audit-labs/audit-tools

A collection of scripts, queries, and other goodies you can use in an audit. audit automation compliance evidence scripts

Commit 5caad24f4f

5caad24f4ff5ea2b7adad19aefd89a12030c38b0

parent: d9a14ddd14

Unsigned

cmc <hello@cleberg.net> ยท 2025-08-02 18:02 UTC

fix: convert README.org to README.md

Layout: unified ยท split

README.md added +112
@@ -0,0 +1,112 @@
1# ๐Ÿ“Š Audit Tools by Christian Cleberg
2
3Welcome to **Audit Tools** โ€” a collection of open-source Python scripts
4and resources designed to help auditors, risk professionals, and data
5analysts automate common audit tasks and analytics.
6
7Whether you're new to audit automation or an experienced tech-enabled
8auditor, this toolkit offers practical, real-world examples you can use,
9customize, and build upon.
10
11# ๐Ÿ“ฆ What's Inside
12
13This repository contains Python scripts and templates for common audit
14procedures and control testing activities, including:
15
16- โœ… **Pseudo-Random Sampling**
17- โœ… **GITC Extractions and Analysis**
18- โœ… **Project Management Tracking & Visualizations**
19- โœ… **Cloud Platform Analysis (planned)**
20- โœ… **Audit AI Prompts & Guides (planned)**
21
22The goal is to provide practical, easy-to-understand tools that auditors
23and analysts can quickly deploy in their environments.
24
25# ๐Ÿš€ Getting Started
26
27****Clone the Repository****
28
29``` bash
30git clone https://git.sr.ht/~cxc/audit-tools
31cd audit-tools
32```
33
34****Install Dependencies****
35
36*Required for Python scripts*
37
38``` bash
39pip install -r requirements.txt
40```
41
42****Run a Sample Script****
43
44Example: Run the **Linux OS Report** tool.
45
46``` bash
47./os/linux/report/linux.sh
48```
49
50View the results in your terminal or within the file created by the
51script.
52
53# ๐Ÿ“– Learn More
54
55If you're new to audit analytics or Python scripting, start here:
56
57- [Python for Auditors](https://realpython.com)
58- [Audit Analytics 101](https://audit-analytics.com)
59- [Intro to Pandas
60 Documentation](https://pandas.pydata.org/docs/getting_started/)
61
62Also, check out the `notebooks/` folder for interactive tutorials and
63use cases.
64
65# ๐Ÿค How to Contribute
66
67Want to add your own audit scripts or improve existing ones?
68Contributions are welcome!
69
70****Ways to Help****
71
72- Submit new Python scripts for audit use cases.
73- Suggest enhancements or new features.
74- Improve documentation or write beginner-friendly tutorials.
75- Test existing tools on new datasets and report issues.
76
77****To Contribute****
78
791. Fork this repo
80
812. Create a new branch:
82
83 ``` bash
84 git checkout -b my-feature
85 ```
86
873. Commit your changes:
88
89 ``` bash
90 git commit -m 'Added new audit test'
91 ```
92
934. Push to the branch:
94
95 ``` bash
96 git push origin my-feature
97 ```
98
995. Open a Pull Request
100
101# ๐Ÿ‘ค About the Creator
102
103Made with โค๏ธ by [Christian Cleberg](https://cleberg.net/).
104
105I'm a technology assurance leader passionate about audit innovation, AI
106in audit, and building practical tools for auditors and risk
107professionals.
108
109# ๐Ÿ“œ License
110
111This project is licensed under the **GNU General Public License v3.0** โ€”
112see the [LICENSE](LICENSE) file for details.
README.org deleted โˆ’102
@@ -1,102 +0,0 @@
1#+TITLE: Audit Tools by Christian Cleberg
2#+AUTHOR: Christian Cleberg
3#+OPTIONS: toc:nil
4
5* ๐Ÿ“Š Audit Tools by Christian Cleberg
6
7Welcome to *Audit Tools* โ€” a collection of open-source Python scripts and
8resources designed to help auditors, risk professionals, and data analysts
9automate common audit tasks and analytics.
10
11Whether you're new to audit automation or an experienced tech-enabled auditor,
12this toolkit offers practical, real-world examples you can use, customize, and
13build upon.
14
15* ๐Ÿ“ฆ What's Inside
16
17This repository contains Python scripts and templates for common audit
18procedures and control testing activities, including:
19
20- โœ… *Pseudo-Random Sampling*
21- โœ… *GITC Extractions and Analysis*
22- โœ… *Project Management Tracking & Visualizations*
23- โœ… *Cloud Platform Analysis (planned)*
24- โœ… *Audit AI Prompts & Guides (planned)*
25
26The goal is to provide practical, easy-to-understand tools that auditors and
27analysts can quickly deploy in their environments.
28
29* ๐Ÿš€ Getting Started
30
31**Clone the Repository**
32
33#+begin_src bash
34git clone https://git.sr.ht/~cxc/audit-tools
35cd audit-tools
36#+end_src
37
38**Install Dependencies**
39
40/Required for Python scripts/
41
42#+begin_src bash
43pip install -r requirements.txt
44#+end_src
45
46**Run a Sample Script**
47
48Example: Run the *Linux OS Report* tool.
49
50#+begin_src bash
51./os/linux/report/linux.sh
52#+end_src
53
54View the results in your terminal or within the file created by the script.
55
56* ๐Ÿ“– Learn More
57
58If you're new to audit analytics or Python scripting, start here:
59- [[https://realpython.com][Python for Auditors]]
60- [[https://audit-analytics.com][Audit Analytics 101]]
61- [[https://pandas.pydata.org/docs/getting_started/][Intro to Pandas Documentation]]
62
63Also, check out the =notebooks/= folder for interactive tutorials and use cases.
64
65* ๐Ÿค How to Contribute
66
67Want to add your own audit scripts or improve existing ones? Contributions are
68welcome!
69
70**Ways to Help**
71- Submit new Python scripts for audit use cases.
72- Suggest enhancements or new features.
73- Improve documentation or write beginner-friendly tutorials.
74- Test existing tools on new datasets and report issues.
75
76**To Contribute**
771. Fork this repo
782. Create a new branch:
79 #+begin_src bash
80 git checkout -b my-feature
81 #+end_src
823. Commit your changes:
83 #+begin_src bash
84 git commit -m 'Added new audit test'
85 #+end_src
864. Push to the branch:
87 #+begin_src bash
88 git push origin my-feature
89 #+end_src
905. Open a Pull Request
91
92* ๐Ÿ‘ค About the Creator
93
94Made with โค๏ธ by [[https://cleberg.net/][Christian Cleberg]].
95
96I'm a technology assurance leader passionate about audit innovation, AI in
97audit, and building practical tools for auditors and risk professionals.
98
99* ๐Ÿ“œ License
100
101This project is licensed under the *GNU General Public License v3.0* โ€” see the
102[[file:LICENSE][LICENSE]] file for details.
applications/github/README.org โ†’ applications/github/README.md renamed +33 โˆ’32
@@ -1,23 +1,25 @@
1#+title: GitHub Scripts 1**NOTE**: I used the same
2 2[PAT](https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens)
3*NOTE*: I used the same [[https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens][PAT]] for all scripts within this folder. Note that you can likely reduce permissions for certain scripts - it's best practice to define a PAT for a specific purpose and avoid using a single PAT with broad permissions. 3for all scripts within this folder. Note that you can likely reduce
4permissions for certain scripts - it's best practice to define a PAT for
5a specific purpose and avoid using a single PAT with broad permissions.
4 6
5- Personal Access Token: 7- Personal Access Token:
6 - [x] Repository Permissions 8 - \[x\] Repository Permissions
7 - [x] Actions: read-only 9 - \[x\] Actions: read-only
8 - [x] Contents: read-only 10 - \[x\] Contents: read-only
9 - [x] Metadata: read-only 11 - \[x\] Metadata: read-only
10 - [x] Workflows: read-only 12 - \[x\] Workflows: read-only
11 - [x] Organization Permissions 13 - \[x\] Organization Permissions
12 - [x] Administration: read-only 14 - \[x\] Administration: read-only
13 15
14* =github_admins.py= 16# `github_admins.py`
15 17
16#+begin_src sh 18``` bash
17python ./github_admins.py 19python ./github_admins.py
18#+end_src 20```
19 21
20#+begin_src text 22``` text
21Members of the organization 'your_organization': 23Members of the organization 'your_organization':
22 24
23Repositories in the organization 'your_organization': 25Repositories in the organization 'your_organization':
@@ -25,28 +27,27 @@ Repositories in the organization 'your_organization':
25 27
26Collaborators for the repository 'demo-repository': 28Collaborators for the repository 'demo-repository':
27- user1: admin 29- user1: admin
28#+end_src 30```
29 31
30* =github_audit_log.py= 32# `github_audit_log.py`
31 33
32*NOTE*: Requires an active GitHub Enterprise subscription. 34**NOTE**: Requires an active GitHub Enterprise subscription.
33 35
34#+begin_src sh 36``` bash
35python ./github_audit_log.py 37python ./github_audit_log.py
36#+end_src 38```
37 39
38#+begin_src text 40``` text
39TODO: Need to get an Enterprise subscription to test this script. 41TODO: Need to get an Enterprise subscription to test this script.
40#+end_src 42```
41
42* =github_branch_protections.py=
43 43
44# `github_branch_protections.py`
44 45
45#+begin_src sh 46``` bash
46python ./github_branch_protections.py 47python ./github_branch_protections.py
47#+end_src 48```
48 49
49#+begin_src text 50``` text
50Total branches in the repository 'demo-repository': 1 51Total branches in the repository 'demo-repository': 1
51 52
52Branch: main 53Branch: main
@@ -54,15 +55,15 @@ No protection settings
54 55
55Repository rulesets for 'demo-repository': 56Repository rulesets for 'demo-repository':
56[{'id': 2311373, 'name': 'default', 'target': 'branch', 'source_type': 'Repository', 'source': 'phryq/demo-repository', 'enforcement': 'active', 'node_id': 'RRS_lACqUmVwb3NpdG9yec40LV1PzgAjRM0', '_links': {'self': {'href': 'https://api.github.com/repos/phryq/demo-repository/rulesets/2311373'}, 'html': {'href': 'https://github.com/phryq/demo-repository/rules/2311373'}}, 'created_at': '2024-10-19T15:59:35.200-05:00', 'updated_at': '2024-10-19T15:59:35.200-05:00'}] 57[{'id': 2311373, 'name': 'default', 'target': 'branch', 'source_type': 'Repository', 'source': 'phryq/demo-repository', 'enforcement': 'active', 'node_id': 'RRS_lACqUmVwb3NpdG9yec40LV1PzgAjRM0', '_links': {'self': {'href': 'https://api.github.com/repos/phryq/demo-repository/rulesets/2311373'}, 'html': {'href': 'https://github.com/phryq/demo-repository/rules/2311373'}}, 'created_at': '2024-10-19T15:59:35.200-05:00', 'updated_at': '2024-10-19T15:59:35.200-05:00'}]
57#+end_src 58```
58 59
59* =github_commits.py= 60# `github_commits.py`
60 61
61#+begin_src sh 62``` bash
62python ./github_commits.py 63python ./github_commits.py
63#+end_src 64```
64 65
65#+begin_src text 66``` text
66Total commits in the repository 'demo-repository' on branch 'main': 3 67Total commits in the repository 'demo-repository' on branch 'main': 3
67 68
68Commit SHA: 13c488a2cdda08e4043f8ef36ced5fdd429e9718 69Commit SHA: 13c488a2cdda08e4043f8ef36ced5fdd429e9718
@@ -109,4 +110,4 @@ Files changed:
109 Additions: 1, Deletions: 0, Changes: 1 110 Additions: 1, Deletions: 0, Changes: 1
110 - package.json (added) 111 - package.json (added)
111 Additions: 9, Deletions: 0, Changes: 9 112 Additions: 9, Deletions: 0, Changes: 9
112#+end_src 113```
applications/gitlab/README.org โ†’ applications/gitlab/README.md renamed +39 โˆ’40
@@ -1,14 +1,12 @@
1#+title: GitLab Scripts 1# `approvals.py`
2 2
3* =approvals.py= 3\\This script requires an active Premium or Ultimate subscription.\*\\
4 4
5\*This script requires an active Premium or Ultimate subscription.*\ 5``` bash
6
7#+begin_src sh
8python ./approvals.py 6python ./approvals.py
9#+end_src 7```
10 8
11#+begin_src text 9``` text
12Rule: All Members 10Rule: All Members
13 Approvals Required: 1 11 Approvals Required: 1
14 Rule type: any_approver 12 Rule type: any_approver
@@ -17,15 +15,15 @@ Rule: Default
17 Rule type: regular 15 Rule type: regular
18 Protected Branch: master 16 Protected Branch: master
19 Eligible Approver: Christian Cleberg 17 Eligible Approver: Christian Cleberg
20#+end_src 18```
21 19
22* =branch_protections.py= 20# `branch_protections.py`
23 21
24#+begin_src sh 22``` bash
25python ./branch_protections.py 23python ./branch_protections.py
26#+end_src 24```
27 25
28#+begin_src json 26``` json
29[ 27[
30 { 28 {
31 "id": 148448212, 29 "id": 148448212,
@@ -55,27 +53,28 @@ python ./branch_protections.py
55 "inherited": false 53 "inherited": false
56 } 54 }
57] 55]
58#+end_src 56```
59 57
60* =passwords.py= 58# `passwords.py`
61 59
62*This script does not apply to GitLab.com. This is for self-hosted instances only.* 60**This script does not apply to GitLab.com. This is for self-hosted
61instances only.**
63 62
64#+begin_src sh 63``` bash
65python ./passwords.py 64python ./passwords.py
66#+end_src 65```
67 66
68#+begin_src text 67``` text
69# TODO: Need access to a self-hosted version of GitLab to test this out. 68# TODO: Need access to a self-hosted version of GitLab to test this out.
70#+end_src 69```
71 70
72* =pipelines.py= 71# `pipelines.py`
73 72
74#+begin_src sh 73``` bash
75python ./pipelines.py 74python ./pipelines.py
76#+end_src 75```
77 76
78#+begin_src text 77``` text
79Pipeline ID: 1754222228 78Pipeline ID: 1754222228
80 Status: failed 79 Status: failed
81 Ref: master 80 Ref: master
@@ -100,28 +99,28 @@ Pipeline ID: 1754214637
100 Created At: 2025-04-06T03:21:39.902Z 99 Created At: 2025-04-06T03:21:39.902Z
101 Duration: N/A seconds 100 Duration: N/A seconds
102 Configuration: N/A 101 Configuration: N/A
103#+end_src 102```
104 103
105* =provisioning.py= 104# `provisioning.py`
106 105
107\*This script requires an active Premium or Ultimate subscription.*\ 106\\This script requires an active Premium or Ultimate subscription.\*\\
108 107
109#+begin_src sh 108``` bash
110python ./provisioning.py 109python ./provisioning.py
111#+end_src 110```
112 111
113#+begin_src text 112``` text
114Group: 105300140 113Group: 105300140
115 2025-04-08T03:33:17.055Z : Action: member_created, Member: 128029250, Author: 24608590 114 2025-04-08T03:33:17.055Z : Action: member_created, Member: 128029250, Author: 24608590
116#+end_src 115```
117 116
118* =repositories.py= 117# `repositories.py`
119 118
120#+begin_src shell 119``` shell
121python ./repositories.py 120python ./repositories.py
122#+end_src 121```
123 122
124#+begin_src text 123``` text
125# User ID Example 124# User ID Example
126Projects under ID: ccleberg: 125Projects under ID: ccleberg:
127- audit-tools (ID: 68757698) 126- audit-tools (ID: 68757698)
@@ -131,15 +130,15 @@ Projects under ID: ccleberg:
131Projects under ID: phryq: 130Projects under ID: phryq:
132- Yoshi Cli (ID: 68757750) 131- Yoshi Cli (ID: 68757750)
133- pages-demo (ID: 68757186) 132- pages-demo (ID: 68757186)
134#+end_src 133```
135 134
136* =users.py= 135# `users.py`
137 136
138#+begin_src sh 137``` bash
139python ./users.py 138python ./users.py
140#+end_src 139```
141 140
142#+begin_src text 141``` text
143Access Level Roles: 142Access Level Roles:
144 0 : No access 143 0 : No access
145 5 : Minimal access 144 5 : Minimal access
@@ -158,4 +157,4 @@ Username: ccleberg, Access Level: 50
158Project 68701468 Members: 157Project 68701468 Members:
159Username: ccleberg, Access Level: 50 158Username: ccleberg, Access Level: 50
160Username: project_68701468_bot_2c7ee010a479c0e48cdb4c7c5cfae886, Access Level: 40 159Username: project_68701468_bot_2c7ee010a479c0e48cdb4c7c5cfae886, Access Level: 40
161#+end_src 160```
databases/mongo/README.org โ†’ databases/mongo/README.md renamed +102 โˆ’104
@@ -1,104 +1,102 @@
1#+title: MongoDB Scripts 1# `admins.py`
2 2
3* =admins.py= 3Dependency:
4 4
5Dependency: 5``` shell
6 6pip install pymongo
7#+begin_src shell 7```
8pip install pymongo 8
9#+end_src 9``` python
10 10python ./admins.py
11#+begin_src python 11```
12python ./admins.py 12
13#+end_src 13Example output:
14 14
15Example output: 15``` json
16 16[
17#+begin_src json 17 {
18[ 18 "_id": "admin.admin",
19 { 19 "user": "admin",
20 "_id": "admin.admin", 20 "db": "admin",
21 "user": "admin", 21 "roles": [
22 "db": "admin", 22 {
23 "roles": [ 23 "role": "userAdminAnyDatabase",
24 { 24 "db": "admin"
25 "role": "userAdminAnyDatabase", 25 },
26 "db": "admin" 26 {
27 }, 27 "role": "readWriteAnyDatabase",
28 { 28 "db": "admin"
29 "role": "readWriteAnyDatabase", 29 },
30 "db": "admin" 30 {
31 }, 31 "role": "dbAdminAnyDatabase",
32 { 32 "db": "admin"
33 "role": "dbAdminAnyDatabase", 33 },
34 "db": "admin" 34 {
35 }, 35 "role": "clusterAdmin",
36 { 36 "db": "admin"
37 "role": "clusterAdmin", 37 }
38 "db": "admin" 38 ],
39 } 39 "credentials": {
40 ], 40 "SCRAM-SHA-1": {
41 "credentials": { 41 "iterationCount": 10000,
42 "SCRAM-SHA-1": { 42 "salt": "abc123",
43 "iterationCount": 10000, 43 "storedKey": "storedKeyHash",
44 "salt": "abc123", 44 "serverKey": "serverKeyHash"
45 "storedKey": "storedKeyHash", 45 },
46 "serverKey": "serverKeyHash" 46 "SCRAM-SHA-256": {
47 }, 47 "iterationCount": 15000,
48 "SCRAM-SHA-256": { 48 "salt": "def456",
49 "iterationCount": 15000, 49 "storedKey": "storedKeyHash256",
50 "salt": "def456", 50 "serverKey": "serverKeyHash256"
51 "storedKey": "storedKeyHash256", 51 }
52 "serverKey": "serverKeyHash256" 52 }
53 } 53 },
54 } 54 {
55 }, 55 "_id": "test.user1",
56 { 56 "user": "user1",
57 "_id": "test.user1", 57 "db": "test",
58 "user": "user1", 58 "roles": [
59 "db": "test", 59 {
60 "roles": [ 60 "role": "readWrite",
61 { 61 "db": "test"
62 "role": "readWrite", 62 }
63 "db": "test" 63 ],
64 } 64 "credentials": {
65 ], 65 "SCRAM-SHA-1": {
66 "credentials": { 66 "iterationCount": 10000,
67 "SCRAM-SHA-1": { 67 "salt": "ghi789",
68 "iterationCount": 10000, 68 "storedKey": "storedKeyHashUser1",
69 "salt": "ghi789", 69 "serverKey": "serverKeyHashUser1"
70 "storedKey": "storedKeyHashUser1", 70 }
71 "serverKey": "serverKeyHashUser1" 71 }
72 } 72 },
73 } 73 {
74 }, 74 "_id": "test.ldapUser",
75 { 75 "user": "ldapUser",
76 "_id": "test.ldapUser", 76 "db": "test",
77 "user": "ldapUser", 77 "roles": [
78 "db": "test", 78 {
79 "roles": [ 79 "role": "read",
80 { 80 "db": "test"
81 "role": "read", 81 }
82 "db": "test" 82 ],
83 } 83 "userSource": "ldap"
84 ], 84 },
85 "userSource": "ldap" 85 {
86 }, 86 "_id": "admin.x509User",
87 { 87 "user": "x509User",
88 "_id": "admin.x509User", 88 "db": "$external",
89 "user": "x509User", 89 "roles": [
90 "db": "$external", 90 {
91 "roles": [ 91 "role": "readWrite",
92 { 92 "db": "admin"
93 "role": "readWrite", 93 }
94 "db": "admin" 94 ],
95 } 95 "credentials": {
96 ], 96 "MONGODB-X509": {
97 "credentials": { 97 "subject": "CN=x509User,OU=OrgUnit,O=Org,L=City,ST=State,C=Country"
98 "MONGODB-X509": { 98 }
99 "subject": "CN=x509User,OU=OrgUnit,O=Org,L=City,ST=State,C=Country" 99 }
100 } 100 }
101 } 101]
102 } 102```
103]
104#+end_src
databases/mysql/README.md added +173
@@ -0,0 +1,173 @@
1# `mysql_admins.sql`
2
3``` sql
4SELECT * FROM information_schema.user_privileges;
5```
6
7 MySQL [(none)]> SELECT * FROM information_schema.user_privileges;
8 +--------------------------------+---------------+---------------------------------+--------------+
9 | GRANTEE | TABLE_CATALOG | PRIVILEGE_TYPE | IS_GRANTABLE |
10 +--------------------------------+---------------+---------------------------------+--------------+
11 | 'mysql.infoschema'@'localhost' | def | SELECT | NO |
12 | 'mysql.infoschema'@'localhost' | def | AUDIT_ABORT_EXEMPT | NO |
13 | 'mysql.infoschema'@'localhost' | def | FIREWALL_EXEMPT | NO |
14 | 'mysql.infoschema'@'localhost' | def | SYSTEM_USER | NO |
15 | 'mysql.session'@'localhost' | def | SHUTDOWN | NO |
16 | 'mysql.session'@'localhost' | def | SUPER | NO |
17 | 'mysql.session'@'localhost' | def | AUDIT_ABORT_EXEMPT | NO |
18 | 'mysql.session'@'localhost' | def | AUTHENTICATION_POLICY_ADMIN | NO |
19 | 'mysql.session'@'localhost' | def | BACKUP_ADMIN | NO |
20 | 'mysql.session'@'localhost' | def | CLONE_ADMIN | NO |
21 | 'mysql.session'@'localhost' | def | CONNECTION_ADMIN | NO |
22 | 'mysql.session'@'localhost' | def | FIREWALL_EXEMPT | NO |
23 | 'mysql.session'@'localhost' | def | PERSIST_RO_VARIABLES_ADMIN | NO |
24 | 'mysql.session'@'localhost' | def | SESSION_VARIABLES_ADMIN | NO |
25 | 'mysql.session'@'localhost' | def | SYSTEM_USER | NO |
26 | 'mysql.session'@'localhost' | def | SYSTEM_VARIABLES_ADMIN | NO |
27 | 'mysql.sys'@'localhost' | def | USAGE | NO |
28 | 'mysql.sys'@'localhost' | def | AUDIT_ABORT_EXEMPT | NO |
29 | 'mysql.sys'@'localhost' | def | FIREWALL_EXEMPT | NO |
30 | 'mysql.sys'@'localhost' | def | SYSTEM_USER | NO |
31 | 'root'@'localhost' | def | SELECT | YES |
32 | 'root'@'localhost' | def | INSERT | YES |
33 | 'root'@'localhost' | def | UPDATE | YES |
34 | 'root'@'localhost' | def | DELETE | YES |
35 | 'root'@'localhost' | def | CREATE | YES |
36 | 'root'@'localhost' | def | DROP | YES |
37 | 'root'@'localhost' | def | RELOAD | YES |
38 | 'root'@'localhost' | def | SHUTDOWN | YES |
39 | 'root'@'localhost' | def | PROCESS | YES |
40 | 'root'@'localhost' | def | FILE | YES |
41 | 'root'@'localhost' | def | REFERENCES | YES |
42 | 'root'@'localhost' | def | INDEX | YES |
43 | 'root'@'localhost' | def | ALTER | YES |
44 | 'root'@'localhost' | def | SHOW DATABASES | YES |
45 | 'root'@'localhost' | def | SUPER | YES |
46 | 'root'@'localhost' | def | CREATE TEMPORARY TABLES | YES |
47 | 'root'@'localhost' | def | LOCK TABLES | YES |
48 | 'root'@'localhost' | def | EXECUTE | YES |
49 | 'root'@'localhost' | def | REPLICATION SLAVE | YES |
50 | 'root'@'localhost' | def | REPLICATION CLIENT | YES |
51 | 'root'@'localhost' | def | CREATE VIEW | YES |
52 | 'root'@'localhost' | def | SHOW VIEW | YES |
53 | 'root'@'localhost' | def | CREATE ROUTINE | YES |
54 | 'root'@'localhost' | def | ALTER ROUTINE | YES |
55 | 'root'@'localhost' | def | CREATE USER | YES |
56 | 'root'@'localhost' | def | EVENT | YES |
57 | 'root'@'localhost' | def | TRIGGER | YES |
58 | 'root'@'localhost' | def | CREATE TABLESPACE | YES |
59 | 'root'@'localhost' | def | CREATE ROLE | YES |
60 | 'root'@'localhost' | def | DROP ROLE | YES |
61 | 'root'@'localhost' | def | ALLOW_NONEXISTENT_DEFINER | YES |
62 | 'root'@'localhost' | def | APPLICATION_PASSWORD_ADMIN | YES |
63 | 'root'@'localhost' | def | AUDIT_ABORT_EXEMPT | YES |
64 | 'root'@'localhost' | def | AUDIT_ADMIN | YES |
65 | 'root'@'localhost' | def | AUTHENTICATION_POLICY_ADMIN | YES |
66 | 'root'@'localhost' | def | BACKUP_ADMIN | YES |
67 | 'root'@'localhost' | def | BINLOG_ADMIN | YES |
68 | 'root'@'localhost' | def | BINLOG_ENCRYPTION_ADMIN | YES |
69 | 'root'@'localhost' | def | CLONE_ADMIN | YES |
70 | 'root'@'localhost' | def | CONNECTION_ADMIN | YES |
71 | 'root'@'localhost' | def | CREATE_SPATIAL_REFERENCE_SYSTEM | YES |
72 | 'root'@'localhost' | def | ENCRYPTION_KEY_ADMIN | YES |
73 | 'root'@'localhost' | def | FIREWALL_EXEMPT | YES |
74 | 'root'@'localhost' | def | FLUSH_OPTIMIZER_COSTS | YES |
75 | 'root'@'localhost' | def | FLUSH_PRIVILEGES | YES |
76 | 'root'@'localhost' | def | FLUSH_STATUS | YES |
77 | 'root'@'localhost' | def | FLUSH_TABLES | YES |
78 | 'root'@'localhost' | def | FLUSH_USER_RESOURCES | YES |
79 | 'root'@'localhost' | def | GROUP_REPLICATION_ADMIN | YES |
80 | 'root'@'localhost' | def | GROUP_REPLICATION_STREAM | YES |
81 | 'root'@'localhost' | def | INNODB_REDO_LOG_ARCHIVE | YES |
82 | 'root'@'localhost' | def | INNODB_REDO_LOG_ENABLE | YES |
83 | 'root'@'localhost' | def | OPTIMIZE_LOCAL_TABLE | YES |
84 | 'root'@'localhost' | def | PASSWORDLESS_USER_ADMIN | YES |
85 | 'root'@'localhost' | def | PERSIST_RO_VARIABLES_ADMIN | YES |
86 | 'root'@'localhost' | def | REPLICATION_APPLIER | YES |
87 | 'root'@'localhost' | def | REPLICATION_SLAVE_ADMIN | YES |
88 | 'root'@'localhost' | def | RESOURCE_GROUP_ADMIN | YES |
89 | 'root'@'localhost' | def | RESOURCE_GROUP_USER | YES |
90 | 'root'@'localhost' | def | ROLE_ADMIN | YES |
91 | 'root'@'localhost' | def | SENSITIVE_VARIABLES_OBSERVER | YES |
92 | 'root'@'localhost' | def | SERVICE_CONNECTION_ADMIN | YES |
93 | 'root'@'localhost' | def | SESSION_VARIABLES_ADMIN | YES |
94 | 'root'@'localhost' | def | SET_ANY_DEFINER | YES |
95 | 'root'@'localhost' | def | SHOW_ROUTINE | YES |
96 | 'root'@'localhost' | def | SYSTEM_USER | YES |
97 | 'root'@'localhost' | def | SYSTEM_VARIABLES_ADMIN | YES |
98 | 'root'@'localhost' | def | TABLE_ENCRYPTION_ADMIN | YES |
99 | 'root'@'localhost' | def | TELEMETRY_LOG_ADMIN | YES |
100 | 'root'@'localhost' | def | TRANSACTION_GTID_TAG | YES |
101 | 'root'@'localhost' | def | XA_RECOVER_ADMIN | YES |
102 | 'cmc'@'%' | def | USAGE | NO |
103 +--------------------------------+---------------+---------------------------------+--------------+
104 92 rows in set (0.001 sec)
105
106# `passwords.sql`
107
108``` sql
109SELECT user, host, plugin FROM mysql.user;
110```
111
112 mysql> SELECT user, host, plugin FROM mysql.user;
113 +------------------+-----------+-----------------------+
114 | user | host | plugin |
115 +------------------+-----------+-----------------------+
116 | cmc | % | caching_sha2_password |
117 | mysql.infoschema | localhost | caching_sha2_password |
118 | mysql.session | localhost | caching_sha2_password |
119 | mysql.sys | localhost | caching_sha2_password |
120 | root | localhost | caching_sha2_password |
121 +------------------+-----------+-----------------------+
122 5 rows in set (0.001 sec)
123
124``` sql
125SHOW GLOBAL VARIABLES LIKE 'validate_password%';
126SHOW VARIABLES LIKE 'validate_password%';
127```
128
129 mysql> SHOW GLOBAL VARIABLES LIKE 'validate_password%';
130 +-------------------------------------------------+--------+
131 | Variable_name | Value |
132 +-------------------------------------------------+--------+
133 | validate_password.changed_characters_percentage | 0 |
134 | validate_password.check_user_name | ON |
135 | validate_password.dictionary_file | |
136 | validate_password.length | 8 |
137 | validate_password.mixed_case_count | 1 |
138 | validate_password.number_count | 1 |
139 | validate_password.policy | MEDIUM |
140 | validate_password.special_char_count | 1 |
141 +-------------------------------------------------+--------+
142 8 rows in set (0.004 sec)
143
144 mysql> SHOW VARIABLES LIKE 'validate_password%';
145 +-------------------------------------------------+--------+
146 | Variable_name | Value |
147 +-------------------------------------------------+--------+
148 | validate_password.changed_characters_percentage | 0 |
149 | validate_password.check_user_name | ON |
150 | validate_password.dictionary_file | |
151 | validate_password.length | 8 |
152 | validate_password.mixed_case_count | 1 |
153 | validate_password.number_count | 1 |
154 | validate_password.policy | MEDIUM |
155 | validate_password.special_char_count | 1 |
156 +-------------------------------------------------+--------+
157 8 rows in set (0.004 sec)
158
159``` sql
160SELECT * FROM mysql.user
161```
162
163 MySQL [(none)]> SELECT * FROM mysql.user;
164 +-----------+------------------+-------------+-------------+-------------+-------------+-------------+-----------+-------------+---------------+--------------+-----------+------------+-----------------+------------+------------+--------------+------------+-----------------------+------------------+--------------+-----------------+------------------+------------------+----------------+---------------------+--------------------+------------------+------------+--------------+------------------------+----------+------------+-------------+--------------+---------------+-------------+-----------------+----------------------+-----------------------+------------------------------------------------------------------------+------------------+-----------------------+-------------------+----------------+------------------+----------------+------------------------+---------------------+--------------------------+-----------------+
165 | Host | User | Select_priv | Insert_priv | Update_priv | Delete_priv | Create_priv | Drop_priv | Reload_priv | Shutdown_priv | Process_priv | File_priv | Grant_priv | References_priv | Index_priv | Alter_priv | Show_db_priv | Super_priv | Create_tmp_table_priv | Lock_tables_priv | Execute_priv | Repl_slave_priv | Repl_client_priv | Create_view_priv | Show_view_priv | Create_routine_priv | Alter_routine_priv | Create_user_priv | Event_priv | Trigger_priv | Create_tablespace_priv | ssl_type | ssl_cipher | x509_issuer | x509_subject | max_questions | max_updates | max_connections | max_user_connections | plugin | authentication_string | password_expired | password_last_changed | password_lifetime | account_locked | Create_role_priv | Drop_role_priv | Password_reuse_history | Password_reuse_time | Password_require_current | User_attributes |
166 +-----------+------------------+-------------+-------------+-------------+-------------+-------------+-----------+-------------+---------------+--------------+-----------+------------+-----------------+------------+------------+--------------+------------+-----------------------+------------------+--------------+-----------------+------------------+------------------+----------------+---------------------+--------------------+------------------+------------+--------------+------------------------+----------+------------+-------------+--------------+---------------+-------------+-----------------+----------------------+-----------------------+------------------------------------------------------------------------+------------------+-----------------------+-------------------+----------------+------------------+----------------+------------------------+---------------------+--------------------------+-----------------+
167 | % | cmc | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | | | | | 0 | 0 | 0 | 0 | caching_sha2_password | | N | 2025-04-25 16:28:52 | NULL | N | N | N | NULL | NULL | NULL | NULL |
168 | localhost | mysql.infoschema | Y | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | | | | | 0 | 0 | 0 | 0 | caching_sha2_password | $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED | N | 2025-04-25 15:51:53 | NULL | Y | N | N | NULL | NULL | NULL | NULL |
169 | localhost | mysql.session | N | N | N | N | N | N | N | Y | N | N | N | N | N | N | N | Y | N | N | N | N | N | N | N | N | N | N | N | N | N | | | | | 0 | 0 | 0 | 0 | caching_sha2_password | $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED | N | 2025-04-25 15:51:53 | NULL | Y | N | N | NULL | NULL | NULL | NULL |
170 | localhost | mysql.sys | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | | | | | 0 | 0 | 0 | 0 | caching_sha2_password | $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED | N | 2025-04-25 15:51:53 | NULL | Y | N | N | NULL | NULL | NULL | NULL |
171 | localhost | root | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | | | | | 0 | 0 | 0 | 0 | caching_sha2_password | | N | 2025-04-25 15:51:53 | NULL | N | Y | Y | NULL | NULL | NULL | NULL |
172 +-----------+------------------+-------------+-------------+-------------+-------------+-------------+-----------+-------------+---------------+--------------+-----------+------------+-----------------+------------+------------+--------------+------------+-----------------------+------------------+--------------+-----------------+------------------+------------------+----------------+---------------------+--------------------+------------------+------------+--------------+------------------------+----------+------------+-------------+--------------+---------------+-------------+-----------------+----------------------+-----------------------+------------------------------------------------------------------------+------------------+-----------------------+-------------------+----------------+------------------+----------------+------------------------+---------------------+--------------------------+-----------------+
173 5 rows in set (0.005 sec)
databases/mysql/README.org deleted โˆ’183
@@ -1,183 +0,0 @@
1#+title: MySQL
2
3* =mysql_admins.sql=
4
5#+begin_src sql
6SELECT * FROM information_schema.user_privileges;
7#+end_src
8
9#+begin_src
10MySQL [(none)]> SELECT * FROM information_schema.user_privileges;
11+--------------------------------+---------------+---------------------------------+--------------+
12| GRANTEE | TABLE_CATALOG | PRIVILEGE_TYPE | IS_GRANTABLE |
13+--------------------------------+---------------+---------------------------------+--------------+
14| 'mysql.infoschema'@'localhost' | def | SELECT | NO |
15| 'mysql.infoschema'@'localhost' | def | AUDIT_ABORT_EXEMPT | NO |
16| 'mysql.infoschema'@'localhost' | def | FIREWALL_EXEMPT | NO |
17| 'mysql.infoschema'@'localhost' | def | SYSTEM_USER | NO |
18| 'mysql.session'@'localhost' | def | SHUTDOWN | NO |
19| 'mysql.session'@'localhost' | def | SUPER | NO |
20| 'mysql.session'@'localhost' | def | AUDIT_ABORT_EXEMPT | NO |
21| 'mysql.session'@'localhost' | def | AUTHENTICATION_POLICY_ADMIN | NO |
22| 'mysql.session'@'localhost' | def | BACKUP_ADMIN | NO |
23| 'mysql.session'@'localhost' | def | CLONE_ADMIN | NO |
24| 'mysql.session'@'localhost' | def | CONNECTION_ADMIN | NO |
25| 'mysql.session'@'localhost' | def | FIREWALL_EXEMPT | NO |
26| 'mysql.session'@'localhost' | def | PERSIST_RO_VARIABLES_ADMIN | NO |
27| 'mysql.session'@'localhost' | def | SESSION_VARIABLES_ADMIN | NO |
28| 'mysql.session'@'localhost' | def | SYSTEM_USER | NO |
29| 'mysql.session'@'localhost' | def | SYSTEM_VARIABLES_ADMIN | NO |
30| 'mysql.sys'@'localhost' | def | USAGE | NO |
31| 'mysql.sys'@'localhost' | def | AUDIT_ABORT_EXEMPT | NO |
32| 'mysql.sys'@'localhost' | def | FIREWALL_EXEMPT | NO |
33| 'mysql.sys'@'localhost' | def | SYSTEM_USER | NO |
34| 'root'@'localhost' | def | SELECT | YES |
35| 'root'@'localhost' | def | INSERT | YES |
36| 'root'@'localhost' | def | UPDATE | YES |
37| 'root'@'localhost' | def | DELETE | YES |
38| 'root'@'localhost' | def | CREATE | YES |
39| 'root'@'localhost' | def | DROP | YES |
40| 'root'@'localhost' | def | RELOAD | YES |
41| 'root'@'localhost' | def | SHUTDOWN | YES |
42| 'root'@'localhost' | def | PROCESS | YES |
43| 'root'@'localhost' | def | FILE | YES |
44| 'root'@'localhost' | def | REFERENCES | YES |
45| 'root'@'localhost' | def | INDEX | YES |
46| 'root'@'localhost' | def | ALTER | YES |
47| 'root'@'localhost' | def | SHOW DATABASES | YES |
48| 'root'@'localhost' | def | SUPER | YES |
49| 'root'@'localhost' | def | CREATE TEMPORARY TABLES | YES |
50| 'root'@'localhost' | def | LOCK TABLES | YES |
51| 'root'@'localhost' | def | EXECUTE | YES |
52| 'root'@'localhost' | def | REPLICATION SLAVE | YES |
53| 'root'@'localhost' | def | REPLICATION CLIENT | YES |
54| 'root'@'localhost' | def | CREATE VIEW | YES |
55| 'root'@'localhost' | def | SHOW VIEW | YES |
56| 'root'@'localhost' | def | CREATE ROUTINE | YES |
57| 'root'@'localhost' | def | ALTER ROUTINE | YES |
58| 'root'@'localhost' | def | CREATE USER | YES |
59| 'root'@'localhost' | def | EVENT | YES |
60| 'root'@'localhost' | def | TRIGGER | YES |
61| 'root'@'localhost' | def | CREATE TABLESPACE | YES |
62| 'root'@'localhost' | def | CREATE ROLE | YES |
63| 'root'@'localhost' | def | DROP ROLE | YES |
64| 'root'@'localhost' | def | ALLOW_NONEXISTENT_DEFINER | YES |
65| 'root'@'localhost' | def | APPLICATION_PASSWORD_ADMIN | YES |
66| 'root'@'localhost' | def | AUDIT_ABORT_EXEMPT | YES |
67| 'root'@'localhost' | def | AUDIT_ADMIN | YES |
68| 'root'@'localhost' | def | AUTHENTICATION_POLICY_ADMIN | YES |
69| 'root'@'localhost' | def | BACKUP_ADMIN | YES |
70| 'root'@'localhost' | def | BINLOG_ADMIN | YES |
71| 'root'@'localhost' | def | BINLOG_ENCRYPTION_ADMIN | YES |
72| 'root'@'localhost' | def | CLONE_ADMIN | YES |
73| 'root'@'localhost' | def | CONNECTION_ADMIN | YES |
74| 'root'@'localhost' | def | CREATE_SPATIAL_REFERENCE_SYSTEM | YES |
75| 'root'@'localhost' | def | ENCRYPTION_KEY_ADMIN | YES |
76| 'root'@'localhost' | def | FIREWALL_EXEMPT | YES |
77| 'root'@'localhost' | def | FLUSH_OPTIMIZER_COSTS | YES |
78| 'root'@'localhost' | def | FLUSH_PRIVILEGES | YES |
79| 'root'@'localhost' | def | FLUSH_STATUS | YES |
80| 'root'@'localhost' | def | FLUSH_TABLES | YES |
81| 'root'@'localhost' | def | FLUSH_USER_RESOURCES | YES |
82| 'root'@'localhost' | def | GROUP_REPLICATION_ADMIN | YES |
83| 'root'@'localhost' | def | GROUP_REPLICATION_STREAM | YES |
84| 'root'@'localhost' | def | INNODB_REDO_LOG_ARCHIVE | YES |
85| 'root'@'localhost' | def | INNODB_REDO_LOG_ENABLE | YES |
86| 'root'@'localhost' | def | OPTIMIZE_LOCAL_TABLE | YES |
87| 'root'@'localhost' | def | PASSWORDLESS_USER_ADMIN | YES |
88| 'root'@'localhost' | def | PERSIST_RO_VARIABLES_ADMIN | YES |
89| 'root'@'localhost' | def | REPLICATION_APPLIER | YES |
90| 'root'@'localhost' | def | REPLICATION_SLAVE_ADMIN | YES |
91| 'root'@'localhost' | def | RESOURCE_GROUP_ADMIN | YES |
92| 'root'@'localhost' | def | RESOURCE_GROUP_USER | YES |
93| 'root'@'localhost' | def | ROLE_ADMIN | YES |
94| 'root'@'localhost' | def | SENSITIVE_VARIABLES_OBSERVER | YES |
95| 'root'@'localhost' | def | SERVICE_CONNECTION_ADMIN | YES |
96| 'root'@'localhost' | def | SESSION_VARIABLES_ADMIN | YES |
97| 'root'@'localhost' | def | SET_ANY_DEFINER | YES |
98| 'root'@'localhost' | def | SHOW_ROUTINE | YES |
99| 'root'@'localhost' | def | SYSTEM_USER | YES |
100| 'root'@'localhost' | def | SYSTEM_VARIABLES_ADMIN | YES |
101| 'root'@'localhost' | def | TABLE_ENCRYPTION_ADMIN | YES |
102| 'root'@'localhost' | def | TELEMETRY_LOG_ADMIN | YES |
103| 'root'@'localhost' | def | TRANSACTION_GTID_TAG | YES |
104| 'root'@'localhost' | def | XA_RECOVER_ADMIN | YES |
105| 'cmc'@'%' | def | USAGE | NO |
106+--------------------------------+---------------+---------------------------------+--------------+
10792 rows in set (0.001 sec)
108#+end_src
109
110* =passwords.sql=
111
112#+begin_src sql
113SELECT user, host, plugin FROM mysql.user;
114#+end_src
115
116#+begin_src
117mysql> SELECT user, host, plugin FROM mysql.user;
118+------------------+-----------+-----------------------+
119| user | host | plugin |
120+------------------+-----------+-----------------------+
121| cmc | % | caching_sha2_password |
122| mysql.infoschema | localhost | caching_sha2_password |
123| mysql.session | localhost | caching_sha2_password |
124| mysql.sys | localhost | caching_sha2_password |
125| root | localhost | caching_sha2_password |
126+------------------+-----------+-----------------------+
1275 rows in set (0.001 sec)
128#+end_src
129
130#+begin_src sql
131SHOW GLOBAL VARIABLES LIKE 'validate_password%';
132SHOW VARIABLES LIKE 'validate_password%';
133#+end_src
134
135#+begin_src
136mysql> SHOW GLOBAL VARIABLES LIKE 'validate_password%';
137+-------------------------------------------------+--------+
138| Variable_name | Value |
139+-------------------------------------------------+--------+
140| validate_password.changed_characters_percentage | 0 |
141| validate_password.check_user_name | ON |
142| validate_password.dictionary_file | |
143| validate_password.length | 8 |
144| validate_password.mixed_case_count | 1 |
145| validate_password.number_count | 1 |
146| validate_password.policy | MEDIUM |
147| validate_password.special_char_count | 1 |
148+-------------------------------------------------+--------+
1498 rows in set (0.004 sec)
150
151mysql> SHOW VARIABLES LIKE 'validate_password%';
152+-------------------------------------------------+--------+
153| Variable_name | Value |
154+-------------------------------------------------+--------+
155| validate_password.changed_characters_percentage | 0 |
156| validate_password.check_user_name | ON |
157| validate_password.dictionary_file | |
158| validate_password.length | 8 |
159| validate_password.mixed_case_count | 1 |
160| validate_password.number_count | 1 |
161| validate_password.policy | MEDIUM |
162| validate_password.special_char_count | 1 |
163+-------------------------------------------------+--------+
1648 rows in set (0.004 sec)
165#+end_src
166
167#+begin_src sql
168SELECT * FROM mysql.user
169#+end_src
170
171#+begin_src
172MySQL [(none)]> SELECT * FROM mysql.user;
173+-----------+------------------+-------------+-------------+-------------+-------------+-------------+-----------+-------------+---------------+--------------+-----------+------------+-----------------+------------+------------+--------------+------------+-----------------------+------------------+--------------+-----------------+------------------+------------------+----------------+---------------------+--------------------+------------------+------------+--------------+------------------------+----------+------------+-------------+--------------+---------------+-------------+-----------------+----------------------+-----------------------+------------------------------------------------------------------------+------------------+-----------------------+-------------------+----------------+------------------+----------------+------------------------+---------------------+--------------------------+-----------------+
174| Host | User | Select_priv | Insert_priv | Update_priv | Delete_priv | Create_priv | Drop_priv | Reload_priv | Shutdown_priv | Process_priv | File_priv | Grant_priv | References_priv | Index_priv | Alter_priv | Show_db_priv | Super_priv | Create_tmp_table_priv | Lock_tables_priv | Execute_priv | Repl_slave_priv | Repl_client_priv | Create_view_priv | Show_view_priv | Create_routine_priv | Alter_routine_priv | Create_user_priv | Event_priv | Trigger_priv | Create_tablespace_priv | ssl_type | ssl_cipher | x509_issuer | x509_subject | max_questions | max_updates | max_connections | max_user_connections | plugin | authentication_string | password_expired | password_last_changed | password_lifetime | account_locked | Create_role_priv | Drop_role_priv | Password_reuse_history | Password_reuse_time | Password_require_current | User_attributes |
175+-----------+------------------+-------------+-------------+-------------+-------------+-------------+-----------+-------------+---------------+--------------+-----------+------------+-----------------+------------+------------+--------------+------------+-----------------------+------------------+--------------+-----------------+------------------+------------------+----------------+---------------------+--------------------+------------------+------------+--------------+------------------------+----------+------------+-------------+--------------+---------------+-------------+-----------------+----------------------+-----------------------+------------------------------------------------------------------------+------------------+-----------------------+-------------------+----------------+------------------+----------------+------------------------+---------------------+--------------------------+-----------------+
176| % | cmc | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | | | | | 0 | 0 | 0 | 0 | caching_sha2_password | | N | 2025-04-25 16:28:52 | NULL | N | N | N | NULL | NULL | NULL | NULL |
177| localhost | mysql.infoschema | Y | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | | | | | 0 | 0 | 0 | 0 | caching_sha2_password | $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED | N | 2025-04-25 15:51:53 | NULL | Y | N | N | NULL | NULL | NULL | NULL |
178| localhost | mysql.session | N | N | N | N | N | N | N | Y | N | N | N | N | N | N | N | Y | N | N | N | N | N | N | N | N | N | N | N | N | N | | | | | 0 | 0 | 0 | 0 | caching_sha2_password | $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED | N | 2025-04-25 15:51:53 | NULL | Y | N | N | NULL | NULL | NULL | NULL |
179| localhost | mysql.sys | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | N | | | | | 0 | 0 | 0 | 0 | caching_sha2_password | $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED | N | 2025-04-25 15:51:53 | NULL | Y | N | N | NULL | NULL | NULL | NULL |
180| localhost | root | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | Y | | | | | 0 | 0 | 0 | 0 | caching_sha2_password | | N | 2025-04-25 15:51:53 | NULL | N | Y | Y | NULL | NULL | NULL | NULL |
181+-----------+------------------+-------------+-------------+-------------+-------------+-------------+-----------+-------------+---------------+--------------+-----------+------------+-----------------+------------+------------+--------------+------------+-----------------------+------------------+--------------+-----------------+------------------+------------------+----------------+---------------------+--------------------+------------------+------------+--------------+------------------------+----------+------------+-------------+--------------+---------------+-------------+-----------------+----------------------+-----------------------+------------------------------------------------------------------------+------------------+-----------------------+-------------------+----------------+------------------+----------------+------------------------+---------------------+--------------------------+-----------------+
1825 rows in set (0.005 sec)
183#+end_src
databases/oracle/README.org โ†’ databases/oracle/README.md renamed +10 โˆ’10
@@ -1,6 +1,6 @@
1* =oracle_admins.sql= 1# `oracle_admins.sql`
2 2
3#+begin_src sql 3``` sql
4SELECT 4SELECT
5 grantee AS "User", 5 grantee AS "User",
6 privilege AS "Privilege" 6 privilege AS "Privilege"
@@ -16,9 +16,9 @@ FROM
16 dba_tab_privs 16 dba_tab_privs
17WHERE 17WHERE
18 grantee IN (SELECT DISTINCT grantee FROM dba_tab_privs); 18 grantee IN (SELECT DISTINCT grantee FROM dba_tab_privs);
19#+end_src 19```
20 20
21#+begin_src text 21``` text
22| User | Privilege | 22| User | Privilege |
23|----------+---------------------| 23|----------+---------------------|
24| SCOTT | CREATE SESSION | 24| SCOTT | CREATE SESSION |
@@ -39,18 +39,18 @@ WHERE
39| APP_USER | SELECT ON EMPLOYEES | 39| APP_USER | SELECT ON EMPLOYEES |
40| APP_USER | INSERT ON EMPLOYEES | 40| APP_USER | INSERT ON EMPLOYEES |
41| APP_USER | UPDATE ON EMPLOYEES | 41| APP_USER | UPDATE ON EMPLOYEES |
42#+end_src 42```
43 43
44* =oracle_admins_alt.sql= 44# `oracle_admins_alt.sql`
45 45
46#+begin_src sql 46``` sql
47SELECT ** FROM sys.dba_role_privs; 47SELECT ** FROM sys.dba_role_privs;
48SELECT ** FROM sys.dba_sys_privs; 48SELECT ** FROM sys.dba_sys_privs;
49SELECT ** FROM sys.dba_tab_privs; 49SELECT ** FROM sys.dba_tab_privs;
50SELECT ** FROM sys.dba_users; 50SELECT ** FROM sys.dba_users;
51#+end_src 51```
52 52
53#+begin_src text 53``` text
54| Grantee | Granted_Role | Admin_Option | 54| Grantee | Granted_Role | Admin_Option |
55|----------+--------------+--------------| 55|----------+--------------+--------------|
56| SCOTT | DBA | NO | 56| SCOTT | DBA | NO |
@@ -78,4 +78,4 @@ SELECT ** FROM sys.dba_users;
78| SYS | OPEN | SYSTEM | TEMP | 78| SYS | OPEN | SYSTEM | TEMP |
79| SYSTEM | OPEN | SYSTEM | TEMP | 79| SYSTEM | OPEN | SYSTEM | TEMP |
80| APP_USER | OPEN | USERS | TEMP | 80| APP_USER | OPEN | USERS | TEMP |
81#+end_src 81```
databases/postgres/README.md added +67
@@ -0,0 +1,67 @@
1# `passwords.sql`
2
3``` sql
4SELECT *
5FROM pg_settings
6WHERE name LIKE 'password_%';
7```
8
9 | name | setting | unit | category | short_desc | extra_desc | context | vartype | source | min_val | max_val | enumvals | boot_val | reset_val | sourcefile | sourceline | pending_restart |
10 |---------------------+---------------+------+-------------------------------------------------+-------------------------------------------------+------------+---------+---------+---------+---------+---------+---------------------+---------------+---------------+------------+------------+-----------------|
11 | password_encryption | scram-sha-256 | | Connections and Authentication / Authentication | Chooses the algorithm for encrypting passwords. | | user | enum | default | | | {md5,scram-sha-256} | scram-sha-256 | scram-sha-256 | | | false |
12
13``` sql
14SELECT
15 usename AS user_name,
16 passwd AS password,
17 valuntil AS valid_until,
18 useconfig AS user_config
19FROM pg_shadow;
20```
21
22 | user_name | password | valid_until | user_config |
23 |-----------+---------------------------------------------------------------------------------------------------------------------------------------+------------------------+-------------|
24 | cmc | | | |
25 | testuser | SCRAM-SHA-256$4096:+NSpEU+8afhJ4BUTkzdKeg==$FGIRcTWr89b42qkLUl4Ntfp4RUpoc3GIpLHqJl/fWZE=:o1UM8YiEj5SLV5l/geMuqXMRi6onWazryn/l+LXYMxU= | 2025-12-31 00:00:00-06 | |
26
27# `admins.sql`
28
29``` sql
30SELECT
31 r.rolname AS role_name,
32 r.rolsuper AS is_superuser,
33 r.rolinherit AS inherits_privileges,
34 r.rolcreaterole AS can_create_roles,
35 r.rolcreatedb AS can_create_db,
36 r.rolcanlogin AS can_login,
37 r.rolreplication AS can_replication,
38 r.rolconnlimit AS connection_limit,
39 r.rolvaliduntil AS valid_until,
40 ARRAY(
41 SELECT b.rolname
42 FROM pg_auth_members m
43 JOIN pg_roles b ON (m.roleid = b.oid)
44 WHERE m.member = r.oid
45 ) AS member_of
46FROM pg_roles r;
47```
48
49 | role_name | is_superuser | inherits_privileges | can_create_roles | can_create_db | can_login | can_replication | connection_limit | valid_until | member_of |
50 |-----------------------------+--------------+---------------------+------------------+---------------+-----------+-----------------+------------------+------------------------+--------------------------------------------------------------|
51 | cmc | true | true | true | true | true | true | -1 | | {} |
52 | pg_database_owner | false | true | false | false | false | false | -1 | | {} |
53 | pg_read_all_data | false | true | false | false | false | false | -1 | | {} |
54 | pg_write_all_data | false | true | false | false | false | false | -1 | | {} |
55 | pg_monitor | false | true | false | false | false | false | -1 | | {pg_read_all_settings,pg_read_all_stats,pg_stat_scan_tables} |
56 | pg_read_all_settings | false | true | false | false | false | false | -1 | | {} |
57 | pg_read_all_stats | false | true | false | false | false | false | -1 | | {} |
58 | pg_stat_scan_tables | false | true | false | false | false | false | -1 | | {} |
59 | pg_read_server_files | false | true | false | false | false | false | -1 | | {} |
60 | pg_write_server_files | false | true | false | false | false | false | -1 | | {} |
61 | pg_execute_server_program | false | true | false | false | false | false | -1 | | {} |
62 | pg_signal_backend | false | true | false | false | false | false | -1 | | {} |
63 | pg_checkpoint | false | true | false | false | false | false | -1 | | {} |
64 | pg_maintain | false | true | false | false | false | false | -1 | | {} |
65 | pg_use_reserved_connections | false | true | false | false | false | false | -1 | | {} |
66 | pg_create_subscription | false | true | false | false | false | false | -1 | | {} |
67 | testuser | false | true | false | false | true | false | -1 | 2025-12-31 00:00:00-06 | {} |
databases/postgres/README.org deleted โˆ’75
@@ -1,75 +0,0 @@
1#+title: Postgres
2
3* =passwords.sql=
4
5#+begin_src sql
6SELECT *
7FROM pg_settings
8WHERE name LIKE 'password_%';
9#+end_src
10
11#+begin_src
12| name | setting | unit | category | short_desc | extra_desc | context | vartype | source | min_val | max_val | enumvals | boot_val | reset_val | sourcefile | sourceline | pending_restart |
13|---------------------+---------------+------+-------------------------------------------------+-------------------------------------------------+------------+---------+---------+---------+---------+---------+---------------------+---------------+---------------+------------+------------+-----------------|
14| password_encryption | scram-sha-256 | | Connections and Authentication / Authentication | Chooses the algorithm for encrypting passwords. | | user | enum | default | | | {md5,scram-sha-256} | scram-sha-256 | scram-sha-256 | | | false |
15#+end_src
16
17#+begin_src sql
18SELECT
19 usename AS user_name,
20 passwd AS password,
21 valuntil AS valid_until,
22 useconfig AS user_config
23FROM pg_shadow;
24#+end_src
25
26#+begin_src
27| user_name | password | valid_until | user_config |
28|-----------+---------------------------------------------------------------------------------------------------------------------------------------+------------------------+-------------|
29| cmc | | | |
30| testuser | SCRAM-SHA-256$4096:+NSpEU+8afhJ4BUTkzdKeg==$FGIRcTWr89b42qkLUl4Ntfp4RUpoc3GIpLHqJl/fWZE=:o1UM8YiEj5SLV5l/geMuqXMRi6onWazryn/l+LXYMxU= | 2025-12-31 00:00:00-06 | |
31#+end_src
32
33* =admins.sql=
34
35#+begin_src sql
36SELECT
37 r.rolname AS role_name,
38 r.rolsuper AS is_superuser,
39 r.rolinherit AS inherits_privileges,
40 r.rolcreaterole AS can_create_roles,
41 r.rolcreatedb AS can_create_db,
42 r.rolcanlogin AS can_login,
43 r.rolreplication AS can_replication,
44 r.rolconnlimit AS connection_limit,
45 r.rolvaliduntil AS valid_until,
46 ARRAY(
47 SELECT b.rolname
48 FROM pg_auth_members m
49 JOIN pg_roles b ON (m.roleid = b.oid)
50 WHERE m.member = r.oid
51 ) AS member_of
52FROM pg_roles r;
53#+end_src
54
55#+begin_src
56| role_name | is_superuser | inherits_privileges | can_create_roles | can_create_db | can_login | can_replication | connection_limit | valid_until | member_of |
57|-----------------------------+--------------+---------------------+------------------+---------------+-----------+-----------------+------------------+------------------------+--------------------------------------------------------------|
58| cmc | true | true | true | true | true | true | -1 | | {} |
59| pg_database_owner | false | true | false | false | false | false | -1 | | {} |
60| pg_read_all_data | false | true | false | false | false | false | -1 | | {} |
61| pg_write_all_data | false | true | false | false | false | false | -1 | | {} |
62| pg_monitor | false | true | false | false | false | false | -1 | | {pg_read_all_settings,pg_read_all_stats,pg_stat_scan_tables} |
63| pg_read_all_settings | false | true | false | false | false | false | -1 | | {} |
64| pg_read_all_stats | false | true | false | false | false | false | -1 | | {} |
65| pg_stat_scan_tables | false | true | false | false | false | false | -1 | | {} |
66| pg_read_server_files | false | true | false | false | false | false | -1 | | {} |
67| pg_write_server_files | false | true | false | false | false | false | -1 | | {} |
68| pg_execute_server_program | false | true | false | false | false | false | -1 | | {} |
69| pg_signal_backend | false | true | false | false | false | false | -1 | | {} |
70| pg_checkpoint | false | true | false | false | false | false | -1 | | {} |
71| pg_maintain | false | true | false | false | false | false | -1 | | {} |
72| pg_use_reserved_connections | false | true | false | false | false | false | -1 | | {} |
73| pg_create_subscription | false | true | false | false | false | false | -1 | | {} |
74| testuser | false | true | false | false | true | false | -1 | 2025-12-31 00:00:00-06 | {} |
75#+end_src
databases/sql/README.org โ†’ databases/sql/README.md renamed +10 โˆ’10
@@ -1,10 +1,10 @@
1* =admins.sql= 1# `admins.sql`
2 2
3#+begin_src sql 3``` sql
4:r admins.sql 4:r admins.sql
5#+end_src 5```
6 6
7#+begin_src text 7``` text
8| UserName | UserType | DatabaseUserName | Role | PermissionType | PermissionState | ObjectType | ObjectName | ColumnName | 8| UserName | UserType | DatabaseUserName | Role | PermissionType | PermissionState | ObjectType | ObjectName | ColumnName |
9|-------------+--------------+------------------+-----------------+----------------+-----------------+----------------------+--------------------+------------| 9|-------------+--------------+------------------+-----------------+----------------+-----------------+----------------------+--------------------+------------|
10| SCOTT | SQL User | SCOTT | NULL | SELECT | GRANT | USER_TABLE | EMPLOYEES | NULL | 10| SCOTT | SQL User | SCOTT | NULL | SELECT | GRANT | USER_TABLE | EMPLOYEES | NULL |
@@ -14,15 +14,15 @@
14| APP_USER | Windows User | APP_USER | ApplicationRole | INSERT | GRANT | USER_TABLE | EMPLOYEES | NULL | 14| APP_USER | Windows User | APP_USER | ApplicationRole | INSERT | GRANT | USER_TABLE | EMPLOYEES | NULL |
15| {All Users} | {All Users} | {All Users} | public | SELECT | GRANT | USER_TABLE | EMPLOYEES | NULL | 15| {All Users} | {All Users} | {All Users} | public | SELECT | GRANT | USER_TABLE | EMPLOYEES | NULL |
16| {All Users} | {All Users} | {All Users} | public | EXECUTE | GRANT | SQL_STORED_PROCEDURE | SP_GET_EMPLOYEE | NULL | 16| {All Users} | {All Users} | {All Users} | public | EXECUTE | GRANT | SQL_STORED_PROCEDURE | SP_GET_EMPLOYEE | NULL |
17#+end_src 17```
18 18
19* =passwords.py= 19# `passwords.py`
20 20
21#+begin_src shell 21``` shell
22python passwords.py 22python passwords.py
23#+end_src 23```
24 24
25#+begin_src text 25``` text
26| Name | Type | Check Policy | Check Expiration | Reason | 26| Name | Type | Check Policy | Check Expiration | Reason |
27|-------+-----------+--------------+------------------+-----------------------------------------------------------------------------------------------------------------------------------------------| 27|-------+-----------+--------------+------------------+-----------------------------------------------------------------------------------------------------------------------------------------------|
28| user1 | SQL_LOGIN | PASS | FAIL | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is not enforced. | 28| user1 | SQL_LOGIN | PASS | FAIL | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is not enforced. |
@@ -33,4 +33,4 @@ python passwords.py
33| user6 | SQL_LOGIN | PASS | PASS | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is enforced. Reviewer to check the expiration policy. | 33| user6 | SQL_LOGIN | PASS | PASS | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is enforced. Reviewer to check the expiration policy. |
34| user7 | SQL_LOGIN | PASS | PASS | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is enforced. Reviewer to check the expiration policy. | 34| user7 | SQL_LOGIN | PASS | PASS | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is enforced. Reviewer to check the expiration policy. |
35| user8 | SQL_LOGIN | PASS | PASS | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is enforced. Reviewer to check the expiration policy. | 35| user8 | SQL_LOGIN | PASS | PASS | Password policy is enforced. Reviewer to check the assigned policy. Password expiration is enforced. Reviewer to check the expiration policy. |
36#+end_src 36```
os/linux/README.md added +56
@@ -0,0 +1,56 @@
1# `report/linux.sh`
2
3``` shell
4./report/linux.sh
5```
6
7 _ ___ _ _ _ ___ __ ___ ____ ____ _____ ____ ___ ____ _____
8 | | |_ _| \ | | | | \ \/ / / _ \/ ___| | _ \| ____| _ \ / _ \| _ \_ _|
9 | | | || \| | | | |\ / | | | \___ \ | |_) | _| | |_) | | | | |_) || |
10 | |___ | || |\ | |_| |/ \ | |_| |___) | | _ <| |___| __/| |_| | _ < | |
11 |_____|___|_| \_|\___//_/\_\ \___/|____/ |_| \_\_____|_| \___/|_| \_\|_|
12
13
14
15 ==========================================
16 # SECTION 00: Script Info
17 ==========================================
18 Execution Date and Time: Wed May 7 11:35:52 AM CDT 2025
19 Script Name: ./linux.sh
20 User Running the Script: root (called by: cmc)
21
22
23
24 ==========================================
25 # SECTION 01: System Info
26 ==========================================
27 ## Hostname
28 hera
29 ## Kernel Version
30 6.14.4-400.asahi.fc42.aarch64+16k
31 ## os-release
32 NAME="Fedora Linux Asahi Remix"
33 VERSION="42 (Forty Two [Adams])"
34 RELEASE_TYPE=stable
35 ID=fedora-asahi-remix
36 ID_LIKE=fedora
37
38# `ssh_root_login.sh`
39
40``` shell
41./ssh_root_login.sh
42```
43
44 PermitRootLogin no
45
46# `passwords.sh`
47
48``` shell
49./passwords.sh
50```
51
52 Starting analysis of authentication and login parameters...
53 Checking /etc/pam.d/system-auth for password parameters...
54 /etc/pam.d/system-auth file not found.
55 Analyzing /etc/login.defs...
56 Contents of /etc/login.defs:
os/linux/README.org deleted โˆ’64
@@ -1,64 +0,0 @@
1#+title: Linux
2
3* =report/linux.sh=
4
5#+begin_src shell
6./report/linux.sh
7#+end_src
8
9#+begin_src
10_ ___ _ _ _ ___ __ ___ ____ ____ _____ ____ ___ ____ _____
11| | |_ _| \ | | | | \ \/ / / _ \/ ___| | _ \| ____| _ \ / _ \| _ \_ _|
12| | | || \| | | | |\ / | | | \___ \ | |_) | _| | |_) | | | | |_) || |
13| |___ | || |\ | |_| |/ \ | |_| |___) | | _ <| |___| __/| |_| | _ < | |
14|_____|___|_| \_|\___//_/\_\ \___/|____/ |_| \_\_____|_| \___/|_| \_\|_|
15
16
17
18==========================================
19# SECTION 00: Script Info
20==========================================
21Execution Date and Time: Wed May 7 11:35:52 AM CDT 2025
22Script Name: ./linux.sh
23User Running the Script: root (called by: cmc)
24
25
26
27==========================================
28# SECTION 01: System Info
29==========================================
30## Hostname
31hera
32## Kernel Version
336.14.4-400.asahi.fc42.aarch64+16k
34## os-release
35NAME="Fedora Linux Asahi Remix"
36VERSION="42 (Forty Two [Adams])"
37RELEASE_TYPE=stable
38ID=fedora-asahi-remix
39ID_LIKE=fedora
40#+end_src
41
42* =ssh_root_login.sh=
43
44#+begin_src shell
45./ssh_root_login.sh
46#+end_src
47
48#+begin_src
49PermitRootLogin no
50#+end_src
51
52* =passwords.sh=
53
54#+begin_src shell
55./passwords.sh
56#+end_src
57
58#+begin_src
59Starting analysis of authentication and login parameters...
60Checking /etc/pam.d/system-auth for password parameters...
61/etc/pam.d/system-auth file not found.
62Analyzing /etc/login.defs...
63Contents of /etc/login.defs:
64#+end_src
sampling/README.org โ†’ sampling/README.md renamed +13 โˆ’14
@@ -1,12 +1,10 @@
1#+title: Sampling Tools 1# `sample.py`
2 2
3* =sample.py= 3``` bash
4
5#+begin_src sh
6python ./sample.py 4python ./sample.py
7#+end_src 5```
8 6
9#+begin_src text 7``` text
10Dataframe size (rows, columns): (100, 9) 8Dataframe size (rows, columns): (100, 9)
11Sample size: 5 9Sample size: 5
12Sample: 10Sample:
@@ -18,15 +16,16 @@ Sample:
1870 71 32BB9Ff4d939788 ... Wireless 6146 1670 71 32BB9Ff4d939788 ... Wireless 6146
19 17
20[5 rows x 9 columns] 18[5 rows x 9 columns]
21#+end_src 19```
22 20
23* =sample.html= 21# `sample.html`
24 22
25This is an interactive web page that allows users to submit their population 23This is an interactive web page that allows users to submit their
26size, sample size(s), and generate a psuedo-random sample list of numbers to use 24population size, sample size(s), and generate a psuedo-random sample
27when sampling against their population. 25list of numbers to use when sampling against their population.
28 26
29Samples can be re-generated and validated using the seed numbers provided during 27Samples can be re-generated and validated using the seed numbers
30the original generation. 28provided during the original generation.
31 29
32[[sample-html.png]] 30<span class="spurious-link"
31target="sample-html.png">*sample-html.png*</span>