abclinuxu.cz AbcLinuxu.cz itbiz.cz ITBiz.cz HDmag.cz HDmag.cz abcprace.cz AbcPráce.cz
AbcLinuxu hledá autory!
Inzerujte na AbcPráce.cz od 950 Kč
Rozšířené hledání
×
    včera 11:55 | IT novinky

    Ministerstvo průmyslu a obchodu propaguje Microsoft. Ten ve spolupráci s Ministerstvem průmyslu a obchodu spouští AI National Skilling Plan v ČR. "Iniciativa Microsoftu přináší konkrétní a praktickou podporu právě tam, kde ji nejvíc potřebujeme – do škol, firem i veřejné správy.", říká ministr průmyslu a obchodu Lukáš Vlček.

    Ladislav Hagara | Komentářů: 10
    včera 10:55 | Zajímavý projekt

    Jste český ISP? Vyplněním krátkého dotazníku můžete pomoci nasměrovat vývoj nové generace routerů Turris Omnia [𝕏].

    Ladislav Hagara | Komentářů: 4
    včera 01:33 | IT novinky

    Celkové tržby společnosti Canonical za rok 2024 byly 292 milionů dolarů (pdf). Za rok 2023 to bylo 251 milionů dolarů.

    Ladislav Hagara | Komentářů: 1
    včera 01:22 | Nová verze

    Byla vydána verze 1.88.0 programovacího jazyka Rust (Wikipedie). Podrobnosti v poznámkách k vydání. Vyzkoušet Rust lze například na stránce Rust by Example.

    Ladislav Hagara | Komentářů: 0
    včera 01:11 | Nová verze

    Distribuce Tails specializující se ochranu online soukromí uživatele byla vydána ve verzi 6.17. Mimo jiné aktualizuje Tor Browser (14.5.4) a opravuje několik chyb.

    Fluttershy, yay! | Komentářů: 0
    26.6. 21:11 | Nová verze Ladislav Hagara | Komentářů: 0
    26.6. 13:11 | IT novinky

    Město Lyon posiluje svou digitální suverenitu a postupně nahrazuje software od společnosti Microsoft bezplatnými alternativami, zejména OnlyOffice pro kancelářské aplikace a Linux a PostgreSQL pro systémy a databáze.

    Ladislav Hagara | Komentářů: 9
    26.6. 11:44 | Zajímavý projekt

    Evropská občanská iniciativa Stop Destroying Videogames se snaží o to, aby vydavatelé, kteří spotřebitelům v Evropské unii prodávají videohry nebo na ně udělují licence, měli povinnost tyto hry ponechat ve funkčním (hratelném) stavu i po ukončení podpory ze své strany. Podpořit podpisem tuto iniciativu můžete v Systému pro online sběr podpisů.

    trekker.dk | Komentářů: 5
    26.6. 11:22 | Komunita

    Mozilla oficiálně ukončila svůj již několik let mrtvý projekt DeepSpeech pro převod řeči na text.

    Ladislav Hagara | Komentářů: 2
    26.6. 05:22 | Komunita

    Krátce po oficiálním oznámení forku X.Org Xserveru s názvem XLibre Xserver byl ve Fedoře předložen návrh, aby byl X.Org Xserver nahrazen tímto XLibre Xserverem. Po krátké ale intenzivní diskusi byl návrh stažen.

    Ladislav Hagara | Komentářů: 25
    Jaký je váš oblíbený skriptovací jazyk?
     (59%)
     (28%)
     (7%)
     (2%)
     (0%)
     (1%)
     (3%)
    Celkem 321 hlasů
     Komentářů: 16, poslední 8.6. 21:05
    Rozcestník

    Administrace komentářů

    Jste na stránce určené pro řešení chyb a problémů týkajících se diskusí a komentářů. Můžete zde našim administrátorům reportovat špatně zařazenou či duplicitní diskusi, vulgární či osočující příspěvek a podobně. Děkujeme vám za vaši pomoc, více očí více vidí, společně můžeme udržet vysokou kvalitu AbcLinuxu.cz.

    Příspěvek
    25.8.2017 10:02 Pfemir | skóre: 5
    Rozbalit Rozbalit vše Re: Vzdálené spouštění procesů.
    Tak jsem to projel maldetecem, trvalo to asi 14hodin a našlo to 2 hity. V reportu je:
    HOST:      pfemir.cz
    SCAN ID:   170824-1932.6655
    STARTED:   srp 24 2017 19:32:25 +0200
    COMPLETED: srp 25 2017 09:18:15 +0200
    ELAPSED:   49550s [find: 44s]
    
    PATH:          /home
    TOTAL FILES:   185970
    TOTAL HITS:    2
    TOTAL CLEANED: 0
    
    WARNING: Automatic quarantine is currently disabled, detected threats are still accessible to users!
    To enable, set quarantine_hits=1 and/or to quarantine hits from this scan run:
    /usr/local/sbin/maldet -q 170824-1932.6655
    
    FILE HIT LIST:
    {HEX}gzbase64.inject.unclassed.15 : /home/pfemir/maldetect-1.6.2/files/clean/gzbase64.inject.unclassed
    {HEX}gzbase64.inject.unclassed.15 : /home/pfemir/maldetect-1.6.2/files/sigs/rfxn.yara
    ===============================================
    Linux Malware Detect v1.6.2 < proj@rfxn.com >
    
    a z toho jsem nepochopil co a kde vlastně našel.

    Lynis proběhl poměrně rychle. Jestli jsem to správně pochopil, tak nekotroluje soubory, ale nastavení systému. Několik warningu tam je, ale moc tomu nerozumím. Mohl by se na to, prosím někdo mrknout?
    [ Lynis 2.5.3 ]
    
    ################################################################################
      Lynis comes with ABSOLUTELY NO WARRANTY. This is free software, and you are
      welcome to redistribute it under the terms of the GNU General Public License.
      See the LICENSE file for details about using this software.
    
      2007-2017, CISOfy - https://cisofy.com/lynis/
      Enterprise support available (compliance, plugins, interface and tools)
    ################################################################################
    
    
    [+] Initializing program
    ------------------------------------
    
      ###################################################################
      #                                                                 #
      #   NON-PRIVILEGED SCAN MODE                                      #
      #                                                                 #
      ###################################################################
    
      NOTES:
      --------------
      * Some tests will be skipped (as they require root permissions)
      * Some tests might fail silently or give different results
    
      - Detecting OS...                                           [ DONE ]
      - Checking profiles...                                      [ DONE ]
      - Detecting language and localization                       [ cs ]
        Notice: no language file found for 'cs' (tried: /usr/local/lynis/lynis/db/la                                                                                                                     nguages/cs)
    
      ---------------------------------------------------
      Program version:           2.5.3
      Operating system:          Linux
      Operating system name:     Debian
      Operating system version:  jessie/sid
      Kernel version:            3.12.1
      Hardware platform:         x86_64
      Hostname:                  pfemir
      ---------------------------------------------------
      Profiles:                  /usr/local/lynis/lynis/default.prf
      Log file:                  /tmp/lynis.log
      Report file:               /tmp/lynis-report.dat
      Report version:            1.0
      Plugin directory:          ./plugins
      ---------------------------------------------------
      Auditor:                   [Not Specified]
      Test category:             all
      Test group:                all
      ---------------------------------------------------
      - Program update status...                                  [ NO UPDATE ]
    
    [+] System Tools
    ------------------------------------
      - Scanning available tools...
      - Checking system binaries...
    
    [+] Plugins (phase 1)
    ------------------------------------
     Note: plugins have more extensive tests and may take several minutes to complete
    
      - Plugins enabled                                           [ NONE ]
    
    [+] Boot and services
    ------------------------------------
      - Service Manager                                           [ SysV Init ]
      - Checking presence GRUB2                                   [ FOUND ]
        - Checking for password protection                        [ WARNING ]
      - Check services at startup (rc2.d)                         [ DONE ]
        Result: found 54 services
      - Check startup files (permissions)                         [ OK ]
    
    [+] Kernel
    ------------------------------------
      - Checking default run level                                [ 2 ]
      - Checking CPU support (NX/PAE)
        CPU support: PAE and/or NoeXecute supported               [ FOUND ]
      - Checking kernel version and release                       [ DONE ]
      - Checking kernel type                                      [ DONE ]
      - Checking loaded kernel modules                            [ DONE ]
          Found 59 active modules
      - Checking Linux kernel configuration file                  [ FOUND ]
      - Checking default I/O kernel scheduler                     [ FOUND ]
      - Checking for available kernel update                      [ OK ]
      - Checking core dumps configuration                         [ DISABLED ]
        - Checking setuid core dumps configuration                [ DEFAULT ]
      - Check if reboot is needed                                 [ NO ]
    
    [+] Memory and Processes
    ------------------------------------
      - Checking /proc/meminfo                                    [ FOUND ]
      - Searching for dead/zombie processes                       [ OK ]
      - Searching for IO waiting processes                        [ OK ]
    
    [+] Users, Groups and Authentication
    ------------------------------------
      - Administrator accounts                                    [ OK ]
      - Unique UIDs                                               [ OK ]
      - Unique group IDs                                          [ OK ]
      - Unique group names                                        [ OK ]
      - Password file consistency                                 [ SUGGESTION ]
      - Query system users (non daemons)                          [ DONE ]
      - NIS+ authentication support                               [ NOT ENABLED ]
      - NIS authentication support                                [ NOT ENABLED ]
      - sudoers file                                              [ FOUND ]
        - Check sudoers file permissions                          [ OK ]
      - PAM password strength tools                               [ SUGGESTION ]
      - PAM configuration files (pam.conf)                        [ FOUND ]
      - PAM configuration files (pam.d)                           [ FOUND ]
      - PAM modules                                               [ FOUND ]
      - LDAP module in PAM                                        [ NOT FOUND ]
      - Accounts without expire date                              [ OK ]
      - Accounts without password                                 [ OK ]
      - Checking user password aging (minimum)                    [ DISABLED ]
      - User password aging (maximum)                             [ DISABLED ]
      - Checking Linux single user mode authentication            [ OK ]
      - Determining default umask
        - umask (/etc/profile)                                    [ NOT FOUND ]
        - umask (/etc/login.defs)                                 [ SUGGESTION ]
        - umask (/etc/init.d/rc)                                  [ SUGGESTION ]
      - LDAP authentication support                               [ NOT ENABLED ]
      - Logging failed login attempts                             [ ENABLED ]
    
    [+] Shells
    ------------------------------------
      - Checking shells from /etc/shells
        Result: found 13 shells (valid shells: 7).
        - Session timeout settings/tools                          [ NONE ]
      - Checking default umask values
        - Checking default umask in /etc/bash.bashrc              [ NONE ]
        - Checking default umask in /etc/profile                  [ NONE ]
    
    [+] File systems
    ------------------------------------
      - Checking mount points
        - Checking /home mount point                              [ SUGGESTION ]
        - Checking /tmp mount point                               [ SUGGESTION ]
        - Checking /var mount point                               [ SUGGESTION ]
      - Query swap partitions (fstab)                             [ OK ]
      - Testing swap partitions                                   [ OK ]
      - Testing /proc mount (hidepid)                             [ SUGGESTION ]
      - Checking for old files in /tmp                            [ OK ]
      - Checking /tmp sticky bit                                  [ OK ]
      - Mount options of /                                        [ NON DEFAULT ]
      - Checking Locate database                                  [ FOUND ]
      - Disable kernel support of some filesystems
        - Discovered kernel modules: cramfs freevxfs hfs hfsplus jffs2 squashfs udf
    
    [+] Storage
    ------------------------------------
      - Checking usb-storage driver (modprobe config)             [ NOT DISABLED ]
      - Checking USB devices authorization                        [ ENABLED ]
      - Checking firewire ohci driver (modprobe config)           [ NOT DISABLED ]
    
    [+] NFS
    ------------------------------------
      - Query rpc registered programs                             [ DONE ]
      - Query NFS versions                                        [ DONE ]
      - Query NFS protocols                                       [ DONE ]
      - Check running NFS daemon                                  [ FOUND ]
        - Checking /etc/exports                                   [ FOUND ]
        - Checking NFS client access                              [ OK ]
    
    [+] Name services
    ------------------------------------
      - Checking default DNS search domain                        [ FOUND ]
      - Searching DNS domain name                                 [ FOUND ]
          Domain name: cz
      - Checking nscd status                                      [ RUNNING ]
      - Checking /etc/hosts
        - Checking /etc/hosts (duplicates)                        [ OK ]
        - Checking /etc/hosts (hostname)                          [ OK ]
        - Checking /etc/hosts (localhost)                         [ SUGGESTION ]
        - Checking /etc/hosts (localhost to IP)                   [ OK ]
    
    [+] Ports and packages
    ------------------------------------
      - Searching package managers
        - Searching dpkg package manager                          [ FOUND ]
          - Querying package manager
        - Query unpurged packages                                 [ FOUND ]
      - Checking security repository in sources.list file or directory  [ WARNING ]
      - Checking package audit tool                               [ NONE ]
    
    [+] Networking
    ------------------------------------
      - Checking IPv6 configuration                               [ DISABLED ]
      - Checking configured nameservers
        - Testing nameservers
            Nameserver: 77.242.95.2                               [ OK ]
            Nameserver: 192.168.1.1                               [ OK ]
        - Minimal of 2 responsive nameservers                     [ OK ]
      - Checking default gateway                                  [ DONE ]
      - Getting listening ports (TCP/UDP)                         [ DONE ]
          * Found 80 ports
      - Checking promiscuous interfaces                           [ OK ]
      - Checking waiting connections                              [ OK ]
      - Checking status DHCP client                               [ NOT ACTIVE ]
      - Checking for ARP monitoring software                      [ NOT FOUND ]
    
    [+] Printers and Spools
    ------------------------------------
      - Checking cups daemon                                      [ RUNNING ]
      - Checking CUPS configuration file                          [ NOT FOUND ]
      - Checking lp daemon                                        [ NOT RUNNING ]
    
    [+] Software: e-mail and messaging
    ------------------------------------
      - Postfix status                                            [ RUNNING ]
        - Postfix configuration                                   [ FOUND ]
          - Postfix configuration errors                          [ WARNING ]
          - Postfix banner                                        [ WARNING ]
      - Dovecot status                                            [ RUNNING ]
    
    [+] Software: firewalls
    ------------------------------------
      - Checking iptables kernel module                           [ FOUND ]
      - Checking host based firewall                              [ ACTIVE ]
    
    [+] Software: webserver
    ------------------------------------
      - Checking Apache (binary /usr/sbin/apache2)                [ FOUND ]
          Info: Found 6 virtual hosts
        * Loadable modules                                        [ FOUND (107) ]
            - Found 107 loadable modules
              mod_evasive: anti-DoS/brute force                   [ NOT FOUND ]
              mod_reqtimeout/mod_qos                              [ FOUND ]
              ModSecurity: web application firewall               [ NOT FOUND ]
      - Checking nginx                                            [ NOT FOUND ]
    
    [+] SSH Support
    ------------------------------------
      - Checking running SSH daemon                               [ FOUND ]
        - Searching SSH configuration                             [ FOUND ]
        - SSH option: AllowTcpForwarding                          [ SUGGESTION ]
        - SSH option: ClientAliveCountMax                         [ SUGGESTION ]
        - SSH option: ClientAliveInterval                         [ OK ]
        - SSH option: Compression                                 [ SUGGESTION ]
        - SSH option: FingerprintHash                             [ NOT FOUND ]
        - SSH option: GatewayPorts                                [ OK ]
        - SSH option: IgnoreRhosts                                [ OK ]
        - SSH option: LoginGraceTime                              [ OK ]
        - SSH option: LogLevel                                    [ SUGGESTION ]
        - SSH option: MaxAuthTries                                [ SUGGESTION ]
        - SSH option: MaxSessions                                 [ SUGGESTION ]
        - SSH option: PermitRootLogin                             [ SUGGESTION ]
        - SSH option: PermitUserEnvironment                       [ OK ]
        - SSH option: PermitTunnel                                [ OK ]
        - SSH option: Port                                        [ SUGGESTION ]
        - SSH option: PrintLastLog                                [ OK ]
        - SSH option: Protocol                                    [ OK ]
        - SSH option: StrictModes                                 [ OK ]
        - SSH option: TCPKeepAlive                                [ SUGGESTION ]
        - SSH option: UseDNS                                      [ SUGGESTION ]
        - SSH option: VerifyReverseMapping                        [ NOT FOUND ]
        - SSH option: X11Forwarding                               [ SUGGESTION ]
        - SSH option: AllowAgentForwarding                        [ NOT FOUND ]
        - SSH option: AllowUsers                                  [ NOT FOUND ]
        - SSH option: AllowGroups                                 [ NOT FOUND ]
    
    [+] SNMP Support
    ------------------------------------
      - Checking running SNMP daemon                              [ NOT FOUND ]
    
    [+] Databases
    ------------------------------------
      - MySQL process status                                      [ FOUND ]
    
    [+] LDAP Services
    ------------------------------------
      - Checking OpenLDAP instance                                [ NOT FOUND ]
    
    [+] PHP
    ------------------------------------
      - Checking PHP                                              [ FOUND ]
        - Checking PHP disabled functions                         [ FOUND ]
        - Checking expose_php option                              [ ON ]
        - Checking enable_dl option                               [ OFF ]
        - Checking allow_url_fopen option                         [ ON ]
        - Checking allow_url_include option                       [ OFF ]
        - Checking PHP suhosin extension status                   [ WARNING ]
          - Suhosin simulation mode status                        [ WARNING ]
    
    [+] Squid Support
    ------------------------------------
      - Checking running Squid daemon                             [ FOUND ]
        - Searching Squid configuration                           [ FOUND ]
        - Checking Squid version                                  [ FOUND ]
    /bin/grep: /etc/squid/squid.conf: Permission denied
        - Checking defined Squid options                          [ DONE ]
        - Checking Squid configuration file permissions           [ OK ]
        - Checking Squid access control
    /bin/grep: /etc/squid/squid.conf: Permission denied
          - Checking Squid authentication methods                 [ NONE ]
    /bin/grep: /etc/squid/squid.conf: Permission denied
          - Checking Squid external authentication methods        [ NONE ]
    /bin/grep: /etc/squid/squid.conf: Permission denied
          - Checking Access Control Lists                         [ NONE ]
    /bin/grep: /etc/squid/squid.conf: Permission denied
          - Checking ACL 'Safe_ports' http_access option          [ NOT FOUND ]
        - Checking Squid Denial of Service tuning options
    /bin/grep: /etc/squid/squid.conf: Permission denied
          - Checking option: reply_body_max_size                  [ NONE ]
        - Checking Squid general options
    /bin/grep: /etc/squid/squid.conf: Permission denied
          - Checking option: httpd_suppress_version_string        [ NOT FOUND ]
    
    [+] Logging and files
    ------------------------------------
      - Checking for a running log daemon                         [ OK ]
        - Checking Syslog-NG status                               [ NOT FOUND ]
        - Checking systemd journal status                         [ NOT FOUND ]
        - Checking Metalog status                                 [ NOT FOUND ]
        - Checking RSyslog status                                 [ FOUND ]
        - Checking RFC 3195 daemon status                         [ NOT FOUND ]
        - Checking minilogd instances                             [ NOT FOUND ]
      - Checking logrotate presence                               [ OK ]
      - Checking log directories (static list)                    [ DONE ]
      - Checking open log files                                   [ DONE ]
      - Checking deleted files in use                             [ FILES FOUND ]
    
    [+] Insecure services
    ------------------------------------
      - Checking inetd status                                     [ NOT ACTIVE ]
    
    [+] Banners and identification
    ------------------------------------
      - /etc/issue                                                [ FOUND ]
        - /etc/issue contents                                     [ WEAK ]
      - /etc/issue.net                                            [ FOUND ]
        - /etc/issue.net contents                                 [ WEAK ]
    
    [+] Scheduled tasks
    ------------------------------------
      - Checking crontab/cronjob                                  [ DONE ]
      - Checking atd status                                       [ RUNNING ]
        - Checking at users                                       [ DONE ]
        - Checking at jobs                                        [ NONE ]
    
    [+] Accounting
    ------------------------------------
      - Checking accounting information                           [ NOT FOUND ]
      - Checking sysstat accounting data                          [ NOT FOUND ]
      - Checking auditd                                           [ NOT FOUND ]
    
    [+] Time and Synchronization
    ------------------------------------
      - NTP daemon found: ntpd                                    [ FOUND ]
      - Checking event based ntpdate (if-up)                      [ FOUND ]
      - Checking for a running NTP daemon or client               [ OK ]
      - Checking valid association ID's                           [ FOUND ]
      - Checking high stratum ntp peers                           [ OK ]
      - Checking unreliable ntp peers                             [ FOUND ]
      - Checking selected time source                             [ OK ]
      - Checking time source candidates                           [ OK ]
      - Checking falsetickers                                     [ OK ]
      - Checking NTP version                                      [ FOUND ]
    
    [+] Cryptography
    ------------------------------------
      - Checking for expired SSL certificates                     [ FOUND ]
    
    [+] Virtualization
    ------------------------------------
    
    [+] Containers
    ------------------------------------
    
    [+] Security frameworks
    ------------------------------------
      - Checking presence AppArmor                                [ NOT FOUND ]
      - Checking presence SELinux                                 [ NOT FOUND ]
      - Checking presence grsecurity                              [ NOT FOUND ]
      - Checking for implemented MAC framework                    [ NONE ]
    
    [+] Software: file integrity
    ------------------------------------
      - Checking file integrity tools
      - Checking presence integrity tool                          [ NOT FOUND ]
    
    [+] Software: System tooling
    ------------------------------------
      - Checking automation tooling
      - Automation tooling                                        [ NOT FOUND ]
      - Checking presence of Fail2ban                             [ FOUND ]
        - Checking Fail2ban jails                                 [ ENABLED ]
      - Checking for IDS/IPS tooling                              [ FOUND ]
    
    [+] Software: Malware
    ------------------------------------
      - Checking LMD (Linux Malware Detect)                       [ FOUND ]
    
    [+] File Permissions
    ------------------------------------
      - Starting file permissions check
    
    [+] Home directories
    ------------------------------------
      - Checking shell history files                              [ OK ]
    
    [+] Kernel Hardening
    ------------------------------------
      - Comparing sysctl key pairs with scan profile
    
    [+] Hardening
    ------------------------------------
        - Installed compiler(s)                                   [ FOUND ]
        - Installed malware scanner                               [ FOUND ]
    
    [+] Custom Tests
    ------------------------------------
      - Running custom tests...                                   [ NONE ]
    
    [+] Plugins (phase 2)
    ------------------------------------
    
    ================================================================================
    
      -[ Lynis 2.5.3 Results ]-
    
      Warnings (3):
      ----------------------------
      ! Can't find any security repository in /etc/apt/sources.list or sources.list.d directory [PKGS-7388]
          https://cisofy.com/controls/PKGS-7388/
    
      ! Found some information disclosure in SMTP banner (OS or software name) [MAIL-8818]
          https://cisofy.com/controls/MAIL-8818/
    
      ! PHP option expose_php is possibly turned on, which can reveal useful information for attackers. [PHP-2372]
          https://cisofy.com/controls/PHP-2372/
    
      Suggestions (50):
      ----------------------------
      * Set a password on GRUB bootloader to prevent altering boot configuration (e.g. boot in single user mode without password) [BOOT-5122]
          https://cisofy.com/controls/BOOT-5122/
    
      * Run pwck manually and correct any errors in the password file [AUTH-9228]
          https://cisofy.com/controls/AUTH-9228/
    
      * Install a PAM module for password strength testing like pam_cracklib or pam_passwdqc [AUTH-9262]
          https://cisofy.com/controls/AUTH-9262/
    
      * Configure minimum password age in /etc/login.defs [AUTH-9286]
          https://cisofy.com/controls/AUTH-9286/
    
      * Configure maximum password age in /etc/login.defs [AUTH-9286]
          https://cisofy.com/controls/AUTH-9286/
    
      * Default umask in /etc/login.defs could be more strict like 027 [AUTH-9328]
          https://cisofy.com/controls/AUTH-9328/
    
      * Default umask in /etc/init.d/rc could be more strict like 027 [AUTH-9328]
          https://cisofy.com/controls/AUTH-9328/
    
      * To decrease the impact of a full /home file system, place /home on a separated partition [FILE-6310]
          https://cisofy.com/controls/FILE-6310/
    
      * To decrease the impact of a full /tmp file system, place /tmp on a separated partition [FILE-6310]
          https://cisofy.com/controls/FILE-6310/
    
      * To decrease the impact of a full /var file system, place /var on a separated partition [FILE-6310]
          https://cisofy.com/controls/FILE-6310/
    
      * Disable drivers like USB storage when not used, to prevent unauthorized storage or data theft [STRG-1840]
          https://cisofy.com/controls/STRG-1840/
    
      * Disable drivers like firewire storage when not used, to prevent unauthorized storage or data theft [STRG-1846]
          https://cisofy.com/controls/STRG-1846/
    
      * Split resolving between localhost and the hostname of the system [NAME-4406]
          https://cisofy.com/controls/NAME-4406/
    
      * Purge old/removed packages (3 found) with aptitude purge or dpkg --purge command. This will cleanup old configuration files, cron jobs and startup scripts. [PKGS-7346]
          https://cisofy.com/controls/PKGS-7346/
    
      * Install debsums utility for the verification of packages with known good database. [PKGS-7370]
          https://cisofy.com/controls/PKGS-7370/
    
      * Install a package audit tool to determine vulnerable packages [PKGS-7398]
          https://cisofy.com/controls/PKGS-7398/
    
      * Consider running ARP monitoring software (arpwatch,arpon) [NETW-3032]
          https://cisofy.com/controls/NETW-3032/
    
      * Found a configuration error in Postfix [MAIL-8817]
        - Details  : /etc/postfix/main.cf
        - Solution : run postconf > /dev/null
          https://cisofy.com/controls/MAIL-8817/
    
      * You are advised to hide the mail_name (option: smtpd_banner) from your postfix configuration. Use postconf -e or change your main.cf file (/etc/postfix/main.cf) [MAIL-8818]
          https://cisofy.com/controls/MAIL-8818/
    
      * Install Apache mod_evasive to guard webserver against DoS/brute force attempts [HTTP-6640]
          https://cisofy.com/controls/HTTP-6640/
    
      * Install Apache modsecurity to guard webserver against web application attacks [HTTP-6643]
          https://cisofy.com/controls/HTTP-6643/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : AllowTcpForwarding (YES --> NO)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : ClientAliveCountMax (3 --> 2)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : Compression (DELAYED --> NO)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : LogLevel (INFO --> VERBOSE)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : MaxAuthTries (6 --> 2)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : MaxSessions (10 --> 2)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : PermitRootLogin (YES --> NO)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : Port (22 --> )
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : TCPKeepAlive (YES --> NO)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : UseDNS (YES --> NO)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : X11Forwarding (YES --> NO)
          https://cisofy.com/controls/SSH-7408/
    
      * Change the expose_php line to: expose_php = Off [PHP-2372]
          https://cisofy.com/controls/PHP-2372/
    
      * Change the allow_url_fopen line to: allow_url_fopen = Off, to disable downloads via PHP [PHP-2376]
          https://cisofy.com/controls/PHP-2376/
    
      * Harden PHP by enabling suhosin extension [PHP-2379]
          https://cisofy.com/controls/PHP-2379/
    
      * Harden PHP by deactivating suhosin simulation mode [PHP-2379]
          https://cisofy.com/controls/PHP-2379/
    
      * Check if Squid has been configured to restrict access to all safe ports [SQD-3624]
          https://cisofy.com/controls/SQD-3624/
    
      * Configure Squid option reply_body_max_size to limit the upper size of requests. [SQD-3630]
          https://cisofy.com/controls/SQD-3630/
    
      * Configure Squid option httpd_suppress_version_string (on) to suppress the version. [SQD-3680]
          https://cisofy.com/controls/SQD-3680/
    
      * Check what deleted files are still in use and why. [LOGG-2190]
          https://cisofy.com/controls/LOGG-2190/
    
      * Add a legal banner to /etc/issue, to warn unauthorized users [BANN-7126]
          https://cisofy.com/controls/BANN-7126/
    
      * Add legal banner to /etc/issue.net, to warn unauthorized users [BANN-7130]
          https://cisofy.com/controls/BANN-7130/
    
      * Enable process accounting [ACCT-9622]
          https://cisofy.com/controls/ACCT-9622/
    
      * Enable sysstat to collect accounting (no results) [ACCT-9626]
          https://cisofy.com/controls/ACCT-9626/
    
      * Enable auditd to collect audit information [ACCT-9628]
          https://cisofy.com/controls/ACCT-9628/
    
      * Check ntpq peers output for unreliable ntp peers and correct/replace them [TIME-3120]
          https://cisofy.com/controls/TIME-3120/
    
      * Check available certificates for expiration [CRYP-7902]
          https://cisofy.com/controls/CRYP-7902/
    
      * Install a file integrity tool to monitor changes to critical and sensitive files [FINT-4350]
          https://cisofy.com/controls/FINT-4350/
    
      * Determine if automation tools are present for system management [TOOL-5002]
          https://cisofy.com/controls/TOOL-5002/
    
      * Harden compilers like restricting access to root user only [HRDN-7222]
          https://cisofy.com/controls/HRDN-7222/
    
      Follow-up:
      ----------------------------
      - Show details of a test (lynis show details TEST-ID)
      - Check the logfile for all details (less /tmp/lynis.log)
      - Read security controls texts (https://cisofy.com)
      - Use --upload to upload data to central system (Lynis Enterprise users)
    
    ================================================================================
    
      Lynis security scan details:
    
      Hardening index : 62 [############        ]
      Tests performed : 235
      Plugins enabled : 0
    
      Components:
      - Firewall               [V]
      - Malware scanner        [V]
    
      Lynis Modules:
      - Compliance Status      [?]
      - Security Audit         [V]
      - Vulnerability Scan     [V]
    
      Files:
      - Test and debug information      : /tmp/lynis.log
      - Report data                     : /tmp/lynis-report.dat
    
    ================================================================================
    
      Skipped tests due to non-privileged mode
        BOOT-5108 - Check Syslinux as bootloader
        BOOT-5116 - Check if system is booted in UEFI mode
        AUTH-9216 - Check group and shadow group files
        AUTH-9288 - Checking for expired passwords
        FILE-6368 - Checking ACL support on root file system
        PKGS-7392 - Check for Debian/Ubuntu security updates
        FIRE-4508 - Check used policies of iptables chains
        FIRE-4512 - Check iptables for empty ruleset
        FIRE-4513 - Check iptables for unused rules
        FIRE-4586 - Check firewall logging
    
    ================================================================================
    
      Lynis 2.5.3
    
      Auditing, system hardening, and compliance for UNIX-based systems
      (Linux, macOS, BSD, and others)
    
      2007-2017, CISOfy - https://cisofy.com/lynis/
      Enterprise support available (compliance, plugins, interface and tools)
    
    ================================================================================
    

    V tomto formuláři můžete formulovat svou stížnost ohledně příspěvku. Nejprve vyberte typ akce, kterou navrhujete provést s diskusí či příspěvkem. Potom do textového pole napište důvody, proč by měli admini provést vaši žádost, problém nemusí být patrný na první pohled. Odkaz na příspěvek bude přidán automaticky.

    Vaše jméno
    Váš email
    Typ požadavku
    Slovní popis
    ISSN 1214-1267   www.czech-server.cz
    © 1999-2015 Nitemedia s. r. o. Všechna práva vyhrazena.