Commit 72182b8b3b
Unsigned
Layout: unified · split
os/linux/ssh_root_login.sh +14 −1
| @@ -1,5 +1,11 @@ | ||
| 1 | 1 | #!/bin/bash |
| 2 | 2 | |
| 3 | # Check if the script is being run as root | |
| 4 | if [ "$EUID" -ne 0 ]; then | |
| 5 | echo "Error: This script must be run as root or with sudo." | |
| 6 | exit 1 | |
| 7 | fi | |
| 8 | ||
| 3 | 9 | # Check if the sshd_config file exists |
| 4 | 10 | if [ ! -f /etc/ssh/sshd_config ]; then |
| 5 | 11 | echo "Error: /etc/ssh/sshd_config not found." |
| @@ -10,7 +16,14 @@ echo "--- SSH Root Login Audit ---" | ||
| 10 | 16 | |
| 11 | 17 | # Find the PermitRootLogin setting, ignoring commented-out lines |
| 12 | 18 | permit_root_login=$(grep -E "^[[:space:]]*PermitRootLogin" /etc/ssh/sshd_config) |
| 13 | echo "Found setting: $permit_root_login" | |
| 19 | ||
| 20 | if [ -z "$permit_root_login" ]; then | |
| 21 | echo "PermitRootLogin is not explicitly set. Relying on sshd defaults (usually 'prohibit-password')." | |
| 22 | # In this case, we can assume it's not a simple 'yes', so we can stop. | |
| 23 | exit 0 | |
| 24 | else | |
| 25 | echo "Found setting: $permit_root_login" | |
| 26 | fi | |
| 14 | 27 | |
| 15 | 28 | |
| 16 | 29 | # Check if PermitRootLogin is set to something other than 'no' |