------------+------------+--------------+------------+-----------------------+------------------+--------------+-----------------+------------------+------------------+----------------+---------------------+--------------------+------------------+------------+--------------+------------------------+----------+------------+-------------+--------------+---------------+-------------+-----------------+----------------------+-----------------------+------------------------------------------------------------------------+------------------+-----------------------+-------------------+----------------+------------------+----------------+------------------------+---------------------+--------------------------+-----------------+
173 5 rows in set (0.005 sec)
databases/mysql/README.org deleted โˆ’183
@@ -1,183 +0,0 @@
1#+title: MySQL
2
3* =mysql_admins.sql=
4
5#+begin_src sql
6SELECT * FROM information_schema.user_privileges;
7#+end_src
8
9#+begin_src
10MySQL [(none)]> SELECT * FROM information_schema.user_privileges;
11+--------------------------------+---------------+---------------------------------+--------------+
12| GRANTEE | TABLE_CATALOG | PRIVILEGE_TYPE | IS_GRANTABLE |
13+--------------------------------+---------------+---------------------------------+--------------+
14| 'mysql.infoschema'@'localhost' | def | SELECT | NO |
15| 'mysql.infoschema'@'localhost' | def | AUDIT_ABORT_EXEMPT | NO |
16| 'mysql.infoschema'@'localhost' | def | FIREWALL_EXEMPT | NO |
17| 'mysql.infoschema'@'localhost' | def | SYSTEM_USER | NO |
18| 'mysql.session'@'localhost' | def | SHUTDOWN | NO |
19| 'mysql.session'@'localhost' | def | SUPER | NO |
20| 'mysql.session'@'localhost' | def | AUDIT_ABORT_EXEMPT | NO |
21| 'mysql.session'@'localhost' | def | AUTHENTICATION_POLICY_ADMIN | NO |
22| 'mysql.session'@'localhost' | def | BACKUP_ADMIN | NO |
23| 'mysql.session'@'localhost' | def | CLONE_ADMIN | NO |
24| 'mysql.session'@'localhost' | def | CONNECTION_ADMIN | NO |
25| 'mysql.session'@'localhost' | def | FIREWALL_EXEMPT | NO |
26| 'mysql.session'@'localhost' | def | PERSIST_RO_VARIABLES_ADMIN | NO |
27| 'mysql.session'@'localhost' | def | SESSION_VARIABLES_ADMIN | NO |
28| 'mysql.session'@'localhost' | def | SYSTEM_USER | NO |
29| 'mysql.session'@'localhost' | def | SYSTEM_VARIABLES_ADMIN | NO |
30| 'mysql.sys'@'localhost' | def | USAGE | NO |
31| 'mysql.sys'@'localhost' | def | AUDIT_ABORT_EXEMPT | NO |
32| 'mysql.sys'@'localhost' | def | FIREWALL_EXEMPT | NO |
33| 'mysql.sys'@'localhost' | def | SYSTEM_USER | NO |
34| 'root'@'localhost' | def | SELECT | YES |
35| 'root'@'localhost' | def | INSERT | YES |
36| 'root'@'localhost' | def | UPDATE | YES |
37| 'root'@'localhost' | def | DELETE | YES |
38| 'root'@'localhost' | def | CREATE | YES |
39| 'root'@'localhost' | def | DROP | YES |
40| 'root'@'localhost' | def | RELOAD | YES |
41| 'root'@'localhost' | def | SHUTDOWN | YES |
42| 'root'@'localhost' | def | PROCESS | YES |
43| 'root'@'localhost' | def | FILE | YES |
44| 'root'@'localhost' | def | REFERENCES | YES |
45| 'root'@'localhost' | def | INDEX | YES |
46| 'root'@'localhost' | def | ALTER | YES |
47| 'root'@'localhost' | def | SHOW DATABASES | YES |
48| 'root'@'localhost' | def | SUPER | YES |
49| 'root'@'localhost' | def | CREATE TEMPORARY TABLES | YES |
50| 'root'@'localhost' | def | LOCK TABLES | YES |
51| 'root'@'localhost' | def | EXECUTE | YES |
52| 'root'@'localhost' | def | REPLICATION SLAVE | YES |
53| 'root'@'localhost' | def | REPLICATION CLIENT | YES |
54| 'root'@'localhost' | def | CREATE VIEW | YES |
55| 'root'@'localhost' | def | SHOW VIEW | YES |
56| 'root'@'localhost' | def | CREATE ROUTINE | YES |
57| 'root'@'localhost' | def | ALTER ROUTINE | YES |
58| 'root'@'localhost' | def | CREATE USER | YES |
59| 'root'@'localhost' | def | EVENT | YES |
60| 'root'@'localhost' | def | TRIGGER | YES |
61| 'root'@'localhost' | def | CREATE TABLESPACE | YES |
62| 'root'@'localhost' | def | CREATE ROLE | YES |
63| 'root'@'localhost' | def | DROP ROLE | YES |
64| 'root'@'localhost' | def | ALLOW_NONEXISTENT_DEFINER | YES |
65| 'root'@'localhost' | def | APPLICATION_PASSWORD_ADMIN | YES |
66| 'root'@'localhost' | def | AUDIT_ABORT_EXEMPT | YES |
67| 'root'@'localhost' | def | AUDIT_ADMIN | YES |
68| 'root'@'localhost' | def | AUTHENTICATION_POLICY_ADMIN | YES |
69| 'root'@'localhost' | def | BACKUP_ADMIN | YES |
70| 'root'@'localhost' | def | BINLOG_ADMIN | YES |
71| 'root'@'localhost' | def | BINLOG_ENCRYPTION_ADMIN | YES |
72| 'root'@'localhost' | def | CLONE_ADMIN | YES |
73| 'root'@'localhost' | def | CONNECTION_ADMIN | YES |
74| 'root'@'localhost' | def | CREATE_SPATIAL_REFERENCE_SYSTEM | YES |
75| 'root'@'localhost' | def | ENCRYPTION_KEY_ADMIN | YES |
76| 'root'@'localhost' | def | FIREWALL_EXEMPT | YES |
77| 'root'@'localhost' | def | FLUSH_OPTIMIZER_COSTS | YES |
78| 'root'@'localhost' | def | FLUSH_PRIVILEGES | YES |
79| 'root'@'localhost' | def | FLUSH_STATUS | YES |
80| 'root'@'localhost' | def | FLUSH_TABLES | YES |
81| 'root'@'localhost' | def | FLUSH_USER_RESOURCES | YES |
82| 'root'@'localhost' | def | GROUP_REPLICATION_ADMIN | YES |
83| 'root'@'localhost' | def | GROUP_REPLICATION_STREAM | YES |
84| 'root'@'localhost' | def | INNODB_REDO_LOG_ARCHIVE | YES |
85| 'root'@'localhost' | def | INNODB_REDO_LOG_ENABLE | YES |
86| 'root'@'localhost' | def | OPTIMIZE_LOCAL_TABLE | YES |
87| 'root'@'localhost' | def | PASSWORDLESS_USER_ADMIN | YES |
88| 'root'@'localhost' | def | PERSIST_RO_VARIABLES_ADMIN | YES |
89| 'root'@'localhost' | def | REPLICATION_APPLIER | YES |
90| 'root'@'localhost' | def | REPLICATION_SLAVE_ADMIN | YES |
91| 'root'@'localhost' | def | RESOURCE_GROUP_ADMIN | YES |
92| 'root'@'localhost' | def | RESOURCE_GROUP_USER | YES |
93| 'root'@'localhost' | def | ROLE_ADMIN | YES |
94| 'root'@'localhost' | def | SENSITIVE_VARIABLES_OBSERVER | YES |
95| 'root'@'localhost' | def | SERVICE_CONNECTION_ADMIN | YES |
96| 'root'@'localhost' | def | SESSION_VARIABLES_ADMIN | YES |
97| 'root'@'localhost' | def | SET_ANY_DEFINER | YES |
98| 'root'@'localhost' | def | SHOW_ROUTINE | YES |
99| 'root'@'localhost' | def | SYSTEM_USER | YES |
100| 'root'@'localhost' | def | SYSTEM_VARIABLES_ADMIN | YES |
101| 'root'@'localhost' | def | TABLE_ENCRYPTION_ADMIN | YES |
102| 'root'@'localhost' | def | TELEMETRY_LOG_ADMIN | YES |
103| 'root'@'localhost' | def | TRANSACTION_GTID_TAG | YES |
104| 'root'@'localhost' | def | XA_RECOVER_ADMIN | YES |
105| 'cmc'@'%' | def | USAGE | NO |
106+--------------------------------+---------------+---------------------------------+--------------+
10792 rows in set (0.001 sec)
108#+end_src
109
110* =passwords.sql=
111
112#+begin_src sql
113SELECT user, host, plugin FROM mysql.user;
114#+end_src
115
116#+begin_src
117mysql> SELECT user, host, plugin FROM mysql.user;
118+------------------+-----------+-----------------------+
119| user | host | plugin |
120+------------------+-----------+-----------------------+
121| cmc | % | caching_sha2_password |
122| mysql.infoschema | localhost | caching_sha2_password |
123| mysql.session | localhost | caching_sha2_password |
124| mysql.sys | localhost | caching_sha2_password |
125| root | localhost | caching_sha2_password |
126+------------------+-----------+-----------------------+
1275 rows in set (0.001 sec)
128#+end_src
129
130#+begin_src sql
131SHOW GLOBAL VARIABLES LIKE 'validate_password%';
132SHOW VARIABLES LIKE 'validate_password%';
133#+end_src
134
135#+begin_src
136mysql> SHOW GLOBAL VARIABLES LIKE 'validate_password%';
137+-------------------------------------------------+--------+
138| Variable_name | Value |
139+-------------------------------------------------+--------+
140| validate_password.changed_characters_percentage | 0 |
141| validate_password.check_user_name | ON |
142| validate_password.dictionary_file | |
143| validate_password.length | 8 |
144| validate_password.mixed_case_count | 1 |
145| validate_password.number_count | 1 |
146| validate_password.policy | MEDIUM |
147| validate_password.special_char_count | 1 |
148+-------------------------------------------------+--------+
1498 rows in set (0.004 sec)
150
151mysql> SHOW VARIABLES LIKE 'validate_password%';
152+-------------------------------------------------+--------+
153| Variable_name | Value |
154+-------------------------------------------------+--------+
155| validate_password.changed_characters_percentage | 0 |
156| validate_password.check_user_name | ON |
157| validate_password.dictionary_file | |
158| validate_password.length | 8 |
159| validate_password.mixed_case_count | 1 |
160| validate_password.number_count | 1 |
161| validate_password.policy | MEDIUM |
162| validate_password.special_char_count | 1 |
163+-------------------------------------------------+--------+
1648 rows in set (0.004 sec)
165#+end_src
166
167#+begin_src sql
168SELECT * FROM mysql.user
169#+end_src
170
171#+begin_src
172MySQL [(none)]> SELECT * FROM mysql.user;
173+-----------+------------------+-------------+-------------+-------------+-------------+-------------+-----------+-------------+---------------+--------------+-----------+------------+-----------------+------------+------------+--------------+------------+-----------------------+------------------+--------------+-----------------+------------------+------------------+----------------+---------------------+--------------------+------------------+------------+--------------+------------------------+----------+------------+-------------+--------------+---------------+-------------+-----------------+----------------------+-----------------------+------------------------------------------------------------------------+------------------+-----------------------+-------------------+----------------+------------------+----------------+------------------------+---------------------+--------------------------+-----------------+
174| Host | User | Select_priv | Insert_priv | Update_priv | Delete_priv | Create_priv | Drop_priv | Reload_priv | Shutdown_priv | Process_priv | File_priv | Grant_priv | References_priv | Index_priv | Alter_priv | Show_db_priv | Super_priv | Create_tmp_table_priv | Lock_tables_priv | Execute_priv | Repl_slave_priv | Repl_client_priv | Create_view_priv | Show_view_priv | Create_routine_priv | Alter_routine_priv | Create_user_priv | Event_priv | Trigger_priv | Create_tablespace_priv | ssl_type | ssl_cipher | x509_issuer | x509_subject | max_questions | max_updates | max_connections | max_user_connections | plugin | authentication_string | password_expired | password_last_changed | password_lifetime | account_locked | Create_role_priv | Drop_role_priv | Password_reuse_history | Password_reuse_time | Password_require_current | User_attributes |
175+-----------+------------------+-------------+-------------+-------------+-------------+-------------+-----------+-------------+---------------+--------------+-----------+------------+-----------------+------------+------------+--------------+------------+-----------------------+------------------+--------------+-----------------+------------------+------------------+----------------+---------------------+--------------------+------------------+------------+--------------+------------------------+----------+------------+-------------+--------------+---------------+-------------+-----------------+----------------------+-----------------------+------------------------------------------------------------------------+------------------+-----------------------+-------------------+----------------+------------------+----------------+------------------------+---------------------+--------------------------+-----------------+
176| % | cmc | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | | | | | 0 | 0 | 0 | 0 | caching_sha2_password | | N | 2025-04-25 16:28:52 | NULL | N | N | N | NULL | NULL | NULL | NULL |
177| localhost | mysql.infoschema | Y | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | | | | | 0 | 0 | 0 | 0 | caching_sha2_password | $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED | N | 2025-04-25 15:51:53 | NULL | Y | N | N | NULL | NULL | NULL | NULL |
178| localhost | mysql.session | N | N | N | N | N | N | N | Y | N | N | N | N | N | N | N | Y | N | N | N | N | N | N | N | N | N | N | N | N | N | | | | | 0 | 0 | 0 | 0 | caching_sha2_password | $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED | N | 2025-04-25 15:51:53 | NULL | Y | N | N | NULL | NULL | NULL | NULL |
179| localhost | mysql.sys | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | | | | | 0 | 0 | 0 | 0 | caching_sha2_password | $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED | N | 2025-04-25 15:51:53 | NULL | Y | N | N | NULL | NULL | NULL | NULL |
180| localhost | root | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | | | | | 0 | 0 | 0 | 0 | caching_sha2_password | | N | 2025-04-25 15:51:53 | NULL | N | Y | Y | NULL | NULL | NULL | NULL |
181+-----------+------------------+-------------+-------------+-------------+-------------+-------------+-----------+-------------+---------------+--------------+-----------+------------+-----------------+------------+------------+--------------+------------+-----------------------+------------------+--------------+-----------------+------------------+------------------+----------------+---------------------+--------------------+------------------+------------+--------------+------------------------+----------+------------+-------------+--------------+---------------+-------------+-----------------+----------------------+-----------------------+------------------------------------------------------------------------+------------------+-----------------------+-------------------+----------------+------------------+----------------+------------------------+---------------------+--------------------------+-----------------+
1825 rows in set (0.005 sec)
183#+end_src
databases/oracle/README.org โ†’ databases/oracle/README.md renamed +10 โˆ’10
@@ -1,6 +1,6 @@
1* =oracle_admins.sql=
1# `oracle_admins.sql`
22
3#+begin_src sql
3``` sql
44SELECT
55 grantee AS "User",
66 privilege AS "Privilege"
@@ -16,9 +16,9 @@ FROM
1616 dba_tab_privs
1717WHERE
1818 grantee IN (SELECT DISTINCT grantee FROM dba_tab_privs);
19#+end_src
19```
2020
21#+begin_src text
21``` text
2222| User | Privilege |
2323|----------+---------------------|
2424| SCOTT | CREATE SESSION |
@@ -39,18 +39,18 @@ WHERE
3939| APP_USER | SELECT ON EMPLOYEES |
4040| APP_USER | INSERT ON EMPLOYEES |
4141| APP_USER | UPDATE ON EMPLOYEES |
42#+end_src
42```
4343
44* =oracle_admins_alt.sql=
44# `oracle_admins_alt.sql`
4545
46#+begin_src sql
46``` sql
4747SELECT ** FROM sys.dba_role_privs;
4848SELECT ** FROM sys.dba_sys_privs;
4949SELECT ** FROM sys.dba_tab_privs;
5050SELECT ** FROM sys.dba_users;
51#+end_src
51```
5252
53#+begin_src text
53``` text
5454| Grantee | Granted_Role | Admin_Option |
5555|----------+--------------+--------------|
5656| SCOTT | DBA | NO |
@@ -78,4 +78,4 @@ SELECT ** FROM sys.dba_users;
7878| SYS | OPEN | SYSTEM | TEMP |
7979| SYSTEM | OPEN | SYSTEM | TEMP |
8080| APP_USER | OPEN | USERS | TEMP |
81#+end_src
81```
databases/postgres/README.md added +67
@@ -0,0 +1,67 @@
1# `passwords.sql`
2
3``` sql
4SELECT *
5FROM pg_settings
6WHERE name LIKE 'password_%';
7```
8
9 | name | setting | unit | category | short_desc | extra_desc | context | vartype | source | min_val | max_val | enumvals | boot_val | reset_val | sourcefile | sourceline | pending_restart |
10 |---------------------+---------------+------+-------------------------------------------------+-------------------------------------------------+------------+---------+---------+---------+---------+---------+---------------------+---------------+---------------+------------+------------+-----------------|
11 | password_encryption | scram-sha-256 | | Connections and Authentication / Authentication | Chooses the algorithm for encrypting passwords. | | user | enum | default | | | {md5,scram-sha-256} | scram-sha-256 | scram-sha-256 | | | false |
12
13``` sql
14SELECT
15 usename AS user_name,
16 passwd AS password,
17 valuntil AS valid_until,
18 useconfig AS user_config
19FROM pg_shadow;
20```
21
22 | user_name | password | valid_until | user_config |
23 |-----------+---------------------------------------------------------------------------------------------------------------------------------------+------------------------+-------------|
24 | cmc | | | |
25 | testuser | SCRAM-SHA-256$4096:+NSpEU+8afhJ4BUTkzdKeg==$FGIRcTWr89b42qkLUl4Ntfp4RUpoc3GIpLHqJl/fWZE=:o1UM8YiEj5SLV5l/geMuqXMRi6onWazryn/l+LXYMxU= | 2025-12-31 00:00:00-06 | |
26
27# `admins.sql`
28
29``` sql
30SELECT
31 r.rolname AS role_name,
32 r.rolsuper AS is_superuser,
33 r.rolinherit AS inherits_privileges,
34 r.rolcreaterole AS can_create_roles,
35 r.rolcreatedb AS can_create_db,
36 r.rolcanlogin AS can_login,
37 r.rolreplication AS can_replication,
38 r.rolconnlimit AS connection_limit,
39 r.rolvaliduntil AS valid_until,
40 ARRAY(
41 SELECT b.rolname
42 FROM pg_auth_members m
43 JOIN pg_roles b ON (m.roleid = b.oid)
44 WHERE m.member = r.oid
45 ) AS member_of
46FROM pg_roles r;
47```
48
49 | role_name | is_superuser | inherits_privileges | can_create_roles | can_create_db | can_login | can_replication | connection_limit | valid_until | member_of |
50 |-----------------------------+--------------+---------------------+------------------+---------------+-----------+-----------------+------------------+------------------------+--------------------------------------------------------------|
51 | cmc | true | true | true | true | true | true | -1 | | {} |
52 | pg_database_owner | false | true | false | false | false | false | -1 | | {} |
53 | pg_read_all_data | false | true | false | false | false | false | -1 | | {} |
54 | pg_write_all_data | false | true | false | false | false | false | -1 | | {} |
55 | pg_monitor | false | true | false | false | false | false | -1 | | {pg_read_all_settings,pg_read_all_stats,pg_stat_scan_tables} |
56 | pg_read_all_settings | false | true | false | false | false | false | -1 | | {} |
57 | pg_read_all_stats | false | true | false | false | false | false | -1 | | {} |
58 | pg_stat_scan_tables | false | true | false | false | false | false | -1 | | {} |
59 | pg_read_server_files | false | true | false | false | false | false | -1 | | {} |
60 | pg_write_server_files | false | true | false | false | false | false | -1 | | {} |
61 | pg_execute_server_program | false | true | false | false | false | false | -1 | | {} |
62 | pg_signal_backend | false | true | false | false | false | false | -1 | | {} |
63 | pg_checkpoint | false | true | false | false | false | false | -1 | | {} |
64 | pg_maintain | false | true | false | false | false | false | -1 | | {} |
65 | pg_use_reserved_connections | false | true | false | false | false | false | -1 | | {} |
66 | pg_create_subscription | false | true | false | false | false | false | -1 | | {} |
67 | testuser | false | true | false | false | true | false | -1 | 2025-12-31 00:00:00-06 | {} |
databases/postgres/README.org deleted โˆ’75
@@ -1,75 +0,0 @@
1#+title: Postgres
2
3* =passwords.sql=
4
5#+begin_src sql
6SELECT *
7FROM pg_settings
8WHERE name LIKE 'password_%';
9#+end_src
10
11#+begin_src
12| name | setting | unit | category | short_desc | extra_desc | context | vartype | source | min_val | max_val | enumvals | boot_val | reset_val | sourcefile | sourceline | pending_restart |
13|---------------------+---------------+------+-------------------------------------------------+-------------------------------------------------+------------+---------+---------+---------+---------+---------+---------------------+---------------+---------------+------------+------------+-----------------|
14| password_encryption | scram-sha-256 | | Connections and Authentication / Authentication | Chooses the algorithm for encrypting passwords. | | user | enum | default | | | {md5,scram-sha-256} | scram-sha-256 | scram-sha-256 | | | false |
15#+end_src
16
17#+begin_src sql
18SELECT
19 usename AS user_name,
20 passwd AS password,
21 valuntil AS valid_until,
22 useconfig AS user_config
23FROM pg_shadow;
24#+end_src
25
26#+begin_src
27| user_name | password | valid_until | user_config |
28|-----------+---------------------------------------------------------------------------------------------------------------------------------------+------------------------+-------------|
29| cmc | | | |
30| testuser | SCRAM-SHA-256$4096:+NSpEU+8afhJ4BUTkzdKeg==$FGIRcTWr89b42qkLUl4Ntfp4RUpoc3GIpLHqJl/fWZE=:o1UM8YiEj5SLV5l/geMuqXMRi6onWazryn/l+LXYMxU= | 2025-12-31 00:00:00-06 | |
31#+end_src
32
33* =admins.sql=
34
35#+begin_src sql
36SELECT
37 r.rolname AS role_name,
38 r.rolsuper AS is_superuser,
39 r.rolinherit AS inherits_privileges,
40 r.rolcreaterole AS can_create_roles,
41 r.rolcreatedb AS can_create_db,
42 r.rolcanlogin AS can_login,
43 r.rolreplication AS can_replication,
44 r.rolconnlimit AS connection_limit,
45 r.rolvaliduntil AS valid_until,
46 ARRAY(
47 SELECT b.rolname
48 FROM pg_auth_members m
49 JOIN pg_roles b ON (m.roleid = b.oid)
50 WHERE m.member = r.oid
51 ) AS member_of
52FROM pg_roles r;
53#+end_src
54
55#+begin_src
56| role_name | is_superuser | inherits_privileges | can_create_roles | can_create_db | can_login | can_replication | connection_limit | valid_until | member_of |
57|-----------------------------+--------------+---------------------+------------------+---------------+-----------+-----------------+------------------+------------------------+--------------------------------------------------------------|
58| cmc | true | true | true | true | true | true | -1 | | {} |
59| pg_database_owner | false | true | false | false | false | false | -1 | | {} |
60| pg_read_all_data | false | true | false | false | false | false | -1 | | {} |
61| pg_write_all_data | false | true | false | false | false | false | -1 | | {} |
62| pg_monitor | false | true | false | false | false | false | -1 | | {pg_read_all_settings,pg_read_all_stats,pg_stat_scan_tables} |
63| pg_read_all_settings | false | true | false | false | false | false | -1 | | {} |
64| pg_read_all_stats | false | true | false | false | false | false | -1 | | {} |
65| pg_stat_scan_tables | false | true | false | false | false | false | -1 | | {} |
66| pg_read_server_files | false | true | false | false | false | false | -1 | | {} |
67| pg_write_server_files | false | true | false | false | false | false | -1 | | {} |
68| pg_execute_server_program | false | true | false | false | false | false | -1 | | {} |
69| pg_signal_backend | false | true | false | false | false | false | -1 | | {} |
70| pg_checkpoint | false | true | false | false | false | false | -1 | | {} |
71| pg_maintain | false | true | false | false | false | false | -1 | | {} |
72| pg_use_reserved_connections | false | true | false | false | false | false | -1 | | {} |
73| pg_create_subscription | false | true | false | false | false | false | -1 | | {} |
74| testuser | false | true | false | false | true | false | -1 | 2025-12-31 00:00:00-06 | {} |
75#+end_src
databases/sql/README.org โ†’ databases/sql/README.md renamed +10 โˆ’10
@@ -1,10 +1,10 @@
1* =admins.sql=
1# `admins.sql`
22
3#+begin_src sql
3``` sql
44:r admins.sql
5#+end_src
5```
66
7#+begin_src text
7``` text
88| UserName | UserType | DatabaseUserName | Role | PermissionType | PermissionState | ObjectType | ObjectName | ColumnName |
99|-------------+--------------+------------------+-----------------+----------------+-----------------+----------------------+--------------------+------------|
1010| SCOTT | SQL User | SCOTT | NULL | SELECT | GRANT | USER_TABLE | EMPLOYEES | NULL |
@@ -14,15 +14,15 @@
1414| APP_USER | Windows User | APP_USER | ApplicationRole | INSERT | GRANT | USER_TABLE | EMPLOYEES | NULL |
1515| {All Users} | {All Users} | {All Users} | public | SELECT | GRANT | USER_TABLE | EMPLOYEES | NULL |
1616| {All Users} | {All Users} | {All Users} | public | EXECUTE | GRANT | SQL_STORED_PROCEDURE | SP_GET_EMPLOYEE | NULL |
17#+end_src
17```
1818
19* =passwords.py=
19# `passwords.py`
2020
21#+begin_src shell
21``` shell
2222python passwords.py
23#+end_src
23```
2424
25#+begin_src text
25``` text
2626| Name | Type | Check Policy | Check Expiration | Reason |
2727|-------+-----------+--------------+------------------+-----------------------------------------------------------------------------------------------------------------------------------------------|
2828| user1 | SQL_LOGIN | PASS | FAIL | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is not enforced. |
@@ -33,4 +33,4 @@ python passwords.py
3333| user6 | SQL_LOGIN | PASS | PASS | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is enforced. Reviewer to check the expiration policy. |
3434| user7 | SQL_LOGIN | PASS | PASS | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is enforced. Reviewer to check the expiration policy. |
3535| user8 | SQL_LOGIN | PASS | PASS | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is enforced. Reviewer to check the expiration policy. |
36#+end_src
36```
os/linux/README.md added +56
@@ -0,0 +1,56 @@
1# `report/linux.sh`
2
3``` shell
4./report/linux.sh
5```
6
7 _ ___ _ _ _ ___ __ ___ ____ ____ _____ ____ ___ ____ _____
8 | | |_ _| \ | | | | \ \/ / / _ \/ ___| | _ \| ____| _ \ / _ \| _ \_ _|
9 | | | || \| | | | |\ / | | | \___ \ | |_) | _| | |_) | | | | |_) || |
10 | |___ | || |\ | |_| |/ \ | |_| |___) | | _ <| |___| __/| |_| | _ < | |
11 |_____|___|_| \_|\___//_/\_\ \___/|____/ |_| \_\_____|_| \___/|_| \_\|_|
12
13
14
15 ==========================================
16 # SECTION 00: Script Info
17 ==========================================
18 Execution Date and Time: Wed May 7 11:35:52 AM CDT 2025
19 Script Name: ./linux.sh
20 User Running the Script: root (called by: cmc)
21
22
23
24 ==========================================
25 # SECTION 01: System Info
26 ==========================================
27 ## Hostname
28 hera
29 ## Kernel Version
30 6.14.4-400.asahi.fc42.aarch64+16k
31 ## os-release
32 NAME="Fedora Linux Asahi Remix"
33 VERSION="42 (Forty Two [Adams])"
34 RELEASE_TYPE=stable
35 ID=fedora-asahi-remix
36 ID_LIKE=fedora
37
38# `ssh_root_login.sh`
39
40``` shell
41./ssh_root_login.sh
42```
43
44 PermitRootLogin no
45
46# `passwords.sh`
47
48``` shell
49./passwords.sh
50```
51
52 Starting analysis of authentication and login parameters...
53 Checking /etc/pam.d/system-auth for password parameters...
54 /etc/pam.d/system-auth file not found.
55 Analyzing /etc/login.defs...
56 Contents of /etc/login.defs:
os/linux/README.org deleted โˆ’64
@@ -1,64 +0,0 @@
1#+title: Linux
2
3* =report/linux.sh=
4
5#+begin_src shell
6./report/linux.sh
7#+end_src
8
9#+begin_src
10_ ___ _ _ _ ___ __ ___ ____ ____ _____ ____ ___ ____ _____
11| | |_ _| \ | | | | \ \/ / / _ \/ ___| | _ \| ____| _ \ / _ \| _ \_ _|
12| | | || \| | | | |\ / | | | \___ \ | |_) | _| | |_) | | | | |_) || |
13| |___ | || |\ | |_| |/ \ | |_| |___) | | _ <| |___| __/| |_| | _ < | |
14|_____|___|_| \_|\___//_/\_\ \___/|____/ |_| \_\_____|_| \___/|_| \_\|_|
15
16
17
18==========================================
19# SECTION 00: Script Info
20==========================================
21Execution Date and Time: Wed May 7 11:35:52 AM CDT 2025
22Script Name: ./linux.sh
23User Running the Script: root (called by: cmc)
24
25
26
27==========================================
28# SECTION 01: System Info
29==========================================
30## Hostname
31hera
32## Kernel Version
336.14.4-400.asahi.fc42.aarch64+16k
34## os-release
35NAME="Fedora Linux Asahi Remix"
36VERSION="42 (Forty Two [Adams])"
37RELEASE_TYPE=stable
38ID=fedora-asahi-remix
39ID_LIKE=fedora
40#+end_src
41
42* =ssh_root_login.sh=
43
44#+begin_src shell
45./ssh_root_login.sh
46#+end_src
47
48#+begin_src
49PermitRootLogin no
50#+end_src
51
52* =passwords.sh=
53
54#+begin_src shell
55./passwords.sh
56#+end_src
57
58#+begin_src
59Starting analysis of authentication and login parameters...
60Checking /etc/pam.d/system-auth for password parameters...
61/etc/pam.d/system-auth file not found.
62Analyzing /etc/login.defs...
63Contents of /etc/login.defs:
64#+end_src
sampling/README.org โ†’ sampling/README.md renamed +13 โˆ’14
@@ -1,12 +1,10 @@
1#+title: Sampling Tools
1# `sample.py`
22
3* =sample.py=
4
5#+begin_src sh
3``` bash
64python ./sample.py
7#+end_src
5```
86
9#+begin_src text
7``` text
108Dataframe size (rows, columns): (100, 9)
119Sample size: 5
1210Sample:
@@ -18,15 +16,16 @@ Sample:
181670 71 32BB9Ff4d939788 ... Wireless 6146
1917
2018[5 rows x 9 columns]
21#+end_src
19```
2220
23* =sample.html=
21# `sample.html`
2422
25This is an interactive web page that allows users to submit their population
26size, sample size(s), and generate a psuedo-random sample list of numbers to use
27when sampling against their population.
23This is an interactive web page that allows users to submit their
24population size, sample size(s), and generate a psuedo-random sample
25list of numbers to use when sampling against their population.
2826
29Samples can be re-generated and validated using the seed numbers provided during
30the original generation.
27Samples can be re-generated and validated using the seed numbers
28provided during the original generation.
3129
32[[sample-html.png]]
30<span class="spurious-link"
31target="sample-html.png">*sample-html.png*</span>