abclinuxu.cz AbcLinuxu.cz itbiz.cz ITBiz.cz HDmag.cz HDmag.cz abcprace.cz AbcPráce.cz
AbcLinuxu hledá autory!
Inzerujte na AbcPráce.cz od 950 Kč
Rozšířené hledání
×
    dnes 12:22 | IT novinky

    Raspberry Pi Touch Display 2 je nově vedle 7palcové k dispozici také v 5palcové variantě. Rozlišení stejné 720 × 1280 pixelů. Cena 40 dolarů.

    Ladislav Hagara | Komentářů: 1
    dnes 04:44 | IT novinky

    Telnet a ssh klient PuTTY postupně přechází na novou doménu putty.software.

    Ladislav Hagara | Komentářů: 3
    16.8. 01:00 | Komunita

    Debian dnes slaví 32 let. Ian Murdock oznámil vydání "Debian Linux Release" 16. srpna 1993.

    Ladislav Hagara | Komentářů: 15
    15.8. 17:44 | IT novinky

    Policisté zadrželi odsouzeného drogového dealera Tomáše Jiřikovského, který daroval ministerstvu spravedlnosti za tehdejšího ministra Pavla Blažka (ODS) bitcoiny v miliardové hodnotě, a zajistili i darovanou kryproměnu. Zadržení Jiřikovského může být podle ministerstva důležité k rozuzlení kauzy, která vypukla koncem května a vedla ke konci Blažka. Zajištění daru podle úřadu potvrzuje závěry dříve publikovaných právních

    … více »
    Ladislav Hagara | Komentářů: 10
    15.8. 13:44 | IT novinky

    Administrativa amerického prezidenta Donalda Trumpa jedná o možném převzetí podílu ve výrobci čipů Intel. Agentuře Bloomberg to řekly zdroje obeznámené se situací. Akcie Intelu v reakci na tuto zprávu výrazně posílily. Trump minulý týden označil Tana za konfliktní osobu, a to kvůli jeho vazbám na čínské společnosti, čímž vyvolal nejistotu ohledně dlouholetého úsilí Intelu o obrat v hospodaření. Po pondělní schůzce však prezident o šéfovi Intelu hovořil příznivě.

    Ladislav Hagara | Komentářů: 3
    15.8. 05:44 | IT novinky

    Společnost Purism stojící za linuxovými telefony a počítači Librem má nově v nabídce postkvantový šifrátor Librem PQC Encryptor.

    Ladislav Hagara | Komentářů: 13
    14.8. 18:00 | Nová verze

    VirtualBox, tj. multiplatformní virtualizační software, byl vydán v nové verzi 7.2. Přehled novinek v Changelogu. Vypíchnou lze vylepšené GUI.

    Ladislav Hagara | Komentářů: 0
    14.8. 14:11 | IT novinky

    Eric Migicovsky, zakladatel společnosti Pebble, v lednu oznámil, že má v plánu spustit výrobu nových hodinek Pebble s již open source PebbleOS. V březnu spustil předprodej hodinek Pebble Time 2 (tenkrát ještě pod názvem Core Time 2) za 225 dolarů s dodáním v prosinci. Včera představil jejich konečný vzhled (YouTube).

    Ladislav Hagara | Komentářů: 31
    14.8. 12:44 | Zajímavý software

    Byla oznámena nativní podpora protokolu ACME (Automated Certificate Management Environment) ve webovém serveru a reverzní proxy NGINX. Modul nginx-acme je zatím v preview verzi.

    Ladislav Hagara | Komentářů: 2
    14.8. 12:22 | Nová verze

    Vývojáři KDE oznámili vydání balíku aplikací KDE Gear 25.08. Přehled novinek i s náhledy a videi v oficiálním oznámení.

    Ladislav Hagara | Komentářů: 0
    Kolik tabů máte standardně otevřeno ve web prohlížeči?
     (52%)
     (19%)
     (4%)
     (5%)
     (2%)
     (1%)
     (1%)
     (17%)
    Celkem 412 hlasů
     Komentářů: 24, poslední dnes 11:25
    Rozcestník

    Administrace komentářů

    Jste na stránce určené pro řešení chyb a problémů týkajících se diskusí a komentářů. Můžete zde našim administrátorům reportovat špatně zařazenou či duplicitní diskusi, vulgární či osočující příspěvek a podobně. Děkujeme vám za vaši pomoc, více očí více vidí, společně můžeme udržet vysokou kvalitu AbcLinuxu.cz.

    Příspěvek
    25.8.2017 12:45 Pfemir | skóre: 5
    Rozbalit Rozbalit vše Re: Vzdálené spouštění procesů.
    Tady je lynis puštěný přes sudo.
    [ Lynis 2.5.3 ]
    
    ################################################################################
      Lynis comes with ABSOLUTELY NO WARRANTY. This is free software, and you are
      welcome to redistribute it under the terms of the GNU General Public License.
      See the LICENSE file for details about using this software.
    
      2007-2017, CISOfy - https://cisofy.com/lynis/
      Enterprise support available (compliance, plugins, interface and tools)
    ################################################################################
    
    
    [+] Initializing program
    ------------------------------------
      - Detecting OS...                                           [ DONE ]
      - Checking profiles...                                      [ DONE ]
      - Detecting language and localization                       [ cs ]
        Notice: no language file found for 'cs' (tried: /usr/local/lynis/lynis/db/languages/cs)
    
      ---------------------------------------------------
      Program version:           2.5.3
      Operating system:          Linux
      Operating system name:     Debian
      Operating system version:  jessie/sid
      Kernel version:            3.12.1
      Hardware platform:         x86_64
      Hostname:                  pfemir
      ---------------------------------------------------
      Profiles:                  /usr/local/lynis/lynis/default.prf
      Log file:                  /var/log/lynis.log
      Report file:               /var/log/lynis-report.dat
      Report version:            1.0
      Plugin directory:          ./plugins
      ---------------------------------------------------
      Auditor:                   [Not Specified]
      Test category:             all
      Test group:                all
      ---------------------------------------------------
      - Program update status...                                  [ NO UPDATE ]
    
    [+] System Tools
    ------------------------------------
      - Scanning available tools...
      - Checking system binaries...
    
    [+] Plugins (phase 1)
    ------------------------------------
     Note: plugins have more extensive tests and may take several minutes to complete
    
      - Plugins enabled                                           [ NONE ]
    
    [+] Boot and services
    ------------------------------------
      - Service Manager                                           [ SysV Init ]
      - Checking UEFI boot                                        [ DISABLED ]
      - Checking presence GRUB2                                   [ FOUND ]
        - Checking for password protection                        [ WARNING ]
      - Check services at startup (rc2.d)                         [ DONE ]
        Result: found 54 services
      - Check startup files (permissions)                         [ OK ]
    
    [+] Kernel
    ------------------------------------
      - Checking default run level                                [ 2 ]
      - Checking CPU support (NX/PAE)
        CPU support: PAE and/or NoeXecute supported               [ FOUND ]
      - Checking kernel version and release                       [ DONE ]
      - Checking kernel type                                      [ DONE ]
      - Checking loaded kernel modules                            [ DONE ]
          Found 59 active modules
      - Checking Linux kernel configuration file                  [ FOUND ]
      - Checking default I/O kernel scheduler                     [ FOUND ]
      - Checking for available kernel update                      [ OK ]
      - Checking core dumps configuration                         [ DISABLED ]
        - Checking setuid core dumps configuration                [ DEFAULT ]
      - Check if reboot is needed                                 [ NO ]
    
    [+] Memory and Processes
    ------------------------------------
      - Checking /proc/meminfo                                    [ FOUND ]
      - Searching for dead/zombie processes                       [ OK ]
      - Searching for IO waiting processes                        [ OK ]
    
    [+] Users, Groups and Authentication
    ------------------------------------
      - Administrator accounts                                    [ OK ]
      - Unique UIDs                                               [ OK ]
      - Consistency of group files (grpck)                        [ OK ]
      - Unique group IDs                                          [ OK ]
      - Unique group names                                        [ OK ]
      - Password file consistency                                 [ OK ]
      - Query system users (non daemons)                          [ DONE ]
      - NIS+ authentication support                               [ NOT ENABLED ]
      - NIS authentication support                                [ NOT ENABLED ]
      - sudoers file                                              [ FOUND ]
        - Check sudoers file permissions                          [ OK ]
      - PAM password strength tools                               [ SUGGESTION ]
      - PAM configuration files (pam.conf)                        [ FOUND ]
      - PAM configuration files (pam.d)                           [ FOUND ]
      - PAM modules                                               [ FOUND ]
      - LDAP module in PAM                                        [ NOT FOUND ]
      - Accounts without expire date                              [ OK ]
      - Accounts without password                                 [ OK ]
      - Checking user password aging (minimum)                    [ DISABLED ]
      - User password aging (maximum)                             [ DISABLED ]
      - Checking expired passwords                                [ OK ]
      - Checking Linux single user mode authentication            [ OK ]
      - Determining default umask
        - umask (/etc/profile)                                    [ NOT FOUND ]
        - umask (/etc/login.defs)                                 [ SUGGESTION ]
        - umask (/etc/init.d/rc)                                  [ SUGGESTION ]
      - LDAP authentication support                               [ NOT ENABLED ]
      - Logging failed login attempts                             [ ENABLED ]
    
    [+] Shells
    ------------------------------------
      - Checking shells from /etc/shells
        Result: found 13 shells (valid shells: 7).
        - Session timeout settings/tools                          [ NONE ]
      - Checking default umask values
        - Checking default umask in /etc/bash.bashrc              [ NONE ]
        - Checking default umask in /etc/profile                  [ NONE ]
    
    [+] File systems
    ------------------------------------
      - Checking mount points
        - Checking /home mount point                              [ SUGGESTION ]
        - Checking /tmp mount point                               [ SUGGESTION ]
        - Checking /var mount point                               [ SUGGESTION ]
      - Query swap partitions (fstab)                             [ OK ]
      - Testing swap partitions                                   [ OK ]
      - Testing /proc mount (hidepid)                             [ SUGGESTION ]
      - Checking for old files in /tmp                            [ OK ]
      - Checking /tmp sticky bit                                  [ OK ]
      - ACL support root file system                              [ ENABLED ]
      - Mount options of /                                        [ NON DEFAULT ]
      - Checking Locate database                                  [ FOUND ]
      - Disable kernel support of some filesystems
        - Discovered kernel modules: cramfs freevxfs hfs hfsplus jffs2 squashfs udf
    
    [+] Storage
    ------------------------------------
      - Checking usb-storage driver (modprobe config)             [ NOT DISABLED ]
      - Checking USB devices authorization                        [ ENABLED ]
      - Checking firewire ohci driver (modprobe config)           [ NOT DISABLED ]
    
    [+] NFS
    ------------------------------------
      - Query rpc registered programs                             [ DONE ]
      - Query NFS versions                                        [ DONE ]
      - Query NFS protocols                                       [ DONE ]
      - Check running NFS daemon                                  [ FOUND ]
        - Checking /etc/exports                                   [ FOUND ]
        - Checking NFS client access                              [ OK ]
    
    [+] Name services
    ------------------------------------
      - Checking default DNS search domain                        [ FOUND ]
      - Searching DNS domain name                                 [ FOUND ]
          Domain name: cz
      - Checking nscd status                                      [ RUNNING ]
      - Checking /etc/hosts
        - Checking /etc/hosts (duplicates)                        [ OK ]
        - Checking /etc/hosts (hostname)                          [ OK ]
        - Checking /etc/hosts (localhost)                         [ SUGGESTION ]
        - Checking /etc/hosts (localhost to IP)                   [ OK ]
    
    [+] Ports and packages
    ------------------------------------
      - Searching package managers
        - Searching dpkg package manager                          [ FOUND ]
          - Querying package manager
        - Query unpurged packages                                 [ FOUND ]
      - Checking security repository in sources.list file or directory  [ WARNING ]
      - Checking vulnerable packages (apt-get only)               [ DONE ]
      - Checking package audit tool                               [ INSTALLED ]
        Found: apt-get
    
    [+] Networking
    ------------------------------------
      - Checking IPv6 configuration                               [ ENABLED ]
          Configuration method                                    [ AUTO ]
          IPv6 only                                               [ NO ]
      - Checking configured nameservers
        - Testing nameservers
            Nameserver: 77.242.95.2                               [ OK ]
            Nameserver: 192.168.1.1                               [ OK ]
        - Minimal of 2 responsive nameservers                     [ OK ]
      - Checking default gateway                                  [ DONE ]
      - Getting listening ports (TCP/UDP)                         [ DONE ]
          * Found 80 ports
      - Checking promiscuous interfaces                           [ OK ]
      - Checking waiting connections                              [ OK ]
      - Checking status DHCP client                               [ NOT ACTIVE ]
      - Checking for ARP monitoring software                      [ NOT FOUND ]
    
    [+] Printers and Spools
    ------------------------------------
      - Checking cups daemon                                      [ RUNNING ]
      - Checking CUPS configuration file                          [ OK ]
        - File permissions                                        [ OK ]
      - Checking CUPS addresses/sockets                           [ FOUND ]
      - Checking lp daemon                                        [ NOT RUNNING ]
    
    [+] Software: e-mail and messaging
    ------------------------------------
      - Postfix status                                            [ RUNNING ]
        - Postfix configuration                                   [ FOUND ]
          - Postfix configuration errors                          [ WARNING ]
          - Postfix banner                                        [ WARNING ]
      - Dovecot status                                            [ RUNNING ]
    
    [+] Software: firewalls
    ------------------------------------
      - Checking iptables kernel module                           [ FOUND ]
        - Checking iptables policies of chains                    [ FOUND ]
          - Checking chain INPUT (table: filter) policy           [ ACCEPT ]
        - Checking for empty ruleset                              [ WARNING ]
        - Checking for unused rules                               [ OK ]
      - Checking host based firewall                              [ ACTIVE ]
    
    [+] Software: webserver
    ------------------------------------
      - Checking Apache (binary /usr/sbin/apache2)                [ FOUND ]
          Info: Found 6 virtual hosts
        * Loadable modules                                        [ FOUND (107) ]
            - Found 107 loadable modules
              mod_evasive: anti-DoS/brute force                   [ NOT FOUND ]
              mod_reqtimeout/mod_qos                              [ FOUND ]
              ModSecurity: web application firewall               [ NOT FOUND ]
      - Checking nginx                                            [ NOT FOUND ]
    
    [+] SSH Support
    ------------------------------------
      - Checking running SSH daemon                               [ FOUND ]
        - Searching SSH configuration                             [ FOUND ]
        - SSH option: AllowTcpForwarding                          [ SUGGESTION ]
        - SSH option: ClientAliveCountMax                         [ SUGGESTION ]
        - SSH option: ClientAliveInterval                         [ OK ]
        - SSH option: Compression                                 [ SUGGESTION ]
        - SSH option: FingerprintHash                             [ NOT FOUND ]
        - SSH option: GatewayPorts                                [ OK ]
        - SSH option: IgnoreRhosts                                [ OK ]
        - SSH option: LoginGraceTime                              [ OK ]
        - SSH option: LogLevel                                    [ SUGGESTION ]
        - SSH option: MaxAuthTries                                [ SUGGESTION ]
        - SSH option: MaxSessions                                 [ SUGGESTION ]
        - SSH option: PermitRootLogin                             [ SUGGESTION ]
        - SSH option: PermitUserEnvironment                       [ OK ]
        - SSH option: PermitTunnel                                [ OK ]
        - SSH option: Port                                        [ SUGGESTION ]
        - SSH option: PrintLastLog                                [ OK ]
        - SSH option: Protocol                                    [ OK ]
        - SSH option: StrictModes                                 [ OK ]
        - SSH option: TCPKeepAlive                                [ SUGGESTION ]
        - SSH option: UseDNS                                      [ SUGGESTION ]
        - SSH option: VerifyReverseMapping                        [ NOT FOUND ]
        - SSH option: X11Forwarding                               [ SUGGESTION ]
        - SSH option: AllowAgentForwarding                        [ NOT FOUND ]
        - SSH option: AllowUsers                                  [ NOT FOUND ]
        - SSH option: AllowGroups                                 [ NOT FOUND ]
    
    [+] SNMP Support
    ------------------------------------
      - Checking running SNMP daemon                              [ NOT FOUND ]
    
    [+] Databases
    ------------------------------------
      - MySQL process status                                      [ FOUND ]
    
    [+] LDAP Services
    ------------------------------------
      - Checking OpenLDAP instance                                [ NOT FOUND ]
    
    [+] PHP
    ------------------------------------
      - Checking PHP                                              [ FOUND ]
        - Checking PHP disabled functions                         [ FOUND ]
        - Checking expose_php option                              [ ON ]
        - Checking enable_dl option                               [ OFF ]
        - Checking allow_url_fopen option                         [ ON ]
        - Checking allow_url_include option                       [ OFF ]
        - Checking PHP suhosin extension status                   [ WARNING ]
          - Suhosin simulation mode status                        [ WARNING ]
    
    [+] Squid Support
    ------------------------------------
      - Checking running Squid daemon                             [ FOUND ]
        - Searching Squid configuration                           [ FOUND ]
        - Checking Squid version                                  [ FOUND ]
        - Checking defined Squid options                          [ DONE ]
        - Checking Squid configuration file permissions           [ OK ]
        - Checking Squid access control
          - Checking Squid authentication methods                 [ FOUND ]
          - Checking Squid external authentication methods        [ NONE ]
          - Checking Access Control Lists                         [ 29 ACLs FOUND ]
          - Checking ACL 'Safe_ports' ports                       [ FOUND ]
          - Checking ACL 'Safe_ports' (port 22)                   [ NOT FOUND ]
          - Checking ACL 'Safe_ports' (port 23)                   [ NOT FOUND ]
          - Checking ACL 'Safe_ports' (port 25)                   [ NOT FOUND ]
        - Checking Squid Denial of Service tuning options
          - Checking option: reply_body_max_size                  [ NONE ]
        - Checking Squid general options
          - Checking option: httpd_suppress_version_string        [ NOT FOUND ]
    
    [+] Logging and files
    ------------------------------------
      - Checking for a running log daemon                         [ OK ]
        - Checking Syslog-NG status                               [ NOT FOUND ]
        - Checking systemd journal status                         [ NOT FOUND ]
        - Checking Metalog status                                 [ NOT FOUND ]
        - Checking RSyslog status                                 [ FOUND ]
        - Checking RFC 3195 daemon status                         [ NOT FOUND ]
        - Checking minilogd instances                             [ NOT FOUND ]
      - Checking logrotate presence                               [ OK ]
      - Checking log directories (static list)                    [ DONE ]
      - Checking open log files                                   [ DONE ]
      - Checking deleted files in use                             [ FILES FOUND ]
    
    [+] Insecure services
    ------------------------------------
      - Checking inetd status                                     [ NOT ACTIVE ]
    
    [+] Banners and identification
    ------------------------------------
      - /etc/issue                                                [ FOUND ]
        - /etc/issue contents                                     [ WEAK ]
      - /etc/issue.net                                            [ FOUND ]
        - /etc/issue.net contents                                 [ WEAK ]
    
    [+] Scheduled tasks
    ------------------------------------
      - Checking crontab/cronjob                                  [ DONE ]
      - Checking atd status                                       [ RUNNING ]
        - Checking at users                                       [ DONE ]
        - Checking at jobs                                        [ NONE ]
    
    [+] Accounting
    ------------------------------------
      - Checking accounting information                           [ NOT FOUND ]
      - Checking sysstat accounting data                          [ NOT FOUND ]
      - Checking auditd                                           [ NOT FOUND ]
    
    [+] Time and Synchronization
    ------------------------------------
      - NTP daemon found: ntpd                                    [ FOUND ]
      - Checking event based ntpdate (if-up)                      [ FOUND ]
      - Checking for a running NTP daemon or client               [ OK ]
      - Checking valid association ID's                           [ FOUND ]
      - Checking high stratum ntp peers                           [ OK ]
      - Checking unreliable ntp peers                             [ FOUND ]
      - Checking selected time source                             [ OK ]
      - Checking time source candidates                           [ OK ]
      - Checking falsetickers                                     [ OK ]
      - Checking NTP version                                      [ FOUND ]
    
    [+] Cryptography
    ------------------------------------
      - Checking for expired SSL certificates                     [ FOUND ]
    
    [+] Virtualization
    ------------------------------------
    
    [+] Containers
    ------------------------------------
    
    [+] Security frameworks
    ------------------------------------
      - Checking presence AppArmor                                [ NOT FOUND ]
      - Checking presence SELinux                                 [ NOT FOUND ]
      - Checking presence grsecurity                              [ NOT FOUND ]
      - Checking for implemented MAC framework                    [ NONE ]
    
    [+] Software: file integrity
    ------------------------------------
      - Checking file integrity tools
      - Checking presence integrity tool                          [ NOT FOUND ]
    
    [+] Software: System tooling
    ------------------------------------
      - Checking automation tooling
        - Ansible artifact                                        [ FOUND ]
      - Automation tooling                                        [ FOUND ]
      - Checking presence of Fail2ban                             [ FOUND ]
        - Checking Fail2ban jails                                 [ ENABLED ]
      - Checking for IDS/IPS tooling                              [ FOUND ]
    
    [+] Software: Malware
    ------------------------------------
      - Checking LMD (Linux Malware Detect)                       [ FOUND ]
    
    [+] File Permissions
    ------------------------------------
      - Starting file permissions check
    
    [+] Home directories
    ------------------------------------
      - Checking shell history files                              [ OK ]
    
    [+] Kernel Hardening
    ------------------------------------
      - Comparing sysctl key pairs with scan profile
        - fs.protected_hardlinks (exp: 1)                         [ DIFFERENT ]
        - fs.protected_symlinks (exp: 1)                          [ DIFFERENT ]
        - fs.suid_dumpable (exp: 0)                               [ OK ]
        - kernel.core_uses_pid (exp: 1)                           [ DIFFERENT ]
        - kernel.ctrl-alt-del (exp: 0)                            [ OK ]
        - kernel.dmesg_restrict (exp: 1)                          [ DIFFERENT ]
        - kernel.kptr_restrict (exp: 2)                           [ DIFFERENT ]
        - kernel.randomize_va_space (exp: 2)                      [ OK ]
        - kernel.sysrq (exp: 0)                                   [ DIFFERENT ]
        - net.ipv4.conf.all.accept_redirects (exp: 0)             [ DIFFERENT ]
        - net.ipv4.conf.all.accept_source_route (exp: 0)          [ OK ]
        - net.ipv4.conf.all.bootp_relay (exp: 0)                  [ OK ]
        - net.ipv4.conf.all.forwarding (exp: 0)                   [ OK ]
        - net.ipv4.conf.all.log_martians (exp: 1)                 [ DIFFERENT ]
        - net.ipv4.conf.all.mc_forwarding (exp: 0)                [ OK ]
        - net.ipv4.conf.all.proxy_arp (exp: 0)                    [ OK ]
        - net.ipv4.conf.all.rp_filter (exp: 1)                    [ DIFFERENT ]
        - net.ipv4.conf.all.send_redirects (exp: 0)               [ DIFFERENT ]
        - net.ipv4.conf.default.accept_redirects (exp: 0)         [ DIFFERENT ]
        - net.ipv4.conf.default.accept_source_route (exp: 0)      [ DIFFERENT ]
        - net.ipv4.conf.default.log_martians (exp: 1)             [ DIFFERENT ]
        - net.ipv4.icmp_echo_ignore_broadcasts (exp: 1)           [ OK ]
        - net.ipv4.icmp_ignore_bogus_error_responses (exp: 1)     [ OK ]
        - net.ipv4.tcp_syncookies (exp: 1)                        [ OK ]
        - net.ipv4.tcp_timestamps (exp: 0)                        [ DIFFERENT ]
        - net.ipv6.conf.all.accept_redirects (exp: 0)             [ DIFFERENT ]
        - net.ipv6.conf.all.accept_source_route (exp: 0)          [ OK ]
        - net.ipv6.conf.default.accept_redirects (exp: 0)         [ DIFFERENT ]
        - net.ipv6.conf.default.accept_source_route (exp: 0)      [ OK ]
    
    [+] Hardening
    ------------------------------------
        - Installed compiler(s)                                   [ FOUND ]
        - Installed malware scanner                               [ FOUND ]
    
    [+] Custom Tests
    ------------------------------------
      - Running custom tests...                                   [ NONE ]
    
    [+] Plugins (phase 2)
    ------------------------------------
    
    ================================================================================
    
      -[ Lynis 2.5.3 Results ]-
    
      Warnings (4):
      ----------------------------
      ! Can't find any security repository in /etc/apt/sources.list or sources.list.d directory [PKGS-7388]
          https://cisofy.com/controls/PKGS-7388/
    
      ! Found some information disclosure in SMTP banner (OS or software name) [MAIL-8818]
          https://cisofy.com/controls/MAIL-8818/
    
      ! iptables module(s) loaded, but no rules active [FIRE-4512]
          https://cisofy.com/controls/FIRE-4512/
    
      ! PHP option expose_php is possibly turned on, which can reveal useful information for attackers. [PHP-2372]
          https://cisofy.com/controls/PHP-2372/
    
      Suggestions (47):
      ----------------------------
      * Set a password on GRUB bootloader to prevent altering boot configuration (e.g. boot in single user mode without password) [BOOT-5122]
          https://cisofy.com/controls/BOOT-5122/
    
      * Install a PAM module for password strength testing like pam_cracklib or pam_passwdqc [AUTH-9262]
          https://cisofy.com/controls/AUTH-9262/
    
      * Configure minimum password age in /etc/login.defs [AUTH-9286]
          https://cisofy.com/controls/AUTH-9286/
    
      * Configure maximum password age in /etc/login.defs [AUTH-9286]
          https://cisofy.com/controls/AUTH-9286/
    
      * Default umask in /etc/login.defs could be more strict like 027 [AUTH-9328]
          https://cisofy.com/controls/AUTH-9328/
    
      * Default umask in /etc/init.d/rc could be more strict like 027 [AUTH-9328]
          https://cisofy.com/controls/AUTH-9328/
    
      * To decrease the impact of a full /home file system, place /home on a separated partition [FILE-6310]
          https://cisofy.com/controls/FILE-6310/
    
      * To decrease the impact of a full /tmp file system, place /tmp on a separated partition [FILE-6310]
          https://cisofy.com/controls/FILE-6310/
    
      * To decrease the impact of a full /var file system, place /var on a separated partition [FILE-6310]
          https://cisofy.com/controls/FILE-6310/
    
      * Disable drivers like USB storage when not used, to prevent unauthorized storage or data theft [STRG-1840]
          https://cisofy.com/controls/STRG-1840/
    
      * Disable drivers like firewire storage when not used, to prevent unauthorized storage or data theft [STRG-1846]
          https://cisofy.com/controls/STRG-1846/
    
      * Split resolving between localhost and the hostname of the system [NAME-4406]
          https://cisofy.com/controls/NAME-4406/
    
      * Purge old/removed packages (3 found) with aptitude purge or dpkg --purge command. This will cleanup old configuration files, cron jobs and startup scripts. [PKGS-7346]
          https://cisofy.com/controls/PKGS-7346/
    
      * Install debsums utility for the verification of packages with known good database. [PKGS-7370]
          https://cisofy.com/controls/PKGS-7370/
    
      * Consider running ARP monitoring software (arpwatch,arpon) [NETW-3032]
          https://cisofy.com/controls/NETW-3032/
    
      * Found a configuration error in Postfix [MAIL-8817]
        - Details  : /etc/postfix/main.cf
        - Solution : run postconf > /dev/null
          https://cisofy.com/controls/MAIL-8817/
    
      * You are advised to hide the mail_name (option: smtpd_banner) from your postfix configuration. Use postconf -e or change your main.cf file (/etc/postfix/main.cf) [MAIL-8818]
          https://cisofy.com/controls/MAIL-8818/
    
      * Install Apache mod_evasive to guard webserver against DoS/brute force attempts [HTTP-6640]
          https://cisofy.com/controls/HTTP-6640/
    
      * Install Apache modsecurity to guard webserver against web application attacks [HTTP-6643]
          https://cisofy.com/controls/HTTP-6643/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : AllowTcpForwarding (YES --> NO)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : ClientAliveCountMax (3 --> 2)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : Compression (DELAYED --> NO)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : LogLevel (INFO --> VERBOSE)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : MaxAuthTries (6 --> 2)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : MaxSessions (10 --> 2)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : PermitRootLogin (YES --> NO)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : Port (22 --> )
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : TCPKeepAlive (YES --> NO)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : UseDNS (YES --> NO)
          https://cisofy.com/controls/SSH-7408/
    
      * Consider hardening SSH configuration [SSH-7408]
        - Details  : X11Forwarding (YES --> NO)
          https://cisofy.com/controls/SSH-7408/
    
      * Change the expose_php line to: expose_php = Off [PHP-2372]
          https://cisofy.com/controls/PHP-2372/
    
      * Change the allow_url_fopen line to: allow_url_fopen = Off, to disable downloads via PHP [PHP-2376]
          https://cisofy.com/controls/PHP-2376/
    
      * Harden PHP by enabling suhosin extension [PHP-2379]
          https://cisofy.com/controls/PHP-2379/
    
      * Harden PHP by deactivating suhosin simulation mode [PHP-2379]
          https://cisofy.com/controls/PHP-2379/
    
      * Configure Squid option reply_body_max_size to limit the upper size of requests. [SQD-3630]
          https://cisofy.com/controls/SQD-3630/
    
      * Configure Squid option httpd_suppress_version_string (on) to suppress the version. [SQD-3680]
          https://cisofy.com/controls/SQD-3680/
    
      * Check what deleted files are still in use and why. [LOGG-2190]
          https://cisofy.com/controls/LOGG-2190/
    
      * Add a legal banner to /etc/issue, to warn unauthorized users [BANN-7126]
          https://cisofy.com/controls/BANN-7126/
    
      * Add legal banner to /etc/issue.net, to warn unauthorized users [BANN-7130]
          https://cisofy.com/controls/BANN-7130/
    
      * Enable process accounting [ACCT-9622]
          https://cisofy.com/controls/ACCT-9622/
    
      * Enable sysstat to collect accounting (no results) [ACCT-9626]
          https://cisofy.com/controls/ACCT-9626/
    
      * Enable auditd to collect audit information [ACCT-9628]
          https://cisofy.com/controls/ACCT-9628/
    
      * Check ntpq peers output for unreliable ntp peers and correct/replace them [TIME-3120]
          https://cisofy.com/controls/TIME-3120/
    
      * Check available certificates for expiration [CRYP-7902]
          https://cisofy.com/controls/CRYP-7902/
    
      * Install a file integrity tool to monitor changes to critical and sensitive files [FINT-4350]
          https://cisofy.com/controls/FINT-4350/
    
      * One or more sysctl values differ from the scan profile and could be tweaked [KRNL-6000]
          https://cisofy.com/controls/KRNL-6000/
    
      * Harden compilers like restricting access to root user only [HRDN-7222]
          https://cisofy.com/controls/HRDN-7222/
    
      Follow-up:
      ----------------------------
      - Show details of a test (lynis show details TEST-ID)
      - Check the logfile for all details (less /var/log/lynis.log)
      - Read security controls texts (https://cisofy.com)
      - Use --upload to upload data to central system (Lynis Enterprise users)
    
    ================================================================================
    
      Lynis security scan details:
    
      Hardening index : 64 [############        ]
      Tests performed : 247
      Plugins enabled : 0
    
      Components:
      - Firewall               [V]
      - Malware scanner        [V]
    
      Lynis Modules:
      - Compliance Status      [?]
      - Security Audit         [V]
      - Vulnerability Scan     [V]
    
      Files:
      - Test and debug information      : /var/log/lynis.log
      - Report data                     : /var/log/lynis-report.dat
    
    ================================================================================
    
      Lynis 2.5.3
    
      Auditing, system hardening, and compliance for UNIX-based systems
      (Linux, macOS, BSD, and others)
    
      2007-2017, CISOfy - https://cisofy.com/lynis/
      Enterprise support available (compliance, plugins, interface and tools)
    
    ================================================================================
    

    V tomto formuláři můžete formulovat svou stížnost ohledně příspěvku. Nejprve vyberte typ akce, kterou navrhujete provést s diskusí či příspěvkem. Potom do textového pole napište důvody, proč by měli admini provést vaši žádost, problém nemusí být patrný na první pohled. Odkaz na příspěvek bude přidán automaticky.

    Vaše jméno
    Váš email
    Typ požadavku
    Slovní popis
    ISSN 1214-1267   www.czech-server.cz
    © 1999-2015 Nitemedia s. r. o. Všechna práva vyhrazena.