abclinuxu.cz AbcLinuxu.cz itbiz.cz ITBiz.cz HDmag.cz HDmag.cz abcprace.cz AbcPráce.cz
AbcLinuxu hledá autory!
Inzerujte na AbcPráce.cz od 950 Kč
Rozšířené hledání
×
    dnes 20:11 | Nová verze

    Bylo vydáno Ubuntu 24.04.4 LTS, tj. čtvrté opravné vydání Ubuntu 24.04 LTS s kódovým názvem Noble Numbat. Přehled novinek a oprav na Discourse.

    Ladislav Hagara | Komentářů: 0
    dnes 17:44 | Pozvánky

    V pátek 20. února 2025 se v pražské kanceláři SUSE v Karlíně uskuteční 6. Mobile Linux Hackday, komunitní setkání zaměřené na Linux na mobilních zařízeních, kernelový vývoj a uživatelský prostor. Akce proběhne od 10:00 do večera. Hackday je určen všem, kteří si chtějí prakticky vyzkoušet práci s linuxovým jádrem i uživatelským prostorem, od posílání patchů například pomocí nástroje b4, přes balíčkování a Flatpak až po drobné úpravy

    … více »
    lkocman | Komentářů: 3
    dnes 13:33 | IT novinky

    Evropská rada vydavatelů (EPC) předložila Evropské komisi stížnost na americkou internetovou společnost Google kvůli její službě AI Overviews (AI souhrny), která při vyhledávání na internetu zobrazuje shrnutí informací ze zpravodajských serverů vytvořená pomocí umělé inteligence (AI). Evropská komise již v prosinci oznámila, že v souvislosti s touto službou začala firmu Google vyšetřovat. Google obvinění ze strany vydavatelů

    … více »
    Ladislav Hagara | Komentářů: 12
    dnes 04:44 | Komunita

    Ubuntu 26.04 (Resolute Raccoon) už nebude v desktopové instalaci obsahovat GUI nástroj 'Software & Updates'. Důvodem jsou obavy z jeho složitosti pro běžné uživatele a z toho plynoucích bezpečnostních rizik. Nástroj lze doinstalovat ručně (sudo apt install software-properties-gtk).

    NUKE GAZA! 🎆 | Komentářů: 21
    dnes 04:33 | IT novinky

    Thomas Dohmke, bývalý CEO GitHubu, představil startup Entire - platformu pro spolupráci vývojářů a agentů umělé inteligence. Entire získalo rekordních 60 milionů dolarů na vývoj databáze a nástrojů, které mají zefektivnit spolupráci mezi lidmi a agenty umělé inteligence. Dohmke zdůrazňuje potřebu přepracovat tradiční vývojové postupy tak, aby odpovídaly realitě, kdy většinu kódu produkuje umělá inteligence.

    NUKE GAZA! 🎆 | Komentářů: 0
    dnes 04:22 | Zajímavý projekt

    Toyota Connected North America oznámila vývoj open-source herního enginu Fluorite, postaveného na frameworku Flutter. Pro renderování grafiky využívá 3D engine Filament od společnosti Google a dle svého tvrzení cílí na konzolovou kvalitu her. Fluorite je zřejmě navržen tak, aby fungoval i na méně výkonném hardware, což naznačuje možnost použití přímo v ICE systémech vozidel. Zdrojový kód zatím zveřejněný není.

    NUKE GAZA! 🎆 | Komentářů: 3
    dnes 04:11 | Bezpečnostní upozornění

    Byl vytvořen nástroj a postup pro překonání věkového ověření platforem Discord, Kick, Twitch, Snapchat (a možná dalších), kód je open-source a dostupný na GitHubu. Všechny tyto sítě používají stejnou službu k-ID, která určuje věk uživatele scanem obličeje a na původní server posílá pouze šifrovaná metadata, ty ale sociální síť už nedokáže sama nijak validovat, 'útok' spočívá ve vygenerování a podstrčení legitimně vypadajících ověřovacích metadat.

    NUKE GAZA! 🎆 | Komentářů: 11
    včera 14:11 | IT novinky

    Jihokorejská kryptoměnová burza Bithumb přiznala vážné selhání interních systémů, které ji vystavilo riziku sabotáže a nezabránilo chybné transakci v hodnotě přes 40 miliard dolarů (814 miliard Kč). Druhá největší kryptoměnová burza v Koreji minulý týden při propagační akci omylem rozeslala zákazníkům zhruba 620 000 bitcoinů místo 620 000 wonů (8700 Kč). Incident vyvolal pokles ceny bitcoinu o 17 procent. Většinu

    … více »
    Ladislav Hagara | Komentářů: 9
    včera 13:55 | Nová verze

    Google Chrome 145 byl prohlášen za stabilní. Nejnovější stabilní verze 145.0.7632.45 přináší řadu novinek z hlediska uživatelů i vývojářů. Podrobný přehled v poznámkách k vydání. Zpátky je podpora grafického formátu JPEG XL, viz Platform Status. Odstraněna byla před třemi lety. Nový dekodér JPEG XL jxl-rs je napsán v Rustu. Zobrazování JPEG XL lze vyzkoušet na testovací stránce. Povolit lze v nastavení chrome://flags (Enable JXL image format).

    Ladislav Hagara | Komentářů: 0
    10.2. 22:44 | Nová verze

    Byla vydána nová verze 1.26 programovacího jazyka Go (Wikipedie). Přehled novinek v poznámkách k vydání.

    Ladislav Hagara | Komentářů: 0
    Které desktopové prostředí na Linuxu používáte?
     (19%)
     (6%)
     (0%)
     (11%)
     (26%)
     (3%)
     (4%)
     (2%)
     (12%)
     (28%)
    Celkem 853 hlasů
     Komentářů: 25, poslední 3.2. 19:50
    Rozcestník

    Administrace komentářů

    Jste na stránce určené pro řešení chyb a problémů týkajících se diskusí a komentářů. Můžete zde našim administrátorům reportovat špatně zařazenou či duplicitní diskusi, vulgární či osočující příspěvek a podobně. Děkujeme vám za vaši pomoc, více očí více vidí, společně můžeme udržet vysokou kvalitu AbcLinuxu.cz.

    Příspěvek
    25.8.2017 12:45 Pfemir | skóre: 5
    Rozbalit Rozbalit vše Re: Vzdálené spouštění procesů.
    Tady je lynis puštěný přes sudo.
    [ Lynis 2.5.3 ]
    
    ################################################################################
      Lynis comes with ABSOLUTELY NO WARRANTY. This is free software, and you are
      welcome to redistribute it under the terms of the GNU General Public License.
      See the LICENSE file for details about using this software.
    
      2007-2017, CISOfy - https://cisofy.com/lynis/
      Enterprise support available (compliance, plugins, interface and tools)
    ################################################################################
    
    
    [+] Initializing program
    ------------------------------------
      - Detecting OS...                                           [ DONE ]
      - Checking profiles...                                      [ DONE ]
      - Detecting language and localization                       [ cs ]
        Notice: no language file found for 'cs' (tried: /usr/local/lynis/lynis/db/languages/cs)
    
      ---------------------------------------------------
      Program version:           2.5.3
      Operating system:          Linux
      Operating system name:     Debian
      Operating system version:  jessie/sid
      Kernel version:            3.12.1
      Hardware platform:         x86_64
      Hostname:                  pfemir
      ---------------------------------------------------
      Profiles:                  /usr/local/lynis/lynis/default.prf
      Log file:                  /var/log/lynis.log
      Report file:               /var/log/lynis-report.dat
      Report version:            1.0
      Plugin directory:          ./plugins
      ---------------------------------------------------
      Auditor:                   [Not Specified]
      Test category:             all
      Test group:                all
      ---------------------------------------------------
      - Program update status...                                  [ NO UPDATE ]
    
    [+] System Tools
    ------------------------------------
      - Scanning available tools...
      - Checking system binaries...
    
    [+] Plugins (phase 1)
    ------------------------------------
     Note: plugins have more extensive tests and may take several minutes to complete
    
      - Plugins enabled                                           [ NONE ]
    
    [+] Boot and services
    ------------------------------------
      - Service Manager                                           [ SysV Init ]
      - Checking UEFI boot                                        [ DISABLED ]
      - Checking presence GRUB2                                   [ FOUND ]
        - Checking for password protection                        [ WARNING ]
      - Check services at startup (rc2.d)                         [ DONE ]
        Result: found 54 services
      - Check startup files (permissions)                         [ OK ]
    
    [+] Kernel
    ------------------------------------
      - Checking default run level                                [ 2 ]
      - Checking CPU support (NX/PAE)
        CPU support: PAE and/or NoeXecute supported               [ FOUND ]
      - Checking kernel version and release                       [ DONE ]
      - Checking kernel type                                      [ DONE ]
      - Checking loaded kernel modules                            [ DONE ]
          Found 59 active modules
      - Checking Linux kernel configuration file                  [ FOUND ]
      - Checking default I/O kernel scheduler                     [ FOUND ]
      - Checking for available kernel update                      [ OK ]
      - Checking core dumps configuration                         [ DISABLED ]
        - Checking setuid core dumps configuration                [ DEFAULT ]
      - Check if reboot is needed                                 [ NO ]
    
    [+] Memory and Processes
    ------------------------------------
      - Checking /proc/meminfo                                    [ FOUND ]
      - Searching for dead/zombie processes                       [ OK ]
      - Searching for IO waiting processes                        [ OK ]
    
    [+] Users, Groups and Authentication
    ------------------------------------
      - Administrator accounts                                    [ OK ]
      - Unique UIDs                                               [ OK ]
      - Consistency of group files (grpck)                        [ OK ]
      - Unique group IDs                                          [ OK ]
      - Unique group names                                        [ OK ]
      - Password file consistency                                 [ OK ]
      - Query system users (non daemons)                          [ DONE ]
      - NIS+ authentication support                               [ NOT ENABLED ]
      - NIS authentication support                                [ NOT ENABLED ]
      - sudoers file                                              [ FOUND ]
        - Check sudoers file permissions                          [ OK ]
      - PAM password strength tools                               [ SUGGESTION ]
      - PAM configuration files (pam.conf)                        [ FOUND ]
      - PAM configuration files (pam.d)                           [ FOUND ]
      - PAM modules                                               [ FOUND ]
      - LDAP module in PAM                                        [ NOT FOUND ]
      - Accounts without expire date                              [ OK ]
      - Accounts without password                                 [ OK ]
      - Checking user password aging (minimum)                    [ DISABLED ]
      - User password aging (maximum)                             [ DISABLED ]
      - Checking expired passwords                                [ OK ]
      - Checking Linux single user mode authentication            [ OK ]
      - Determining default umask
        - umask (/etc/profile)                                    [ NOT FOUND ]
        - umask (/etc/login.defs)                                 [ SUGGESTION ]
        - umask (/etc/init.d/rc)                                  [ SUGGESTION ]
      - LDAP authentication support                               [ NOT ENABLED ]
      - Logging failed login attempts                             [ ENABLED ]
    
    [+] Shells
    ------------------------------------
      - Checking shells from /etc/shells
        Result: found 13 shells (valid shells: 7).
        - Session timeout settings/tools                          [ NONE ]
      - Checking default umask values
        - Checking default umask in /etc/bash.bashrc              [ NONE ]
        - Checking default umask in /etc/profile                  [ NONE ]
    
    [+] File systems
    ------------------------------------
      - Checking mount points
        - Checking /home mount point                              [ SUGGESTION ]
        - Checking /tmp mount point                               [ SUGGESTION ]
        - Checking /var mount point                               [ SUGGESTION ]
      - Query swap partitions (fstab)                             [ OK ]
      - Testing swap partitions                                   [ OK ]
      - Testing /proc mount (hidepid)                             [ SUGGESTION ]
      - Checking for old files in /tmp                            [ OK ]
      - Checking /tmp sticky bit                                  [ OK ]
      - ACL support root file system                              [ ENABLED ]
      - Mount options of /                                        [ NON DEFAULT ]
      - Checking Locate database                                  [ FOUND ]
      - Disable kernel support of some filesystems
        - Discovered kernel modules: cramfs freevxfs hfs hfsplus jffs2 squashfs udf
    
    [+] Storage
    ------------------------------------
      - Checking usb-storage driver (modprobe config)             [ NOT DISABLED ]
      - Checking USB devices authorization                        [ ENABLED ]
      - Checking firewire ohci driver (modprobe config)           [ NOT DISABLED ]
    
    [+] NFS
    ------------------------------------
      - Query rpc registered programs                             [ DONE ]
      - Query NFS versions                                        [ DONE ]
      - Query NFS protocols                                       [ DONE ]
      - Check running NFS daemon                                  [ FOUND ]
        - Checking /etc/exports                                   [ FOUND ]
        - Checking NFS client access                              [ OK ]
    
    [+] Name services
    ------------------------------------
      - Checking default DNS search domain                        [ FOUND ]
      - Searching DNS domain name                                 [ FOUND ]
          Domain name: cz
      - Checking nscd status                                      [ RUNNING ]
      - Checking /etc/hosts
        - Checking /etc/hosts (duplicates)                        [ OK ]
        - Checking /etc/hosts (hostname)                          [ OK ]
        - Checking /etc/hosts (localhost)                         [ SUGGESTION ]
        - Checking /etc/hosts (localhost to IP)                   [ OK ]
    
    [+] Ports and packages
    ------------------------------------
      - Searching package managers
        - Searching dpkg package manager                          [ FOUND ]
          - Querying package manager
        - Query unpurged packages                                 [ FOUND ]
      - Checking security repository in sources.list file or directory  [ WARNING ]
      - Checking vulnerable packages (apt-get only)               [ DONE ]
      - Checking package audit tool                               [ INSTALLED ]
        Found: apt-get
    
    [+] Networking
    ------------------------------------
      - Checking IPv6 configuration                               [ ENABLED ]
          Configuration method                                    [ AUTO ]
          IPv6 only                                               [ NO ]
      - Checking configured nameservers
        - Testing nameservers
            Nameserver: 77.242.95.2                               [ OK ]
            Nameserver: 192.168.1.1                               [ OK ]
        - Minimal of 2 responsive nameservers                     [ OK ]
      - Checking default gateway                                  [ DONE ]
      - Getting listening ports (TCP/UDP)                         [ DONE ]
          * Found 80 ports
      - Checking promiscuous interfaces                           [ OK ]
      - Checking waiting connections                              [ OK ]
      - Checking status DHCP client                               [ NOT ACTIVE ]
      - Checking for ARP monitoring software                      [ NOT FOUND ]
    
    [+] Printers and Spools
    ------------------------------------
      - Checking cups daemon                                      [ RUNNING ]
      - Checking CUPS configuration file                          [ OK ]
        - File permissions                                        [ OK ]
      - Checking CUPS addresses/sockets                           [ FOUND ]
      - Checking lp daemon                                        [ NOT RUNNING ]
    
    [+] Software: e-mail and messaging
    ------------------------------------
      - Postfix status                                            [ RUNNING ]
        - Postfix configuration                                   [ FOUND ]
          - Postfix configuration errors                          [ WARNING ]
          - Postfix banner                                        [ WARNING ]
      - Dovecot status                                            [ RUNNING ]
    
    [+] Software: firewalls
    ------------------------------------
      - Checking iptables kernel module                           [ FOUND ]
        - Checking iptables policies of chains                    [ FOUND ]
          - Checking chain INPUT (table: filter) policy           [ ACCEPT ]
        - Checking for empty ruleset                              [ WARNING ]
        - Checking for unused rules                               [ OK ]
      - Checking host based firewall                              [ ACTIVE ]
    
    [+] Software: webserver
    ------------------------------------
      - Checking Apache (binary /usr/sbin/apache2)                [ FOUND ]
          Info: Found 6 virtual hosts
        * Loadable modules                                        [ FOUND (107) ]
            - Found 107 loadable modules
              mod_evasive: anti-DoS/brute force                   [ NOT FOUND ]
              mod_reqtimeout/mod_qos                              [ FOUND ]
              ModSecurity: web application firewall               [ NOT FOUND ]
      - Checking nginx                                            [ NOT FOUND ]
    
    [+] SSH Support
    ------------------------------------
      - Checking running SSH daemon                               [ FOUND ]
        - Searching SSH configuration                             [ FOUND ]
        - SSH option: AllowTcpForwarding                          [ SUGGESTION ]
        - SSH option: ClientAliveCountMax                         [ SUGGESTION ]
        - SSH option: ClientAliveInterval                         [ OK ]
        - SSH option: Compression                                 [ SUGGESTION ]
        - SSH option: FingerprintHash                             [ NOT FOUND ]
        - SSH option: GatewayPorts                                [ OK ]
        - SSH option: IgnoreRhosts                                [ OK ]
        - SSH option: LoginGraceTime                              [ OK ]
        - SSH option: LogLevel                                    [ SUGGESTION ]
        - SSH option: MaxAuthTries                                [ SUGGESTION ]
        - SSH option: MaxSessions                                 [ SUGGESTION ]
        - SSH option: PermitRootLogin                             [ SUGGESTION ]
        - SSH option: PermitUserEnvironment                       [ OK ]
        - SSH option: PermitTunnel                                [ OK ]
        - SSH option: Port                                        [ SUGGESTION ]
        - SSH option: PrintLastLog                                [ OK ]
        - SSH option: Protocol                                    [ OK ]
        - SSH option: StrictModes                                 [ OK ]
        - SSH option: TCPKeepAlive                                [ SUGGESTION ]
        - SSH option: UseDNS                                      [ SUGGESTION ]
        - SSH option: VerifyReverseMapping                        [ NOT FOUND ]
        - SSH option: X11Forwarding                               [ SUGGESTION ]
        - SSH option: AllowAgentForwarding                        [ NOT FOUND ]
        - SSH option: AllowUsers                                  [ NOT FOUND ]
        - SSH option: AllowGroups                                 [ NOT FOUND ]
    
    [+] SNMP Support
    ------------------------------------
      - Checking running SNMP daemon                              [ NOT FOUND ]
    
    [+] Databases
    ------------------------------------
      - MySQL process status                                      [ FOUND ]
    
    [+] LDAP Services
    ------------------------------------
      - Checking OpenLDAP instance                                [ NOT FOUND ]
    
    [+] PHP
    ------------------------------------
      - Checking PHP                                              [ FOUND ]
        - Checking PHP disabled functions                         [ FOUND ]
        - Checking expose_php option                              [ ON ]
        - Checking enable_dl option                               [ OFF ]
        - Checking allow_url_fopen option                         [ ON ]
        - Checking allow_url_include option                       [ OFF ]
        - Checking PHP suhosin extension status                   [ WARNING ]
          - Suhosin simulation mode status                        [ WARNING ]
    
    [+] Squid Support
    ------------------------------------
      - Checking running Squid daemon                             [ FOUND ]
        - Searching Squid configuration                           [ FOUND ]
        - Checking Squid version                                  [ FOUND ]
        - Checking defined Squid options                          [ DONE ]
        - Checking Squid configuration file permissions           [ OK ]
        - Checking Squid access control
          - Checking Squid authentication methods                 [ FOUND ]
          - Checking Squid external authentication methods        [ NONE ]
          - Checking Access Control Lists                         [ 29 ACLs FOUND ]
          - Checking ACL 'Safe_ports' ports                       [ FOUND ]
          - Checking ACL 'Safe_ports' (port 22)                   [ NOT FOUND ]
          - Checking ACL 'Safe_ports' (port 23)                   [ NOT FOUND ]
          - Checking ACL 'Safe_ports' (port 25)                   [ NOT FOUND ]
        - Checking Squid Denial of Service tuning options
          - Checking option: reply_body_max_size                  [ NONE ]
        - Checking Squid general options
          - Checking option: httpd_suppress_version_string        [ NOT FOUND ]
    
    [+] Logging and files
    ------------------------------------
      - Checking for a running log daemon                         [ OK ]
        - Checking Syslog-NG status                               [ NOT FOUND ]
        - Checking systemd journal status                         [ NOT FOUND ]
        - Checking Metalog status                                 [ NOT FOUND ]
        - Checking RSyslog status                                 [ FOUND ]
        - Checking RFC 3195 daemon status                         [ NOT FOUND ]
        - Checking minilogd instances                             [ NOT FOUND ]
      - Checking logrotate presence                               [ OK ]
      - Checking log directories (static list)                    [ DONE ]
      - Checking open log files                                   [ DONE ]
      - Checking deleted files in use                             [ FILES FOUND ]
    
    [+] Insecure services
    ------------------------------------
      - Checking inetd status                                     [ NOT ACTIVE ]
    
    [+] Banners and identification
    ------------------------------------
      - /etc/issue                                                [ FOUND ]
        - /etc/issue contents                                     [ WEAK ]
      - /etc/issue.net                                            [ FOUND ]
        - /etc/issue.net contents                                 [ WEAK ]
    
    [+] Scheduled tasks
    ------------------------------------
      - Checking crontab/cronjob                                  [ DONE ]
      - Checking atd status                                       [ RUNNING ]
        - Checking at users                                       [ DONE ]
        - Checking at jobs                                        [ NONE ]
    
    [+] Accounting
    ------------------------------------
      - Checking accounting information                           [ NOT FOUND ]
      - Checking sysstat accounting data                          [ NOT FOUND ]
      - Checking auditd                                           [ NOT FOUND ]
    
    [+] Time and Synchronization
    ------------------------------------
      - NTP daemon found: ntpd                                    [ FOUND ]
      - Checking event based ntpdate (if-up)                      [ FOUND ]
      - Checking for a running NTP daemon or client               [ OK ]
      - Checking valid association ID's                           [ FOUND ]
      - Checking high stratum ntp peers                           [ OK ]
      - Checking unreliable ntp peers                             [ FOUND ]
      - Checking selected time source                             [ OK ]
      - Checking time source candidates                           [ OK ]
      - Checking falsetickers                                     [ OK ]
      - Checking NTP version                                      [ FOUND ]
    
    [+] Cryptography
    ------------------------------------
      - Checking for expired SSL certificates                     [ FOUND ]
    
    [+] Virtualization
    ------------------------------------
    
    [+] Containers
    ------------------------------------
    
    [+] Security frameworks
    ------------------------------------
      - Checking presence AppArmor                                [ NOT FOUND ]
      - Checking presence SELinux                                 [ NOT FOUND ]
      - Checking presence grsecurity                              [ NOT FOUND ]
      - Checking for implemented MAC framework                    [ NONE ]
    
    [+] Software: file integrity
    ------------------------------------
      - Checking file integrity tools
      - Checking presence integrity tool                          [ NOT FOUND ]
    
    [+] Software: System tooling
    ------------------------------------
      - Checking automation tooling
        - Ansible artifact                                        [ FOUND ]
      - Automation tooling                                        [ FOUND ]
      - Checking presence of Fail2ban                             [ FOUND ]
        - Checking Fail2ban jails                                 [ ENABLED ]
      - Checking for IDS/IPS tooling                              [ FOUND ]
    
    [+] Software: Malware
    ------------------------------------
      - Checking LMD (Linux Malware Detect)                       [ FOUND ]
    
    [+] File Permissions
    ------------------------------------
      - Starting file permissions check
    
    [+] Home directories
    ------------------------------------
      - Checking shell history files                              [ OK ]
    
    [+] Kernel Hardening
    ------------------------------------
      - Comparing sysctl key pairs with scan profile
        - fs.protected_hardlinks (exp: 1)                         [ DIFFERENT ]
        - fs.protected_symlinks (exp: 1)                          [ DIFFERENT ]
        - fs.suid_dumpable (exp: 0)                               [ OK ]
        - kernel.core_uses_pid (exp: 1)                           [ DIFFERENT ]
        - kernel.ctrl-alt-del (exp: 0)                            [ OK ]
        - kernel.dmesg_restrict (exp: 1)                          [ DIFFERENT ]
        - kernel.kptr_restrict (exp: 2)                           [ DIFFERENT ]
        - kernel.randomize_va_space (exp: 2)                      [ OK ]
        - kernel.sysrq (exp: 0)                                   [ DIFFERENT ]
        - net.ipv4.conf.all.accept_redirects (exp: 0)             [ DIFFERENT ]
        - net.ipv4.conf.all.accept_source_route (exp: 0)          [ OK ]
        - net.ipv4.conf.all.bootp_relay (exp: 0)                  [ OK ]
        - net.ipv4.conf.all.forwarding (exp: 0)                   [ OK ]
        - net.ipv4.conf.all.log_martians (exp: 1)                 [ DIFFERENT ]
        - net.ipv4.conf.all.mc_forwarding (exp: 0)                [ OK ]
        - net.ipv4.conf.all.proxy_arp (exp: 0)                    [ OK ]
        - net.ipv4.conf.all.rp_filter (exp: 1)                    [ DIFFERENT ]
        - net.ipv4.conf.all.send_redirects (exp: 0)               [ DIFFERENT ]
        - net.ipv4.conf.default.accept_redirects (exp: 0)         [ DIFFERENT ]
        - net.ipv4.conf.default.accept_source_route (exp: 0)      [ DIFFERENT ]
        - net.ipv4.conf.default.log_martians (exp: 1)             [ DIFFERENT ]
        - net.ipv4.icmp_echo_ignore_broadcasts (exp: 1)           [ OK ]
        - net.ipv4.icmp_ignore_bogus_error_responses (exp: 1)     [ OK ]
        - net.ipv4.tcp_syncookies (exp: 1)                        [ OK ]
        - net.ipv4.tcp_timestamps (exp: 0)                        [ DIFFERENT ]
        - net.ipv6.conf.all.accept_redirects (exp: 0)             [ DIFFERENT ]
        - net.ipv6.conf.all.accept_source_route (exp: 0)          [ OK ]
        - net.ipv6.conf.default.accept_redirects (exp: 0)         [ DIFFERENT ]
        - net.ipv6.conf.default.accept_source_route (exp: 0)      [ OK ]
    
    [+] Hardening
    ------------------------------------
        - Installed compiler(s)                                   [ FOUND ]
        - Installed malware scanner                               [ FOUND ]
    
    [+] Custom Tests
    ------------------------------------
      - Running custom tests...                                   [ NONE ]
    
    [+] Plugins (phase 2)
    ------------------------------------
    
    ================================================================================
    
      -[ Lynis 2.5.3 Results ]-
    
      Warnings (4):
      ----------------------------
      ! Can't find any security repository in /etc/apt/sources.list or sources.list.d directory [PKGS-7388]
          https://cisofy.com/controls/PKGS-7388/
    
      ! Found some information disclosure in SMTP banner (OS or software name) [MAIL-8818]
          https://cisofy.com/controls/MAIL-8818/
    
      ! iptables module(s) loaded, but no rules active [FIRE-4512]
          https://cisofy.com/controls/FIRE-4512/
    
      ! PHP option expose_php is possibly turned on, which can reveal useful information for attackers. [PHP-2372]
          https://cisofy.com/controls/PHP-2372/
    
      Suggestions (47):
      ----------------------------
      * Set a password on GRUB bootloader to prevent altering boot configuration (e.g. boot in single user mode without password) [BOOT-5122]
          https://cisofy.com/controls/BOOT-5122/
    
      * Install a PAM module for password strength testing like pam_cracklib or pam_passwdqc [AUTH-9262]
          https://cisofy.com/controls/AUTH-9262/
    
      * Configure minimum password age in /etc/login.defs [AUTH-9286]
          https://cisofy.com/controls/AUTH-9286/
    
      * Configure maximum password age in /etc/login.defs [AUTH-9286]
          https://cisofy.com/controls/AUTH-9286/
    
      * Default umask in /etc/login.defs could be more strict like 027 [AUTH-9328]
          https://cisofy.com/controls/AUTH-9328/
    
      * Default umask in /etc/init.d/rc could be more strict like 027 [AUTH-9328]
          https://cisofy.com/controls/AUTH-9328/
    
      * To decrease the impact of a full /home file system, place /home on a separated partition [FILE-6310]
          https://cisofy.com/controls/FILE-6310/
    
      * To decrease the impact of a full /tmp file system, place /tmp on a separated partition [FILE-6310]
          https://cisofy.com/controls/FILE-6310/
    
      * To decrease the impact of a full /var file system, place /var on a separated partition [FILE-6310]
          https://cisofy.com/controls/FILE-6310/
    
      * Disable drivers like USB storage when not used, to prevent unauthorized storage or data theft [STRG-1840]
          https://cisofy.com/controls/STRG-1840/
    
      * Disable drivers like firewire storage when not used, to prevent unauthorized storage or data theft [STRG-1846]
          https://cisofy.com/controls/STRG-1846/
    
      * Split resolving between localhost and the hostname of the system [NAME-4406]
          https://cisofy.com/controls/NAME-4406/
    
      * Purge old/removed packages (3 found) with aptitude purge or dpkg --purge command. This will cleanup old configuration files, cron jobs and startup scripts. [PKGS-7346]
          https://cisofy.com/controls/PKGS-7346/
    
      * Install debsums utility for the verification of packages with known good database. [PKGS-7370]
          https://cisofy.com/controls/PKGS-7370/
    
      * Consider running ARP monitoring software (arpwatch,arpon) [NETW-3032]
          https://cisofy.com/controls/NETW-3032/
    
      * Found a configuration error in Postfix [MAIL-8817]
        - Details  : /etc/postfix/main.cf
        - Solution : run postconf > /dev/null
          https://cisofy.com/controls/MAIL-8817/
    
      * You are advised to hide the mail_name (option: smtpd_banner) from your postfix configuration. Use postconf -e or change your main.cf file (/etc/postfix/main.cf) [MAIL-8818]
          https://cisofy.com/controls/MAIL-8818/
    
      * Install Apache mod_evasive to guard webserver against DoS/brute force attempts [HTTP-6640]
          https://cisofy.com/controls/HTTP-6640/
    
      * Install Apache modsecurity to guard webserver against web application attacks [HTTP-6643]
          https://cisofy.com/controls/HTTP-6643/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : AllowTcpForwarding (YES --> NO)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : ClientAliveCountMax (3 --> 2)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : Compression (DELAYED --> NO)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : LogLevel (INFO --> VERBOSE)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : MaxAuthTries (6 --> 2)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : MaxSessions (10 --> 2)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : PermitRootLogin (YES --> NO)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : Port (22 --> )
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : TCPKeepAlive (YES --> NO)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : UseDNS (YES --> NO)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : X11Forwarding (YES --> NO)
          https://cisofy.com/controls/SSH-7408/
    
      * Change the expose_php line to: expose_php = Off [PHP-2372]
          https://cisofy.com/controls/PHP-2372/
    
      * Change the allow_url_fopen line to: allow_url_fopen = Off, to disable downloads via PHP [PHP-2376]
          https://cisofy.com/controls/PHP-2376/
    
      * Harden PHP by enabling suhosin extension [PHP-2379]
          https://cisofy.com/controls/PHP-2379/
    
      * Harden PHP by deactivating suhosin simulation mode [PHP-2379]
          https://cisofy.com/controls/PHP-2379/
    
      * Configure Squid option reply_body_max_size to limit the upper size of requests. [SQD-3630]
          https://cisofy.com/controls/SQD-3630/
    
      * Configure Squid option httpd_suppress_version_string (on) to suppress the version. [SQD-3680]
          https://cisofy.com/controls/SQD-3680/
    
      * Check what deleted files are still in use and why. [LOGG-2190]
          https://cisofy.com/controls/LOGG-2190/
    
      * Add a legal banner to /etc/issue, to warn unauthorized users [BANN-7126]
          https://cisofy.com/controls/BANN-7126/
    
      * Add legal banner to /etc/issue.net, to warn unauthorized users [BANN-7130]
          https://cisofy.com/controls/BANN-7130/
    
      * Enable process accounting [ACCT-9622]
          https://cisofy.com/controls/ACCT-9622/
    
      * Enable sysstat to collect accounting (no results) [ACCT-9626]
          https://cisofy.com/controls/ACCT-9626/
    
      * Enable auditd to collect audit information [ACCT-9628]
          https://cisofy.com/controls/ACCT-9628/
    
      * Check ntpq peers output for unreliable ntp peers and correct/replace them [TIME-3120]
          https://cisofy.com/controls/TIME-3120/
    
      * Check available certificates for expiration [CRYP-7902]
          https://cisofy.com/controls/CRYP-7902/
    
      * Install a file integrity tool to monitor changes to critical and sensitive files [FINT-4350]
          https://cisofy.com/controls/FINT-4350/
    
      * One or more sysctl values differ from the scan profile and could be tweaked [KRNL-6000]
          https://cisofy.com/controls/KRNL-6000/
    
      * Harden compilers like restricting access to root user only [HRDN-7222]
          https://cisofy.com/controls/HRDN-7222/
    
      Follow-up:
      ----------------------------
      - Show details of a test (lynis show details TEST-ID)
      - Check the logfile for all details (less /var/log/lynis.log)
      - Read security controls texts (https://cisofy.com)
      - Use --upload to upload data to central system (Lynis Enterprise users)
    
    ================================================================================
    
      Lynis security scan details:
    
      Hardening index : 64 [############        ]
      Tests performed : 247
      Plugins enabled : 0
    
      Components:
      - Firewall               [V]
      - Malware scanner        [V]
    
      Lynis Modules:
      - Compliance Status      [?]
      - Security Audit         [V]
      - Vulnerability Scan     [V]
    
      Files:
      - Test and debug information      : /var/log/lynis.log
      - Report data                     : /var/log/lynis-report.dat
    
    ================================================================================
    
      Lynis 2.5.3
    
      Auditing, system hardening, and compliance for UNIX-based systems
      (Linux, macOS, BSD, and others)
    
      2007-2017, CISOfy - https://cisofy.com/lynis/
      Enterprise support available (compliance, plugins, interface and tools)
    
    ================================================================================
    

    V tomto formuláři můžete formulovat svou stížnost ohledně příspěvku. Nejprve vyberte typ akce, kterou navrhujete provést s diskusí či příspěvkem. Potom do textového pole napište důvody, proč by měli admini provést vaši žádost, problém nemusí být patrný na první pohled. Odkaz na příspěvek bude přidán automaticky.

    Vaše jméno
    Váš email
    Typ požadavku
    Slovní popis
    ISSN 1214-1267   www.czech-server.cz
    © 1999-2015 Nitemedia s. r. o. Všechna práva vyhrazena.