Welcome to mirror list, hosted at ThFree Co, Russian Federation.

github.com/CISOfy/lynis.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2021-10-26allow unknown number of spaces in modprobe blacklistsThomas Sjögren
Signed-off-by: Thomas Sjögren <konstruktoid@users.noreply.github.com>
2021-07-29Update tests_networkingMichael Boelen
2021-07-24grep options change from gnu to posixZachary Lee Andrews
fix issue #1167
2021-01-07Preparation for release 3.0.3Michael Boelen
2020-12-16Adding and improvement translated stringsStéphane
2020-12-15Merge pull request #1060 from Varbin/solaris-netstatMichael Boelen
[NETW-3012] Use netstat on Solaris to gather listening ports
2020-11-14Use the new status strings in testsSimon Biewald
See-Also: HEAD^ Signed-off-by: Simon Biewald <simon@fam-biewald.de>
2020-11-09Merge pull request #1061 from Varbin/solaris-hostnameMichael Boelen
Simplify tr hostname checking expression
2020-10-31Use correct character classSimon Biewald
Signed-off-by: Simon Biewald <simon@fam-biewald.de>
2020-10-25Reduce tr hostname checking expressionSimon Biewald
Solaris' tr does not support full regular expressions.
2020-10-25Use netstat on Solaris to gather listening portsSimon Biewald
2020-10-22Add translate function for all sectionsStéphane
+ add EN and FR up to date languages files
2020-06-02Adds uppercase option to the hostname validation regexIain Cuthbertson
2020-04-04[NETW-2400] Improved loggingMichael Boelen
2020-04-04Added new test NETW-2400Michael Boelen
2020-04-03[NETW-2706] allow usage of systemd-resolve and resolvectl, improved screen ↵Michael Boelen
output and logging
2020-04-03[NETW-2706] redirect errors to stderrMichael Boelen
2020-03-25Added notes to NETW-3200 for future extending this testMichael Boelen
2020-03-25[NETW-3200] corrected testMichael Boelen
2020-03-20Updated date/yearMichael Boelen
2020-03-20Check DNSSEC status with resolvectl when availableTopi Miettinen
'resolvectl statistics' shows if DNSSEC is supported by systemd-resolved and upstream DNS servers. Signed-off-by: Topi Miettinen <toiwoton@gmail.com>
2020-01-28NETW-3014: Report correct promisc interfaceSascha Holzleiter
2020-01-11[NETW-3015] check for promiscuity value that is higher than 0 instead of just 1Michael Boelen
2019-12-18Code style improvement: quote argumentMichael Boelen
2019-09-13Tests using lsof may ignore threads (if supported)Michael Boelen
2019-08-28Disabled suggestion for now, as some people will just install a suggested ↵Michael Boelen
tool to comply instead of determining if it really makes sense. So this suggestion requires more explanation before people turning it on. Also, promisc mode may be impacted, so users see a new issue show up while they just resolved another.
2019-08-22Added NETW-3200Michael Boelen
2019-08-04Don't quote in for loop to prevent glueing individual lines togetherMichael Boelen
2019-07-26Use IsRunning exit code instead of variableMichael Boelen
2019-07-16Formatting and improved loggingMichael Boelen
2019-07-16Use -n instead of ! -zMichael Boelen
2019-07-14[NETW-3032] small rewrite of test and extended with addrwatchMichael Boelen
2019-06-24[NETW-3012] make ss command output preferred for Linux system and changed ↵Michael Boelen
output format
2019-05-16Move state recording to report sectionMichael Boelen
2019-03-21[NETW-3015] added support for ip binaryMichael Boelen
2019-02-28Fix #638. (#640)dataking
* fix for issue #453; simply add RPi/Raspian path to PAM_FILE_LOCATIONS * Only use data before # to handle inline comments in /etc/resolv.conf.
2019-01-31Changed year and preparing for new releaseMichael Boelen
2018-06-26query DNS with FQDN (#555)Thomas Sjögren
Signed-off-by: Thomas Sjögren <konstruktoid@users.noreply.github.com>
2018-05-01[NETW-2704] added support for local resolver used on Ubuntu 18.04Michael Boelen
2018-01-21Fix/amend DHCP client detection (#513)melak
- dhcpd is a server; the client is dhcpcd - While here, add udhcpc to the list of recognised DHCP clients
2018-01-11Changed yearMichael Boelen
2017-09-17Add 127.0.1.1 to NETW-2704 testMichael Boelen
2017-09-16Minor changes to using local resolversMichael Boelen
2017-09-16[NETW-2705] This is related to #437 and resolvconf but is split up. (#459)Ben Abrams
This specifically makes it so that when `/etc/resolv.conf` has one or more nameservers matching `127.0.[0-1].1` it should not warn as it is using local resolvers. We are simply using `grep -c "127.0.[0-1].1" /etc/resolv.conf` to determine this.
2017-08-03[NETW-3006] Updated detection of MAC addresses on LinuxMichael Boelen
2017-04-30[bulk change] cleaning up, code enhancements, initialization of variables, ↵Michael Boelen
and new tests
2017-04-23Code enhancementsMichael Boelen
2017-03-07Lots of cleanups (#366)hlein
* Description fix: SafePerms works on files not dirs. All uses of SafePerms are on files (and indeed, it would reject directories which would have +x set). * Lots of whitespace cleanups. Enforce everywhere(?) the same indentations for if/fi blocks. The standard for the Lynis codebase is 4 spaces. But sometimes it's 1, sometimes 3, sometimes 8. These patches standardize all(?) if blocks but _not_ else's (which are usually indented 2, but sometimes zero); I was too lazy to identify those (see below). This diff is giant, but should not change code behavior at all; diff -w shows no changes apart from whitespace. FWIW I identified instances to check by using: perl -ne 'if ($oldfile ne $ARGV) { $.=1; $oldfile=$ARGV; }; chomp; if ($spaces) { next unless /^( *)([^ ]+)/; $newspaces=length($1); $firsttok = $2; next unless defined($firsttok); $offset = ($firsttok eq "elif" ? 0 : 4); if ($newspaces != $spaces + $offset) { print "$ARGV:$ifline\n$ARGV:$.:$_\n\n" }; $ifline=""; $spaces=""; } if (/^( *)if (?!.*[; ]fi)/) { $ifline = "$.:$_"; $spaces = length($1); }' $(find . -type f -print0 | xargs -0 file | egrep shell | cut -d: -f1) Which produced output like: ./extras/build-lynis.sh:217: if [ ${VERSION_IN_SPECFILE} = "" -o ! "${VERSION_IN_SPECFILE}" = "${LYNIS_VERSION}" ]; then ./extras/build-lynis.sh:218: echo "[X] Version in specfile is outdated" ./plugins/plugin_pam_phase1:69: if [ -d ${PAM_DIRECTORY} ]; then ./plugins/plugin_pam_phase1:70: LogText "Result: /etc/pam.d exists" ...There's probably formal shellscript-beautification tools that I'm oblivious about. * More whitespace standardization. * Fix a syntax error. This looks like an if [ foo -o bar ]; was converted to if .. elif, but incompletely. * Add whitespace before closing ]. Without it, the shell thinks the ] is part of the last string, and emits warnings like: .../lynis/include/tests_authentication: line 1028: [: missing `]'
2017-03-06Various cleanups (#363)hlein
* Typo fix. * Style change: always use $(), never ``. The Lynis code already mostly used $(), but backticks were sprinkled around. Converted all of them. * Lots of minor spelling/typo fixes. FWIW these were found with: find . -type f -print0 | xargs -0 cat | aspell list | sort -u | egrep '^[a-z]+$' | less And then reviewing the list to pick out things that looked like misspelled words as opposed to variables, etc., and then manual inspection of context to determine the intention.
2017-02-09Changed date and preparing for release2.4.1Michael Boelen