diff options
author | Michael Boelen <michael.boelen@cisofy.com> | 2018-01-11 12:19:16 +0300 |
---|---|---|
committer | Michael Boelen <michael.boelen@cisofy.com> | 2018-01-11 12:19:16 +0300 |
commit | 1504370e416240d486e7aa1f88fbd7277c97e77d (patch) | |
tree | ad37fdb3ad14da1a42c4f17ea086c8b18ef4b787 /include/tests_kernel_hardening | |
parent | 66f8cb2441411c27b4d0ad3c0554b55af3c29178 (diff) |
Added solution, extended timestamps key values, allow multiple values
Diffstat (limited to 'include/tests_kernel_hardening')
-rw-r--r-- | include/tests_kernel_hardening | 44 |
1 files changed, 27 insertions, 17 deletions
diff --git a/include/tests_kernel_hardening b/include/tests_kernel_hardening index 54479895..7ed07e3d 100644 --- a/include/tests_kernel_hardening +++ b/include/tests_kernel_hardening @@ -71,32 +71,42 @@ for I in ${DATA_TO_SCAN}; do tFINDkey=$(echo ${I} | ${AWKBINARY} -F\; '{ print $2 }') - tFINDexpvalue=$(echo ${I} | ${AWKBINARY} -F\; '{ print $3 }') - tFINDhp=$(echo ${I} | ${AWKBINARY} -F\; '{ print $4 }' | ${GREPBINARY} "[0-9]") - tFINDdesc=$(echo ${I} | ${AWKBINARY} -F\; '{ print $5 }' | ${SEDBINARY} 's/-space-/ /g') - tFINDcurvalue=$(${SYSCTL_READKEY} ${tFINDkey} 2> /dev/null) - if [ ! "${tFINDcurvalue}" = "" ]; then - if [ "${tFINDexpvalue}" = "${tFINDcurvalue}" ]; then - LogText "Result: sysctl key ${tFINDkey} contains equal expected and current value (${tFINDexpvalue})" - Display --indent 4 --text "- ${tFINDkey} (exp: ${tFINDexpvalue})" --result "${STATUS_OK}" --color GREEN - AddHP ${tFINDhp} ${tFINDhp} + if ! SkipAtomicTest "${TEST_NO}:${tFINDkey}"; then + tFINDexpvalue=$(echo ${I} | ${AWKBINARY} -F\; '{ print $3 }' | ${TRBINARY} '|' ' ') + tFINDhp=$(echo ${I} | ${AWKBINARY} -F\; '{ print $4 }' | ${GREPBINARY} "[0-9]") + tFINDdesc=$(echo ${I} | ${AWKBINARY} -F\; '{ print $5 }' | ${SEDBINARY} 's/-space-/ /g') + tFINDcurvalue=$(${SYSCTL_READKEY} ${tFINDkey} 2> /dev/null) + if [ ! -z "${tFINDcurvalue}" ]; then + positive_match=0 + for value in ${tFINDexpvalue}; do + if [ "${value}" = "${tFINDcurvalue}" ]; then + positive_match=1 + fi + done + if [ ${positive_match} -eq 1 ]; then + LogText "Result: sysctl key ${tFINDkey} contains equal expected and current value (${tFINDexpvalue})" + Display --indent 4 --text "- ${tFINDkey} (exp: ${tFINDexpvalue})" --result "${STATUS_OK}" --color GREEN + AddHP ${tFINDhp} ${tFINDhp} + else + LogText "Result: sysctl key ${tFINDkey} has a different value than expected in scan profile. Expected=${tFINDexpvalue}, Real=${tFINDcurvalue}" + Display --indent 4 --text "- ${tFINDkey} (exp: ${tFINDexpvalue})" --result DIFFERENT --color RED + AddHP 0 ${tFINDhp} + FOUND=1 + N=$((N + 1)) + ReportDetails --test "${TEST_NO}" --service "sysctl" --field "${tFINDkey}" --value "${tFINDcurvalue}" --preferredvalue "${tFINDexpvalue}" --description "${tFINDdesc}" + fi else - LogText "Result: sysctl key ${tFINDkey} has a different value than expected in scan profile. Expected=${tFINDexpvalue}, Real=${tFINDcurvalue}" - Display --indent 4 --text "- ${tFINDkey} (exp: ${tFINDexpvalue})" --result DIFFERENT --color RED - AddHP 0 ${tFINDhp} - FOUND=1 - N=$((N + 1)) - ReportDetails --test "${TEST_NO}" --service "sysctl" --field "${tFINDkey}" --value "${tFINDcurvalue}" --preferredvalue "${tFINDexpvalue}" --description "${tFINDdesc}" + LogText "Result: key ${tFINDkey} does not exist on this machine" fi else - LogText "Result: key ${tFINDkey} does not exist on this machine" + LogText "Skipped test for ${tFINDkey} via profile" fi done # Add suggestion if one or more sysctls have a different value than scan profile if [ ${FOUND} -eq 1 ]; then LogText "Result: found ${N} keys that can use tuning, according scan profile" - ReportSuggestion ${TEST_NO} "One or more sysctl values differ from the scan profile and could be tweaked" + ReportSuggestion ${TEST_NO} "One or more sysctl values differ from the scan profile and could be tweaked" "" "Change sysctl value or disable test (skip-test=${TEST_NO}:<sysctl-key>)" fi fi # |