Commit 7eb1b86bc9
Unsigned
Layout: unified · split
os/linux/README.org +39 −422
| @@ -1,5 +1,44 @@ | ||
| 1 | 1 | #+title: Linux |
| 2 | 2 | |
| 3 | * =report/linux.sh= | |
| 4 | ||
| 5 | #+begin_src shell | |
| 6 | ./report/linux.sh | |
| 7 | #+end_src | |
| 8 | ||
| 9 | #+begin_src | |
| 10 | _ ___ _ _ _ ___ __ ___ ____ ____ _____ ____ ___ ____ _____ | |
| 11 | | | |_ _| \ | | | | \ \/ / / _ \/ ___| | _ \| ____| _ \ / _ \| _ \_ _| | |
| 12 | | | | || \| | | | |\ / | | | \___ \ | |_) | _| | |_) | | | | |_) || | | |
| 13 | | |___ | || |\ | |_| |/ \ | |_| |___) | | _ <| |___| __/| |_| | _ < | | | |
| 14 | |_____|___|_| \_|\___//_/\_\ \___/|____/ |_| \_\_____|_| \___/|_| \_\|_| | |
| 15 | ||
| 16 | ||
| 17 | ||
| 18 | ========================================== | |
| 19 | # SECTION 00: Script Info | |
| 20 | ========================================== | |
| 21 | Execution Date and Time: Wed May 7 11:35:52 AM CDT 2025 | |
| 22 | Script Name: ./linux.sh | |
| 23 | User Running the Script: root (called by: cmc) | |
| 24 | ||
| 25 | ||
| 26 | ||
| 27 | ========================================== | |
| 28 | # SECTION 01: System Info | |
| 29 | ========================================== | |
| 30 | ## Hostname | |
| 31 | hera | |
| 32 | ## Kernel Version | |
| 33 | 6.14.4-400.asahi.fc42.aarch64+16k | |
| 34 | ## os-release | |
| 35 | NAME="Fedora Linux Asahi Remix" | |
| 36 | VERSION="42 (Forty Two [Adams])" | |
| 37 | RELEASE_TYPE=stable | |
| 38 | ID=fedora-asahi-remix | |
| 39 | ID_LIKE=fedora | |
| 40 | #+end_src | |
| 41 | ||
| 3 | 42 | * =ssh_root_login.sh= |
| 4 | 43 | |
| 5 | 44 | #+begin_src shell |
| @@ -22,426 +61,4 @@ Checking /etc/pam.d/system-auth for password parameters... | ||
| 22 | 61 | /etc/pam.d/system-auth file not found. |
| 23 | 62 | Analyzing /etc/login.defs... |
| 24 | 63 | Contents of /etc/login.defs: |
| 25 | # | |
| 26 | # /etc/login.defs - Configuration control definitions for the login package. | |
| 27 | # | |
| 28 | # Three items must be defined: MAIL_DIR, ENV_SUPATH, and ENV_PATH. | |
| 29 | # If unspecified, some arbitrary (and possibly incorrect) value will | |
| 30 | # be assumed. All other items are optional - if not specified then | |
| 31 | # the described action or option will be inhibited. | |
| 32 | # | |
| 33 | # Comment lines (lines beginning with "#") and blank lines are ignored. | |
| 34 | # | |
| 35 | # Modified for Linux. --marekm | |
| 36 | ||
| 37 | # REQUIRED for useradd/userdel/usermod | |
| 38 | # Directory where mailboxes reside, _or_ name of file, relative to the | |
| 39 | # home directory. If you _do_ define MAIL_DIR and MAIL_FILE, | |
| 40 | # MAIL_DIR takes precedence. | |
| 41 | # | |
| 42 | # Essentially: | |
| 43 | # - MAIL_DIR defines the location of users mail spool files | |
| 44 | # (for mbox use) by appending the username to MAIL_DIR as defined | |
| 45 | # below. | |
| 46 | # - MAIL_FILE defines the location of the users mail spool files as the | |
| 47 | # fully-qualified filename obtained by prepending the user home | |
| 48 | # directory before $MAIL_FILE | |
| 49 | # | |
| 50 | # NOTE: This is no more used for setting up users MAIL environment variable | |
| 51 | # which is, starting from shadow 4.0.12-1 in Debian, entirely the | |
| 52 | # job of the pam_mail PAM modules | |
| 53 | # See default PAM configuration files provided for | |
| 54 | # login, su, etc. | |
| 55 | # | |
| 56 | # This is a temporary situation: setting these variables will soon | |
| 57 | # move to /etc/default/useradd and the variables will then be | |
| 58 | # no more supported | |
| 59 | MAIL_DIR /var/mail | |
| 60 | #MAIL_FILE .mail | |
| 61 | ||
| 62 | # | |
| 63 | # Enable logging and display of /var/log/faillog login failure info. | |
| 64 | # This option conflicts with the pam_tally PAM module. | |
| 65 | # | |
| 66 | FAILLOG_ENAB yes | |
| 67 | ||
| 68 | # | |
| 69 | # Enable display of unknown usernames when login failures are recorded. | |
| 70 | # | |
| 71 | # WARNING: Unknown usernames may become world readable. | |
| 72 | # See #290803 and #298773 for details about how this could become a security | |
| 73 | # concern | |
| 74 | LOG_UNKFAIL_ENAB no | |
| 75 | ||
| 76 | # | |
| 77 | # Enable logging of successful logins | |
| 78 | # | |
| 79 | LOG_OK_LOGINS no | |
| 80 | ||
| 81 | # | |
| 82 | # Enable "syslog" logging of su activity - in addition to sulog file logging. | |
| 83 | # SYSLOG_SG_ENAB does the same for newgrp and sg. | |
| 84 | # | |
| 85 | SYSLOG_SU_ENAB yes | |
| 86 | SYSLOG_SG_ENAB yes | |
| 87 | ||
| 88 | # | |
| 89 | # If defined, all su activity is logged to this file. | |
| 90 | # | |
| 91 | #SULOG_FILE /var/log/sulog | |
| 92 | ||
| 93 | # | |
| 94 | # If defined, file which maps tty line to TERM environment parameter. | |
| 95 | # Each line of the file is in a format something like "vt100 tty01". | |
| 96 | # | |
| 97 | #TTYTYPE_FILE /etc/ttytype | |
| 98 | ||
| 99 | # | |
| 100 | # If defined, login failures will be logged here in a utmp format | |
| 101 | # last, when invoked as lastb, will read /var/log/btmp, so... | |
| 102 | # | |
| 103 | FTMP_FILE /var/log/btmp | |
| 104 | ||
| 105 | # | |
| 106 | # If defined, the command name to display when running "su -". For | |
| 107 | # example, if this is defined as "su" then a "ps" will display the | |
| 108 | # command is "-su". If not defined, then "ps" would display the | |
| 109 | # name of the shell actually being run, e.g. something like "-sh". | |
| 110 | # | |
| 111 | SU_NAME su | |
| 112 | ||
| 113 | # | |
| 114 | # If defined, file which inhibits all the usual chatter during the login | |
| 115 | # sequence. If a full pathname, then hushed mode will be enabled if the | |
| 116 | # user's name or shell are found in the file. If not a full pathname, then | |
| 117 | # hushed mode will be enabled if the file exists in the user's home directory. | |
| 118 | # | |
| 119 | HUSHLOGIN_FILE .hushlogin | |
| 120 | #HUSHLOGIN_FILE /etc/hushlogins | |
| 121 | ||
| 122 | # | |
| 123 | # *REQUIRED* The default PATH settings, for superuser and normal users. | |
| 124 | # | |
| 125 | # (they are minimal, add the rest in the shell startup files) | |
| 126 | ENV_SUPATH PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin | |
| 127 | ENV_PATH PATH=/usr/local/bin:/usr/bin:/bin:/usr/local/games:/usr/games | |
| 128 | ||
| 129 | # | |
| 130 | # Terminal permissions | |
| 131 | # | |
| 132 | # TTYGROUP Login tty will be assigned this group ownership. | |
| 133 | # TTYPERM Login tty will be set to this permission. | |
| 134 | # | |
| 135 | # If you have a "write" program which is "setgid" to a special group | |
| 136 | # which owns the terminals, define TTYGROUP to the group number and | |
| 137 | # TTYPERM to 0620. Otherwise leave TTYGROUP commented out and assign | |
| 138 | # TTYPERM to either 622 or 600. | |
| 139 | # | |
| 140 | # In Debian /usr/bin/bsd-write or similar programs are setgid tty | |
| 141 | # However, the default and recommended value for TTYPERM is still 0600 | |
| 142 | # to not allow anyone to write to anyone else console or terminal | |
| 143 | ||
| 144 | # Users can still allow other people to write them by issuing | |
| 145 | # the "mesg y" command. | |
| 146 | ||
| 147 | TTYGROUP tty | |
| 148 | TTYPERM 0600 | |
| 149 | ||
| 150 | # | |
| 151 | # Login configuration initializations: | |
| 152 | # | |
| 153 | # ERASECHAR Terminal ERASE character ('\010' = backspace). | |
| 154 | # KILLCHAR Terminal KILL character ('\025' = CTRL/U). | |
| 155 | # UMASK Default "umask" value. | |
| 156 | # | |
| 157 | # The ERASECHAR and KILLCHAR are used only on System V machines. | |
| 158 | # | |
| 159 | # UMASK is the default umask value for pam_umask and is used by | |
| 160 | # useradd and newusers to set the mode of the new home directories. | |
| 161 | # 022 is the "historical" value in Debian for UMASK | |
| 162 | # 027, or even 077, could be considered better for privacy | |
| 163 | # There is no One True Answer here : each sysadmin must make up his/her | |
| 164 | # mind. | |
| 165 | # | |
| 166 | # If USERGROUPS_ENAB is set to "yes", that will modify this UMASK default value | |
| 167 | # for private user groups, i. e. the uid is the same as gid, and username is | |
| 168 | # the same as the primary group name: for these, the user permissions will be | |
| 169 | # used as group permissions, e. g. 022 will become 002. | |
| 170 | # | |
| 171 | # Prefix these values with "0" to get octal, "0x" to get hexadecimal. | |
| 172 | # | |
| 173 | ERASECHAR 0177 | |
| 174 | KILLCHAR 025 | |
| 175 | UMASK 022 | |
| 176 | ||
| 177 | # HOME_MODE is used by useradd(8) and newusers(8) to set the mode for new | |
| 178 | # home directories. | |
| 179 | # If HOME_MODE is not set, the value of UMASK is used to create the mode. | |
| 180 | HOME_MODE 0750 | |
| 181 | ||
| 182 | # | |
| 183 | # Password aging controls: | |
| 184 | # | |
| 185 | # PASS_MAX_DAYS Maximum number of days a password may be used. | |
| 186 | # PASS_MIN_DAYS Minimum number of days allowed between password changes. | |
| 187 | # PASS_WARN_AGE Number of days warning given before a password expires. | |
| 188 | # | |
| 189 | PASS_MAX_DAYS 99999 | |
| 190 | PASS_MIN_DAYS 0 | |
| 191 | PASS_WARN_AGE 7 | |
| 192 | ||
| 193 | # | |
| 194 | # Min/max values for automatic uid selection in useradd | |
| 195 | # | |
| 196 | UID_MIN 1000 | |
| 197 | UID_MAX 60000 | |
| 198 | # System accounts | |
| 199 | #SYS_UID_MIN 100 | |
| 200 | #SYS_UID_MAX 999 | |
| 201 | # Extra per user uids | |
| 202 | SUB_UID_MIN 100000 | |
| 203 | SUB_UID_MAX 600100000 | |
| 204 | SUB_UID_COUNT 65536 | |
| 205 | ||
| 206 | # | |
| 207 | # Min/max values for automatic gid selection in groupadd | |
| 208 | # | |
| 209 | GID_MIN 1000 | |
| 210 | GID_MAX 60000 | |
| 211 | # System accounts | |
| 212 | #SYS_GID_MIN 100 | |
| 213 | #SYS_GID_MAX 999 | |
| 214 | # Extra per user group ids | |
| 215 | SUB_GID_MIN 100000 | |
| 216 | SUB_GID_MAX 600100000 | |
| 217 | SUB_GID_COUNT 65536 | |
| 218 | ||
| 219 | # | |
| 220 | # Max number of login retries if password is bad. This will most likely be | |
| 221 | # overriden by PAM, since the default pam_unix module has it's own built | |
| 222 | # in of 3 retries. However, this is a safe fallback in case you are using | |
| 223 | # an authentication module that does not enforce PAM_MAXTRIES. | |
| 224 | # | |
| 225 | LOGIN_RETRIES 5 | |
| 226 | ||
| 227 | # | |
| 228 | # Max time in seconds for login | |
| 229 | # | |
| 230 | LOGIN_TIMEOUT 60 | |
| 231 | ||
| 232 | # | |
| 233 | # Which fields may be changed by regular users using chfn - use | |
| 234 | # any combination of letters "frwh" (full name, room number, work | |
| 235 | # phone, home phone). If not defined, no changes are allowed. | |
| 236 | # For backward compatibility, "yes" = "rwh" and "no" = "frwh". | |
| 237 | # | |
| 238 | CHFN_RESTRICT rwh | |
| 239 | ||
| 240 | # | |
| 241 | # Should login be allowed if we can't cd to the home directory? | |
| 242 | # Default is no. | |
| 243 | # | |
| 244 | DEFAULT_HOME yes | |
| 245 | ||
| 246 | # | |
| 247 | # If defined, this command is run when removing a user. | |
| 248 | # It should remove any at/cron/print jobs etc. owned by | |
| 249 | # the user to be removed (passed as the first argument). | |
| 250 | # | |
| 251 | #USERDEL_CMD /usr/sbin/userdel_local | |
| 252 | ||
| 253 | # | |
| 254 | # Enable setting of the umask group bits to be the same as owner bits | |
| 255 | # (examples: 022 -> 002, 077 -> 007) for non-root users, if the uid is | |
| 256 | # the same as gid, and username is the same as the primary group name. | |
| 257 | # | |
| 258 | # If set to yes, userdel will remove the user's group if it contains no | |
| 259 | # more members, and useradd will create by default a group with the name | |
| 260 | # of the user. | |
| 261 | # | |
| 262 | USERGROUPS_ENAB yes | |
| 263 | ||
| 264 | # | |
| 265 | # Instead of the real user shell, the program specified by this parameter | |
| 266 | # will be launched, although its visible name (argv[0]) will be the shell's. | |
| 267 | # The program may do whatever it wants (logging, additional authentification, | |
| 268 | # banner, ...) before running the actual shell. | |
| 269 | # | |
| 270 | # FAKE_SHELL /bin/fakeshell | |
| 271 | ||
| 272 | # | |
| 273 | # If defined, either full pathname of a file containing device names or | |
| 274 | # a ":" delimited list of device names. Root logins will be allowed only | |
| 275 | # upon these devices. | |
| 276 | # | |
| 277 | # This variable is used by login and su. | |
| 278 | # | |
| 279 | #CONSOLE /etc/consoles | |
| 280 | #CONSOLE console:tty01:tty02:tty03:tty04 | |
| 281 | ||
| 282 | # | |
| 283 | # List of groups to add to the user's supplementary group set | |
| 284 | # when logging in on the console (as determined by the CONSOLE | |
| 285 | # setting). Default is none. | |
| 286 | # | |
| 287 | # Use with caution - it is possible for users to gain permanent | |
| 288 | # access to these groups, even when not logged in on the console. | |
| 289 | # How to do it is left as an exercise for the reader... | |
| 290 | # | |
| 291 | # This variable is used by login and su. | |
| 292 | # | |
| 293 | #CONSOLE_GROUPS floppy:audio:cdrom | |
| 294 | ||
| 295 | # | |
| 296 | # If set to "yes", new passwords will be encrypted using the MD5-based | |
| 297 | # algorithm compatible with the one used by recent releases of FreeBSD. | |
| 298 | # It supports passwords of unlimited length and longer salt strings. | |
| 299 | # Set to "no" if you need to copy encrypted passwords to other systems | |
| 300 | # which don't understand the new algorithm. Default is "no". | |
| 301 | # | |
| 302 | # This variable is deprecated. You should use ENCRYPT_METHOD. | |
| 303 | # | |
| 304 | #MD5_CRYPT_ENAB no | |
| 305 | ||
| 306 | # | |
| 307 | # If set to MD5, MD5-based algorithm will be used for encrypting password | |
| 308 | # If set to SHA256, SHA256-based algorithm will be used for encrypting password | |
| 309 | # If set to SHA512, SHA512-based algorithm will be used for encrypting password | |
| 310 | # If set to BCRYPT, BCRYPT-based algorithm will be used for encrypting password | |
| 311 | # If set to YESCRYPT, YESCRYPT-based algorithm will be used for encrypting password | |
| 312 | # If set to DES, DES-based algorithm will be used for encrypting password (default) | |
| 313 | # MD5 and DES should not be used for new hashes, see crypt(5) for recommendations. | |
| 314 | # Overrides the MD5_CRYPT_ENAB option | |
| 315 | # | |
| 316 | # Note: It is recommended to use a value consistent with | |
| 317 | # the PAM modules configuration. | |
| 318 | # | |
| 319 | ENCRYPT_METHOD SHA512 | |
| 320 | ||
| 321 | # | |
| 322 | # Only works if ENCRYPT_METHOD is set to SHA256 or SHA512. | |
| 323 | # | |
| 324 | # Define the number of SHA rounds. | |
| 325 | # With a lot of rounds, it is more difficult to brute-force the password. | |
| 326 | # However, more CPU resources will be needed to authenticate users if | |
| 327 | # this value is increased. | |
| 328 | # | |
| 329 | # If not specified, the libc will choose the default number of rounds (5000), | |
| 330 | # which is orders of magnitude too low for modern hardware. | |
| 331 | # The values must be within the 1000-999999999 range. | |
| 332 | # If only one of the MIN or MAX values is set, then this value will be used. | |
| 333 | # If MIN > MAX, the highest value will be used. | |
| 334 | # | |
| 335 | #SHA_CRYPT_MIN_ROUNDS 5000 | |
| 336 | #SHA_CRYPT_MAX_ROUNDS 5000 | |
| 337 | ||
| 338 | # | |
| 339 | # Only works if ENCRYPT_METHOD is set to YESCRYPT. | |
| 340 | # | |
| 341 | # Define the YESCRYPT cost factor. | |
| 342 | # With a higher cost factor, it is more difficult to brute-force the password. | |
| 343 | # However, more CPU time and more memory will be needed to authenticate users | |
| 344 | # if this value is increased. | |
| 345 | # | |
| 346 | # If not specified, a cost factor of 5 will be used. | |
| 347 | # The value must be within the 1-11 range. | |
| 348 | # | |
| 349 | #YESCRYPT_COST_FACTOR 5 | |
| 350 | ||
| 351 | # | |
| 352 | # The pwck(8) utility emits a warning for any system account with a home | |
| 353 | # directory that does not exist. Some system accounts intentionally do | |
| 354 | # not have a home directory. Such accounts may have this string as | |
| 355 | # their home directory in /etc/passwd to avoid a spurious warning. | |
| 356 | # | |
| 357 | NONEXISTENT /nonexistent | |
| 358 | ||
| 359 | # | |
| 360 | # Allow newuidmap and newgidmap when running under an alternative | |
| 361 | # primary group. | |
| 362 | # | |
| 363 | #GRANT_AUX_GROUP_SUBIDS yes | |
| 364 | ||
| 365 | # | |
| 366 | # Select the HMAC cryptography algorithm. | |
| 367 | # Used in pam_timestamp module to calculate the keyed-hash message | |
| 368 | # authentication code. | |
| 369 | # | |
| 370 | # Note: It is recommended to check hmac(3) to see the possible algorithms | |
| 371 | # that are available in your system. | |
| 372 | # | |
| 373 | #HMAC_CRYPTO_ALGO SHA512 | |
| 374 | ||
| 375 | ################# OBSOLETED BY PAM ############## | |
| 376 | # # | |
| 377 | # These options are now handled by PAM. Please # | |
| 378 | # edit the appropriate file in /etc/pam.d/ to # | |
| 379 | # enable the equivelants of them. | |
| 380 | # | |
| 381 | ############### | |
| 382 | ||
| 383 | #MOTD_FILE | |
| 384 | #DIALUPS_CHECK_ENAB | |
| 385 | #LASTLOG_ENAB | |
| 386 | #MAIL_CHECK_ENAB | |
| 387 | #OBSCURE_CHECKS_ENAB | |
| 388 | #PORTTIME_CHECKS_ENAB | |
| 389 | #SU_WHEEL_ONLY | |
| 390 | #CRACKLIB_DICTPATH | |
| 391 | #PASS_CHANGE_TRIES | |
| 392 | #PASS_ALWAYS_WARN | |
| 393 | #ENVIRON_FILE | |
| 394 | #NOLOGINS_FILE | |
| 395 | #ISSUE_FILE | |
| 396 | #PASS_MIN_LEN | |
| 397 | #PASS_MAX_LEN | |
| 398 | #ULIMIT | |
| 399 | #ENV_HZ | |
| 400 | #CHFN_AUTH | |
| 401 | #CHSH_AUTH | |
| 402 | #FAIL_DELAY | |
| 403 | ||
| 404 | ################# OBSOLETED ####################### | |
| 405 | # # | |
| 406 | # These options are no more handled by shadow. # | |
| 407 | # # | |
| 408 | # Shadow utilities will display a warning if they # | |
| 409 | # still appear. # | |
| 410 | # # | |
| 411 | ################################################### | |
| 412 | ||
| 413 | # CLOSE_SESSIONS | |
| 414 | # LOGIN_STRING | |
| 415 | # NO_PASSWORD_CONSOLE | |
| 416 | # QMAIL_DIR | |
| 417 | ||
| 418 | ||
| 419 | ||
| 420 | ||
| 421 | Login restrictions and parameters in /etc/login.defs: | |
| 422 | # PASS_MAX_DAYS Maximum number of days a password may be used. | |
| 423 | # PASS_MIN_DAYS Minimum number of days allowed between password changes. | |
| 424 | # PASS_WARN_AGE Number of days warning given before a password expires. | |
| 425 | PASS_MAX_DAYS 99999 | |
| 426 | PASS_MIN_DAYS 0 | |
| 427 | PASS_WARN_AGE 7 | |
| 428 | UID_MIN 1000 | |
| 429 | UID_MAX 60000 | |
| 430 | #SYS_UID_MIN 100 | |
| 431 | #SYS_UID_MAX 999 | |
| 432 | SUB_UID_MIN 100000 | |
| 433 | SUB_UID_MAX 600100000 | |
| 434 | SUB_UID_COUNT 65536 | |
| 435 | GID_MIN 1000 | |
| 436 | GID_MAX 60000 | |
| 437 | #SYS_GID_MIN 100 | |
| 438 | #SYS_GID_MAX 999 | |
| 439 | SUB_GID_MIN 100000 | |
| 440 | SUB_GID_MAX 600100000 | |
| 441 | SUB_GID_COUNT 65536 | |
| 442 | LOGIN_RETRIES 5 | |
| 443 | LOGIN_TIMEOUT 60 | |
| 444 | #PASS_MIN_LEN | |
| 445 | ||
| 446 | Analysis complete. | |
| 447 | 64 | #+end_src |
os/linux/passwords.sh
os/linux/report/linux.sh added +135
| @@ -0,0 +1,135 @@ | ||
| 1 | #!/bin/bash | |
| 2 | ||
| 3 | # Default report file | |
| 4 | REPORT_FILE="report.txt" | |
| 5 | TRIM_COMMENTS=false | |
| 6 | ||
| 7 | # Function to log section header | |
| 8 | log_section() { | |
| 9 | echo -e "\n\n" >> "$REPORT_FILE" | |
| 10 | echo "==========================================" >> "$REPORT_FILE" | |
| 11 | echo "# SECTION $1: $2" >> "$REPORT_FILE" | |
| 12 | echo "==========================================" >> "$REPORT_FILE" | |
| 13 | } | |
| 14 | ||
| 15 | # Function to log file content | |
| 16 | log_file_content() { | |
| 17 | FILE_PATH="$1" | |
| 18 | FILE_NAME=$(basename "$FILE_PATH") | |
| 19 | echo "## $FILE_NAME" >> "$REPORT_FILE" | |
| 20 | if [[ -f $FILE_PATH ]]; then | |
| 21 | if $TRIM_COMMENTS; then | |
| 22 | # Trim comments (lines starting with # or empty lines) | |
| 23 | grep -vE '^\s*#|^\s*$' "$FILE_PATH" >> "$REPORT_FILE" | |
| 24 | else | |
| 25 | cat "$FILE_PATH" >> "$REPORT_FILE" | |
| 26 | fi | |
| 27 | else | |
| 28 | echo "File $FILE_PATH not found!" >> "$REPORT_FILE" | |
| 29 | fi | |
| 30 | } | |
| 31 | ||
| 32 | # Function to log command output | |
| 33 | log_command_output() { | |
| 34 | echo "## $1" >> "$REPORT_FILE" | |
| 35 | $2 >> "$REPORT_FILE" 2>&1 | |
| 36 | } | |
| 37 | ||
| 38 | # Check for sudo privileges | |
| 39 | if [[ $EUID -ne 0 ]]; then | |
| 40 | echo "This script requires sudo privileges. Please enter your password." | |
| 41 | exec sudo "$0" "$@" | |
| 42 | fi | |
| 43 | ||
| 44 | # Parse command-line arguments | |
| 45 | while getopts "t" opt; do | |
| 46 | case $opt in | |
| 47 | t) | |
| 48 | TRIM_COMMENTS=true | |
| 49 | REPORT_FILE="report_trimmed.txt" | |
| 50 | ;; | |
| 51 | *) | |
| 52 | echo "Usage: $0 [-t] # Use -t to trim comments from files" | |
| 53 | exit 1 | |
| 54 | ;; | |
| 55 | esac | |
| 56 | done | |
| 57 | ||
| 58 | # Initialize report file | |
| 59 | > "$REPORT_FILE" # Clear the file if it exists | |
| 60 | ||
| 61 | # ASCII Header | |
| 62 | cat << "EOF" >> "$REPORT_FILE" | |
| 63 | _ ___ _ _ _ ___ __ ___ ____ ____ _____ ____ ___ ____ _____ | |
| 64 | | | |_ _| \ | | | | \ \/ / / _ \/ ___| | _ \| ____| _ \ / _ \| _ \_ _| | |
| 65 | | | | || \| | | | |\ / | | | \___ \ | |_) | _| | |_) | | | | |_) || | | |
| 66 | | |___ | || |\ | |_| |/ \ | |_| |___) | | _ <| |___| __/| |_| | _ < | | | |
| 67 | |_____|___|_| \_|\___//_/\_\ \___/|____/ |_| \_\_____|_| \___/|_| \_\|_| | |
| 68 | EOF | |
| 69 | ||
| 70 | # Log Script Info | |
| 71 | log_section "00" "Script Info" | |
| 72 | echo "Execution Date and Time: $(date)" >> "$REPORT_FILE" | |
| 73 | echo "Script Name: $0" >> "$REPORT_FILE" | |
| 74 | ||
| 75 | if [[ $(whoami) == "root" ]]; then | |
| 76 | echo "User Running the Script: root (called by: $SUDO_USER)" >> "$REPORT_FILE" | |
| 77 | else | |
| 78 | echo "User Running the Script: $(whoami)" >> "$REPORT_FILE" | |
| 79 | fi | |
| 80 | ||
| 81 | # Log System Info | |
| 82 | log_section "01" "System Info" | |
| 83 | log_command_output "Hostname" "hostname" | |
| 84 | log_command_output "Kernel Version" "uname -r" | |
| 85 | log_file_content "/etc/os-release" | |
| 86 | log_command_output "IP Address" "hostname -I" | |
| 87 | ||
| 88 | # Log Password Parameters | |
| 89 | log_section "02" "Password Parameters" | |
| 90 | log_file_content "/etc/pam.d/system-auth" | |
| 91 | log_file_content "/etc/login.defs" | |
| 92 | ||
| 93 | # Log Users | |
| 94 | log_section "03" "Users" | |
| 95 | log_file_content "/etc/passwd" | |
| 96 | log_file_content "/etc/group" | |
| 97 | ||
| 98 | # Log Admins | |
| 99 | log_section "04" "Admins" | |
| 100 | log_file_content "/etc/sudoers" | |
| 101 | log_command_output "Sudo Group" "getent group sudo" | |
| 102 | log_command_output "Wheel Group" "getent group wheel" | |
| 103 | log_command_output "Root User" "getent passwd 0" | |
| 104 | ||
| 105 | # Log SSH Configuration | |
| 106 | log_section "05" "SSH Configuration" | |
| 107 | log_file_content "/etc/ssh/sshd_config" | |
| 108 | ||
| 109 | # Log Logging Configuration | |
| 110 | log_section "06" "Logging Configuration" | |
| 111 | log_file_content "/etc/syslog.conf" | |
| 112 | log_file_content "/etc/logrotate.conf" | |
| 113 | ||
| 114 | # Log Jobs | |
| 115 | log_section "07" "Jobs" | |
| 116 | log_command_output "Sudo Crontab" "sudo crontab -l" | |
| 117 | log_file_content "/etc/cron.allow" | |
| 118 | ||
| 119 | # Log Security Status | |
| 120 | log_section "08" "Security Status" | |
| 121 | log_command_output "SELinux Status" "sestatus" | |
| 122 | log_command_output "AppArmor Status" "aa-status" | |
| 123 | ||
| 124 | # Log Firewall Rules | |
| 125 | log_section "09" "Firewall Rules" | |
| 126 | log_command_output "Iptables Rules" "sudo iptables -L" | |
| 127 | ||
| 128 | # Log Open Ports | |
| 129 | log_section "10" "Open Ports" | |
| 130 | log_command_output "Netstat" "netstat -tuln" | |
| 131 | ||
| 132 | # Set report ownership | |
| 133 | if [[ $(whoami) == "root" ]]; then | |
| 134 | chown "$SUDO_USER" "$REPORT_FILE" | |
| 135 | fi | |