Commit 7eb1b86bc9
Unsigned
Layout: unified · split
os/linux/README.org +39 −422
| @@ -1,5 +1,44 @@ | |||
| 1 | #+title: Linux | 1 | #+title: Linux |
| 2 | 2 | ||
| 3 | * =report/linux.sh= | ||
| 4 | |||
| 5 | #+begin_src shell | ||
| 6 | ./report/linux.sh | ||
| 7 | #+end_src | ||
| 8 | |||
| 9 | #+begin_src | ||
| 10 | _ ___ _ _ _ ___ __ ___ ____ ____ _____ ____ ___ ____ _____ | ||
| 11 | | | |_ _| \ | | | | \ \/ / / _ \/ ___| | _ \| ____| _ \ / _ \| _ \_ _| | ||
| 12 | | | | || \| | | | |\ / | | | \___ \ | |_) | _| | |_) | | | | |_) || | | ||
| 13 | | |___ | || |\ | |_| |/ \ | |_| |___) | | _ <| |___| __/| |_| | _ < | | | ||
| 14 | |_____|___|_| \_|\___//_/\_\ \___/|____/ |_| \_\_____|_| \___/|_| \_\|_| | ||
| 15 | |||
| 16 | |||
| 17 | |||
| 18 | ========================================== | ||
| 19 | # SECTION 00: Script Info | ||
| 20 | ========================================== | ||
| 21 | Execution Date and Time: Wed May 7 11:35:52 AM CDT 2025 | ||
| 22 | Script Name: ./linux.sh | ||
| 23 | User Running the Script: root (called by: cmc) | ||
| 24 | |||
| 25 | |||
| 26 | |||
| 27 | ========================================== | ||
| 28 | # SECTION 01: System Info | ||
| 29 | ========================================== | ||
| 30 | ## Hostname | ||
| 31 | hera | ||
| 32 | ## Kernel Version | ||
| 33 | 6.14.4-400.asahi.fc42.aarch64+16k | ||
| 34 | ## os-release | ||
| 35 | NAME="Fedora Linux Asahi Remix" | ||
| 36 | VERSION="42 (Forty Two [Adams])" | ||
| 37 | RELEASE_TYPE=stable | ||
| 38 | ID=fedora-asahi-remix | ||
| 39 | ID_LIKE=fedora | ||
| 40 | #+end_src | ||
| 41 | |||
| 3 | * =ssh_root_login.sh= | 42 | * =ssh_root_login.sh= |
| 4 | 43 | ||
| 5 | #+begin_src shell | 44 | #+begin_src shell |
| @@ -22,426 +61,4 @@ Checking /etc/pam.d/system-auth for password parameters... | |||
| 22 | /etc/pam.d/system-auth file not found. | 61 | /etc/pam.d/system-auth file not found. |
| 23 | Analyzing /etc/login.defs... | 62 | Analyzing /etc/login.defs... |
| 24 | Contents of /etc/login.defs: | 63 | Contents of /etc/login.defs: |
| 25 | # | ||
| 26 | # /etc/login.defs - Configuration control definitions for the login package. | ||
| 27 | # | ||
| 28 | # Three items must be defined: MAIL_DIR, ENV_SUPATH, and ENV_PATH. | ||
| 29 | # If unspecified, some arbitrary (and possibly incorrect) value will | ||
| 30 | # be assumed. All other items are optional - if not specified then | ||
| 31 | # the described action or option will be inhibited. | ||
| 32 | # | ||
| 33 | # Comment lines (lines beginning with "#") and blank lines are ignored. | ||
| 34 | # | ||
| 35 | # Modified for Linux. --marekm | ||
| 36 | |||
| 37 | # REQUIRED for useradd/userdel/usermod | ||
| 38 | # Directory where mailboxes reside, _or_ name of file, relative to the | ||
| 39 | # home directory. If you _do_ define MAIL_DIR and MAIL_FILE, | ||
| 40 | # MAIL_DIR takes precedence. | ||
| 41 | # | ||
| 42 | # Essentially: | ||
| 43 | # - MAIL_DIR defines the location of users mail spool files | ||
| 44 | # (for mbox use) by appending the username to MAIL_DIR as defined | ||
| 45 | # below. | ||
| 46 | # - MAIL_FILE defines the location of the users mail spool files as the | ||
| 47 | # fully-qualified filename obtained by prepending the user home | ||
| 48 | # directory before $MAIL_FILE | ||
| 49 | # | ||
| 50 | # NOTE: This is no more used for setting up users MAIL environment variable | ||
| 51 | # which is, starting from shadow 4.0.12-1 in Debian, entirely the | ||
| 52 | # job of the pam_mail PAM modules | ||
| 53 | # See default PAM configuration files provided for | ||
| 54 | # login, su, etc. | ||
| 55 | # | ||
| 56 | # This is a temporary situation: setting these variables will soon | ||
| 57 | # move to /etc/default/useradd and the variables will then be | ||
| 58 | # no more supported | ||
| 59 | MAIL_DIR /var/mail | ||
| 60 | #MAIL_FILE .mail | ||
| 61 | |||
| 62 | # | ||
| 63 | # Enable logging and display of /var/log/faillog login failure info. | ||
| 64 | # This option conflicts with the pam_tally PAM module. | ||
| 65 | # | ||
| 66 | FAILLOG_ENAB yes | ||
| 67 | |||
| 68 | # | ||
| 69 | # Enable display of unknown usernames when login failures are recorded. | ||
| 70 | # | ||
| 71 | # WARNING: Unknown usernames may become world readable. | ||
| 72 | # See #290803 and #298773 for details about how this could become a security | ||
| 73 | # concern | ||
| 74 | LOG_UNKFAIL_ENAB no | ||
| 75 | |||
| 76 | # | ||
| 77 | # Enable logging of successful logins | ||
| 78 | # | ||
| 79 | LOG_OK_LOGINS no | ||
| 80 | |||
| 81 | # | ||
| 82 | # Enable "syslog" logging of su activity - in addition to sulog file logging. | ||
| 83 | # SYSLOG_SG_ENAB does the same for newgrp and sg. | ||
| 84 | # | ||
| 85 | SYSLOG_SU_ENAB yes | ||
| 86 | SYSLOG_SG_ENAB yes | ||
| 87 | |||
| 88 | # | ||
| 89 | # If defined, all su activity is logged to this file. | ||
| 90 | # | ||
| 91 | #SULOG_FILE /var/log/sulog | ||
| 92 | |||
| 93 | # | ||
| 94 | # If defined, file which maps tty line to TERM environment parameter. | ||
| 95 | # Each line of the file is in a format something like "vt100 tty01". | ||
| 96 | # | ||
| 97 | #TTYTYPE_FILE /etc/ttytype | ||
| 98 | |||
| 99 | # | ||
| 100 | # If defined, login failures will be logged here in a utmp format | ||
| 101 | # last, when invoked as lastb, will read /var/log/btmp, so... | ||
| 102 | # | ||
| 103 | FTMP_FILE /var/log/btmp | ||
| 104 | |||
| 105 | # | ||
| 106 | # If defined, the command name to display when running "su -". For | ||
| 107 | # example, if this is defined as "su" then a "ps" will display the | ||
| 108 | # command is "-su". If not defined, then "ps" would display the | ||
| 109 | # name of the shell actually being run, e.g. something like "-sh". | ||
| 110 | # | ||
| 111 | SU_NAME su | ||
| 112 | |||
| 113 | # | ||
| 114 | # If defined, file which inhibits all the usual chatter during the login | ||
| 115 | # sequence. If a full pathname, then hushed mode will be enabled if the | ||
| 116 | # user's name or shell are found in the file. If not a full pathname, then | ||
| 117 | # hushed mode will be enabled if the file exists in the user's home directory. | ||
| 118 | # | ||
| 119 | HUSHLOGIN_FILE .hushlogin | ||
| 120 | #HUSHLOGIN_FILE /etc/hushlogins | ||
| 121 | |||
| 122 | # | ||
| 123 | # *REQUIRED* The default PATH settings, for superuser and normal users. | ||
| 124 | # | ||
| 125 | # (they are minimal, add the rest in the shell startup files) | ||
| 126 | ENV_SUPATH PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin | ||
| 127 | ENV_PATH PATH=/usr/local/bin:/usr/bin:/bin:/usr/local/games:/usr/games | ||
| 128 | |||
| 129 | # | ||
| 130 | # Terminal permissions | ||
| 131 | # | ||
| 132 | # TTYGROUP Login tty will be assigned this group ownership. | ||
| 133 | # TTYPERM Login tty will be set to this permission. | ||
| 134 | # | ||
| 135 | # If you have a "write" program which is "setgid" to a special group | ||
| 136 | # which owns the terminals, define TTYGROUP to the group number and | ||
| 137 | # TTYPERM to 0620. Otherwise leave TTYGROUP commented out and assign | ||
| 138 | # TTYPERM to either 622 or 600. | ||
| 139 | # | ||
| 140 | # In Debian /usr/bin/bsd-write or similar programs are setgid tty | ||
| 141 | # However, the default and recommended value for TTYPERM is still 0600 | ||
| 142 | # to not allow anyone to write to anyone else console or terminal | ||
| 143 | |||
| 144 | # Users can still allow other people to write them by issuing | ||
| 145 | # the "mesg y" command. | ||
| 146 | |||
| 147 | TTYGROUP tty | ||
| 148 | TTYPERM 0600 | ||
| 149 | |||
| 150 | # | ||
| 151 | # Login configuration initializations: | ||
| 152 | # | ||
| 153 | # ERASECHAR Terminal ERASE character ('\010' = backspace). | ||
| 154 | # KILLCHAR Terminal KILL character ('\025' = CTRL/U). | ||
| 155 | # UMASK Default "umask" value. | ||
| 156 | # | ||
| 157 | # The ERASECHAR and KILLCHAR are used only on System V machines. | ||
| 158 | # | ||
| 159 | # UMASK is the default umask value for pam_umask and is used by | ||
| 160 | # useradd and newusers to set the mode of the new home directories. | ||
| 161 | # 022 is the "historical" value in Debian for UMASK | ||
| 162 | # 027, or even 077, could be considered better for privacy | ||
| 163 | # There is no One True Answer here : each sysadmin must make up his/her | ||
| 164 | # mind. | ||
| 165 | # | ||
| 166 | # If USERGROUPS_ENAB is set to "yes", that will modify this UMASK default value | ||
| 167 | # for private user groups, i. e. the uid is the same as gid, and username is | ||
| 168 | # the same as the primary group name: for these, the user permissions will be | ||
| 169 | # used as group permissions, e. g. 022 will become 002. | ||
| 170 | # | ||
| 171 | # Prefix these values with "0" to get octal, "0x" to get hexadecimal. | ||
| 172 | # | ||
| 173 | ERASECHAR 0177 | ||
| 174 | KILLCHAR 025 | ||
| 175 | UMASK 022 | ||
| 176 | |||
| 177 | # HOME_MODE is used by useradd(8) and newusers(8) to set the mode for new | ||
| 178 | # home directories. | ||
| 179 | # If HOME_MODE is not set, the value of UMASK is used to create the mode. | ||
| 180 | HOME_MODE 0750 | ||
| 181 | |||
| 182 | # | ||
| 183 | # Password aging controls: | ||
| 184 | # | ||
| 185 | # PASS_MAX_DAYS Maximum number of days a password may be used. | ||
| 186 | # PASS_MIN_DAYS Minimum number of days allowed between password changes. | ||
| 187 | # PASS_WARN_AGE Number of days warning given before a password expires. | ||
| 188 | # | ||
| 189 | PASS_MAX_DAYS 99999 | ||
| 190 | PASS_MIN_DAYS 0 | ||
| 191 | PASS_WARN_AGE 7 | ||
| 192 | |||
| 193 | # | ||
| 194 | # Min/max values for automatic uid selection in useradd | ||
| 195 | # | ||
| 196 | UID_MIN 1000 | ||
| 197 | UID_MAX 60000 | ||
| 198 | # System accounts | ||
| 199 | #SYS_UID_MIN 100 | ||
| 200 | #SYS_UID_MAX 999 | ||
| 201 | # Extra per user uids | ||
| 202 | SUB_UID_MIN 100000 | ||
| 203 | SUB_UID_MAX 600100000 | ||
| 204 | SUB_UID_COUNT 65536 | ||
| 205 | |||
| 206 | # | ||
| 207 | # Min/max values for automatic gid selection in groupadd | ||
| 208 | # | ||
| 209 | GID_MIN 1000 | ||
| 210 | GID_MAX 60000 | ||
| 211 | # System accounts | ||
| 212 | #SYS_GID_MIN 100 | ||
| 213 | #SYS_GID_MAX 999 | ||
| 214 | # Extra per user group ids | ||
| 215 | SUB_GID_MIN 100000 | ||
| 216 | SUB_GID_MAX 600100000 | ||
| 217 | SUB_GID_COUNT 65536 | ||
| 218 | |||
| 219 | # | ||
| 220 | # Max number of login retries if password is bad. This will most likely be | ||
| 221 | # overriden by PAM, since the default pam_unix module has it's own built | ||
| 222 | # in of 3 retries. However, this is a safe fallback in case you are using | ||
| 223 | # an authentication module that does not enforce PAM_MAXTRIES. | ||
| 224 | # | ||
| 225 | LOGIN_RETRIES 5 | ||
| 226 | |||
| 227 | # | ||
| 228 | # Max time in seconds for login | ||
| 229 | # | ||
| 230 | LOGIN_TIMEOUT 60 | ||
| 231 | |||
| 232 | # | ||
| 233 | # Which fields may be changed by regular users using chfn - use | ||
| 234 | # any combination of letters "frwh" (full name, room number, work | ||
| 235 | # phone, home phone). If not defined, no changes are allowed. | ||
| 236 | # For backward compatibility, "yes" = "rwh" and "no" = "frwh". | ||
| 237 | # | ||
| 238 | CHFN_RESTRICT rwh | ||
| 239 | |||
| 240 | # | ||
| 241 | # Should login be allowed if we can't cd to the home directory? | ||
| 242 | # Default is no. | ||
| 243 | # | ||
| 244 | DEFAULT_HOME yes | ||
| 245 | |||
| 246 | # | ||
| 247 | # If defined, this command is run when removing a user. | ||
| 248 | # It should remove any at/cron/print jobs etc. owned by | ||
| 249 | # the user to be removed (passed as the first argument). | ||
| 250 | # | ||
| 251 | #USERDEL_CMD /usr/sbin/userdel_local | ||
| 252 | |||
| 253 | # | ||
| 254 | # Enable setting of the umask group bits to be the same as owner bits | ||
| 255 | # (examples: 022 -> 002, 077 -> 007) for non-root users, if the uid is | ||
| 256 | # the same as gid, and username is the same as the primary group name. | ||
| 257 | # | ||
| 258 | # If set to yes, userdel will remove the user's group if it contains no | ||
| 259 | # more members, and useradd will create by default a group with the name | ||
| 260 | # of the user. | ||
| 261 | # | ||
| 262 | USERGROUPS_ENAB yes | ||
| 263 | |||
| 264 | # | ||
| 265 | # Instead of the real user shell, the program specified by this parameter | ||
| 266 | # will be launched, although its visible name (argv[0]) will be the shell's. | ||
| 267 | # The program may do whatever it wants (logging, additional authentification, | ||
| 268 | # banner, ...) before running the actual shell. | ||
| 269 | # | ||
| 270 | # FAKE_SHELL /bin/fakeshell | ||
| 271 | |||
| 272 | # | ||
| 273 | # If defined, either full pathname of a file containing device names or | ||
| 274 | # a ":" delimited list of device names. Root logins will be allowed only | ||
| 275 | # upon these devices. | ||
| 276 | # | ||
| 277 | # This variable is used by login and su. | ||
| 278 | # | ||
| 279 | #CONSOLE /etc/consoles | ||
| 280 | #CONSOLE console:tty01:tty02:tty03:tty04 | ||
| 281 | |||
| 282 | # | ||
| 283 | # List of groups to add to the user's supplementary group set | ||
| 284 | # when logging in on the console (as determined by the CONSOLE | ||
| 285 | # setting). Default is none. | ||
| 286 | # | ||
| 287 | # Use with caution - it is possible for users to gain permanent | ||
| 288 | # access to these groups, even when not logged in on the console. | ||
| 289 | # How to do it is left as an exercise for the reader... | ||
| 290 | # | ||
| 291 | # This variable is used by login and su. | ||
| 292 | # | ||
| 293 | #CONSOLE_GROUPS floppy:audio:cdrom | ||
| 294 | |||
| 295 | # | ||
| 296 | # If set to "yes", new passwords will be encrypted using the MD5-based | ||
| 297 | # algorithm compatible with the one used by recent releases of FreeBSD. | ||
| 298 | # It supports passwords of unlimited length and longer salt strings. | ||
| 299 | # Set to "no" if you need to copy encrypted passwords to other systems | ||
| 300 | # which don't understand the new algorithm. Default is "no". | ||
| 301 | # | ||
| 302 | # This variable is deprecated. You should use ENCRYPT_METHOD. | ||
| 303 | # | ||
| 304 | #MD5_CRYPT_ENAB no | ||
| 305 | |||
| 306 | # | ||
| 307 | # If set to MD5, MD5-based algorithm will be used for encrypting password | ||
| 308 | # If set to SHA256, SHA256-based algorithm will be used for encrypting password | ||
| 309 | # If set to SHA512, SHA512-based algorithm will be used for encrypting password | ||
| 310 | # If set to BCRYPT, BCRYPT-based algorithm will be used for encrypting password | ||
| 311 | # If set to YESCRYPT, YESCRYPT-based algorithm will be used for encrypting password | ||
| 312 | # If set to DES, DES-based algorithm will be used for encrypting password (default) | ||
| 313 | # MD5 and DES should not be used for new hashes, see crypt(5) for recommendations. | ||
| 314 | # Overrides the MD5_CRYPT_ENAB option | ||
| 315 | # | ||
| 316 | # Note: It is recommended to use a value consistent with | ||
| 317 | # the PAM modules configuration. | ||
| 318 | # | ||
| 319 | ENCRYPT_METHOD SHA512 | ||
| 320 | |||
| 321 | # | ||
| 322 | # Only works if ENCRYPT_METHOD is set to SHA256 or SHA512. | ||
| 323 | # | ||
| 324 | # Define the number of SHA rounds. | ||
| 325 | # With a lot of rounds, it is more difficult to brute-force the password. | ||
| 326 | # However, more CPU resources will be needed to authenticate users if | ||
| 327 | # this value is increased. | ||
| 328 | # | ||
| 329 | # If not specified, the libc will choose the default number of rounds (5000), | ||
| 330 | # which is orders of magnitude too low for modern hardware. | ||
| 331 | # The values must be within the 1000-999999999 range. | ||
| 332 | # If only one of the MIN or MAX values is set, then this value will be used. | ||
| 333 | # If MIN > MAX, the highest value will be used. | ||
| 334 | # | ||
| 335 | #SHA_CRYPT_MIN_ROUNDS 5000 | ||
| 336 | #SHA_CRYPT_MAX_ROUNDS 5000 | ||
| 337 | |||
| 338 | # | ||
| 339 | # Only works if ENCRYPT_METHOD is set to YESCRYPT. | ||
| 340 | # | ||
| 341 | # Define the YESCRYPT cost factor. | ||
| 342 | # With a higher cost factor, it is more difficult to brute-force the password. | ||
| 343 | # However, more CPU time and more memory will be needed to authenticate users | ||
| 344 | # if this value is increased. | ||
| 345 | # | ||
| 346 | # If not specified, a cost factor of 5 will be used. | ||
| 347 | # The value must be within the 1-11 range. | ||
| 348 | # | ||
| 349 | #YESCRYPT_COST_FACTOR 5 | ||
| 350 | |||
| 351 | # | ||
| 352 | # The pwck(8) utility emits a warning for any system account with a home | ||
| 353 | # directory that does not exist. Some system accounts intentionally do | ||
| 354 | # not have a home directory. Such accounts may have this string as | ||
| 355 | # their home directory in /etc/passwd to avoid a spurious warning. | ||
| 356 | # | ||
| 357 | NONEXISTENT /nonexistent | ||
| 358 | |||
| 359 | # | ||
| 360 | # Allow newuidmap and newgidmap when running under an alternative | ||
| 361 | # primary group. | ||
| 362 | # | ||
| 363 | #GRANT_AUX_GROUP_SUBIDS yes | ||
| 364 | |||
| 365 | # | ||
| 366 | # Select the HMAC cryptography algorithm. | ||
| 367 | # Used in pam_timestamp module to calculate the keyed-hash message | ||
| 368 | # authentication code. | ||
| 369 | # | ||
| 370 | # Note: It is recommended to check hmac(3) to see the possible algorithms | ||
| 371 | # that are available in your system. | ||
| 372 | # | ||
| 373 | #HMAC_CRYPTO_ALGO SHA512 | ||
| 374 | |||
| 375 | ################# OBSOLETED BY PAM ############## | ||
| 376 | # # | ||
| 377 | # These options are now handled by PAM. Please # | ||
| 378 | # edit the appropriate file in /etc/pam.d/ to # | ||
| 379 | # enable the equivelants of them. | ||
| 380 | # | ||
| 381 | ############### | ||
| 382 | |||
| 383 | #MOTD_FILE | ||
| 384 | #DIALUPS_CHECK_ENAB | ||
| 385 | #LASTLOG_ENAB | ||
| 386 | #MAIL_CHECK_ENAB | ||
| 387 | #OBSCURE_CHECKS_ENAB | ||
| 388 | #PORTTIME_CHECKS_ENAB | ||
| 389 | #SU_WHEEL_ONLY | ||
| 390 | #CRACKLIB_DICTPATH | ||
| 391 | #PASS_CHANGE_TRIES | ||
| 392 | #PASS_ALWAYS_WARN | ||
| 393 | #ENVIRON_FILE | ||
| 394 | #NOLOGINS_FILE | ||
| 395 | #ISSUE_FILE | ||
| 396 | #PASS_MIN_LEN | ||
| 397 | #PASS_MAX_LEN | ||
| 398 | #ULIMIT | ||
| 399 | #ENV_HZ | ||
| 400 | #CHFN_AUTH | ||
| 401 | #CHSH_AUTH | ||
| 402 | #FAIL_DELAY | ||
| 403 | |||
| 404 | ################# OBSOLETED ####################### | ||
| 405 | # # | ||
| 406 | # These options are no more handled by shadow. # | ||
| 407 | # # | ||
| 408 | # Shadow utilities will display a warning if they # | ||
| 409 | # still appear. # | ||
| 410 | # # | ||
| 411 | ################################################### | ||
| 412 | |||
| 413 | # CLOSE_SESSIONS | ||
| 414 | # LOGIN_STRING | ||
| 415 | # NO_PASSWORD_CONSOLE | ||
| 416 | # QMAIL_DIR | ||
| 417 | |||
| 418 | |||
| 419 | |||
| 420 | |||
| 421 | Login restrictions and parameters in /etc/login.defs: | ||
| 422 | # PASS_MAX_DAYS Maximum number of days a password may be used. | ||
| 423 | # PASS_MIN_DAYS Minimum number of days allowed between password changes. | ||
| 424 | # PASS_WARN_AGE Number of days warning given before a password expires. | ||
| 425 | PASS_MAX_DAYS 99999 | ||
| 426 | PASS_MIN_DAYS 0 | ||
| 427 | PASS_WARN_AGE 7 | ||
| 428 | UID_MIN 1000 | ||
| 429 | UID_MAX 60000 | ||
| 430 | #SYS_UID_MIN 100 | ||
| 431 | #SYS_UID_MAX 999 | ||
| 432 | SUB_UID_MIN 100000 | ||
| 433 | SUB_UID_MAX 600100000 | ||
| 434 | SUB_UID_COUNT 65536 | ||
| 435 | GID_MIN 1000 | ||
| 436 | GID_MAX 60000 | ||
| 437 | #SYS_GID_MIN 100 | ||
| 438 | #SYS_GID_MAX 999 | ||
| 439 | SUB_GID_MIN 100000 | ||
| 440 | SUB_GID_MAX 600100000 | ||
| 441 | SUB_GID_COUNT 65536 | ||
| 442 | LOGIN_RETRIES 5 | ||
| 443 | LOGIN_TIMEOUT 60 | ||
| 444 | #PASS_MIN_LEN | ||
| 445 | |||
| 446 | Analysis complete. | ||
| 447 | #+end_src | 64 | #+end_src |
os/linux/passwords.sh
os/linux/report/linux.sh added +135
| @@ -0,0 +1,135 @@ | |||
| 1 | #!/bin/bash | ||
| 2 | |||
| 3 | # Default report file | ||
| 4 | REPORT_FILE="report.txt" | ||
| 5 | TRIM_COMMENTS=false | ||
| 6 | |||
| 7 | # Function to log section header | ||
| 8 | log_section() { | ||
| 9 | echo -e "\n\n" >> "$REPORT_FILE" | ||
| 10 | echo "==========================================" >> "$REPORT_FILE" | ||
| 11 | echo "# SECTION $1: $2" >> "$REPORT_FILE" | ||
| 12 | echo "==========================================" >> "$REPORT_FILE" | ||
| 13 | } | ||
| 14 | |||
| 15 | # Function to log file content | ||
| 16 | log_file_content() { | ||
| 17 | FILE_PATH="$1" | ||
| 18 | FILE_NAME=$(basename "$FILE_PATH") | ||
| 19 | echo "## $FILE_NAME" >> "$REPORT_FILE" | ||
| 20 | if [[ -f $FILE_PATH ]]; then | ||
| 21 | if $TRIM_COMMENTS; then | ||
| 22 | # Trim comments (lines starting with # or empty lines) | ||
| 23 | grep -vE '^\s*#|^\s*$' "$FILE_PATH" >> "$REPORT_FILE" | ||
| 24 | else | ||
| 25 | cat "$FILE_PATH" >> "$REPORT_FILE" | ||
| 26 | fi | ||
| 27 | else | ||
| 28 | echo "File $FILE_PATH not found!" >> "$REPORT_FILE" | ||
| 29 | fi | ||
| 30 | } | ||
| 31 | |||
| 32 | # Function to log command output | ||
| 33 | log_command_output() { | ||
| 34 | echo "## $1" >> "$REPORT_FILE" | ||
| 35 | $2 >> "$REPORT_FILE" 2>&1 | ||
| 36 | } | ||
| 37 | |||
| 38 | # Check for sudo privileges | ||
| 39 | if [[ $EUID -ne 0 ]]; then | ||
| 40 | echo "This script requires sudo privileges. Please enter your password." | ||
| 41 | exec sudo "$0" "$@" | ||
| 42 | fi | ||
| 43 | |||
| 44 | # Parse command-line arguments | ||
| 45 | while getopts "t" opt; do | ||
| 46 | case $opt in | ||
| 47 | t) | ||
| 48 | TRIM_COMMENTS=true | ||
| 49 | REPORT_FILE="report_trimmed.txt" | ||
| 50 | ;; | ||
| 51 | *) | ||
| 52 | echo "Usage: $0 [-t] # Use -t to trim comments from files" | ||
| 53 | exit 1 | ||
| 54 | ;; | ||
| 55 | esac | ||
| 56 | done | ||
| 57 | |||
| 58 | # Initialize report file | ||
| 59 | > "$REPORT_FILE" # Clear the file if it exists | ||
| 60 | |||
| 61 | # ASCII Header | ||
| 62 | cat << "EOF" >> "$REPORT_FILE" | ||
| 63 | _ ___ _ _ _ ___ __ ___ ____ ____ _____ ____ ___ ____ _____ | ||
| 64 | | | |_ _| \ | | | | \ \/ / / _ \/ ___| | _ \| ____| _ \ / _ \| _ \_ _| | ||
| 65 | | | | || \| | | | |\ / | | | \___ \ | |_) | _| | |_) | | | | |_) || | | ||
| 66 | | |___ | || |\ | |_| |/ \ | |_| |___) | | _ <| |___| __/| |_| | _ < | | | ||
| 67 | |_____|___|_| \_|\___//_/\_\ \___/|____/ |_| \_\_____|_| \___/|_| \_\|_| | ||
| 68 | EOF | ||
| 69 | |||
| 70 | # Log Script Info | ||
| 71 | log_section "00" "Script Info" | ||
| 72 | echo "Execution Date and Time: $(date)" >> "$REPORT_FILE" | ||
| 73 | echo "Script Name: $0" >> "$REPORT_FILE" | ||
| 74 | |||
| 75 | if [[ $(whoami) == "root" ]]; then | ||
| 76 | echo "User Running the Script: root (called by: $SUDO_USER)" >> "$REPORT_FILE" | ||
| 77 | else | ||
| 78 | echo "User Running the Script: $(whoami)" >> "$REPORT_FILE" | ||
| 79 | fi | ||
| 80 | |||
| 81 | # Log System Info | ||
| 82 | log_section "01" "System Info" | ||
| 83 | log_command_output "Hostname" "hostname" | ||
| 84 | log_command_output "Kernel Version" "uname -r" | ||
| 85 | log_file_content "/etc/os-release" | ||
| 86 | log_command_output "IP Address" "hostname -I" | ||
| 87 | |||
| 88 | # Log Password Parameters | ||
| 89 | log_section "02" "Password Parameters" | ||
| 90 | log_file_content "/etc/pam.d/system-auth" | ||
| 91 | log_file_content "/etc/login.defs" | ||
| 92 | |||
| 93 | # Log Users | ||
| 94 | log_section "03" "Users" | ||
| 95 | log_file_content "/etc/passwd" | ||
| 96 | log_file_content "/etc/group" | ||
| 97 | |||
| 98 | # Log Admins | ||
| 99 | log_section "04" "Admins" | ||
| 100 | log_file_content "/etc/sudoers" | ||
| 101 | log_command_output "Sudo Group" "getent group sudo" | ||
| 102 | log_command_output "Wheel Group" "getent group wheel" | ||
| 103 | log_command_output "Root User" "getent passwd 0" | ||
| 104 | |||
| 105 | # Log SSH Configuration | ||
| 106 | log_section "05" "SSH Configuration" | ||
| 107 | log_file_content "/etc/ssh/sshd_config" | ||
| 108 | |||
| 109 | # Log Logging Configuration | ||
| 110 | log_section "06" "Logging Configuration" | ||
| 111 | log_file_content "/etc/syslog.conf" | ||
| 112 | log_file_content "/etc/logrotate.conf" | ||
| 113 | |||
| 114 | # Log Jobs | ||
| 115 | log_section "07" "Jobs" | ||
| 116 | log_command_output "Sudo Crontab" "sudo crontab -l" | ||
| 117 | log_file_content "/etc/cron.allow" | ||
| 118 | |||
| 119 | # Log Security Status | ||
| 120 | log_section "08" "Security Status" | ||
| 121 | log_command_output "SELinux Status" "sestatus" | ||
| 122 | log_command_output "AppArmor Status" "aa-status" | ||
| 123 | |||
| 124 | # Log Firewall Rules | ||
| 125 | log_section "09" "Firewall Rules" | ||
| 126 | log_command_output "Iptables Rules" "sudo iptables -L" | ||
| 127 | |||
| 128 | # Log Open Ports | ||
| 129 | log_section "10" "Open Ports" | ||
| 130 | log_command_output "Netstat" "netstat -tuln" | ||
| 131 | |||
| 132 | # Set report ownership | ||
| 133 | if [[ $(whoami) == "root" ]]; then | ||
| 134 | chown "$SUDO_USER" "$REPORT_FILE" | ||
| 135 | fi | ||