Welcome to mirror list, hosted at ThFree Co, Russian Federation.

tests_databases « include - github.com/CISOfy/lynis.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
blob: ca7d34e00f6ca1ee2f0c61c7dc7ce2b7f220af17 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
#!/bin/sh

#################################################################################
#
#   Lynis
# ------------------
#
# Copyright 2007-2013, Michael Boelen
# Copyright 2007-2017, CISOfy
#
# Website  : https://cisofy.com
# Blog     : http://linux-audit.com
# GitHub   : https://github.com/CISOfy/lynis
#
# Lynis comes with ABSOLUTELY NO WARRANTY. This is free software, and you are
# welcome to redistribute it under the terms of the GNU General Public License.
# See LICENSE file for usage of this software.
#
#################################################################################
#
# Databases
#
#################################################################################
#
    # Paths to DATADIR
    sMYSQLDBPATHS="${ROOTDIR}var/lib/mysql"
    # Paths to my.cnf
    sMYCNFLOCS="${ROOTDIR}etc/mysql/my.cnf ${ROOTDIR}usr/etc/my.cnf"
    REDIS_CONFIGURATION_FILES=""
    REDIS_CONFIGURATION_FOUND=0
#
#################################################################################
#
    InsertSection "Databases"

    # Test        : DBS-1804
    # Description : Check if MySQL is being used
    Register --test-no DBS-1804 --weight L --network NO --category security --description "Checking active MySQL process"
    if [ ${SKIPTEST} -eq 0 ]; then
        FIND=`${PSBINARY} ax | ${EGREPBINARY} "mysqld|mysqld_safe" | ${GREPBINARY} -v "grep"`
        if [ "${FIND}" = "" ]; then
            if [ ${DEBUG} -eq 1 ]; then Display --indent 2 --text "- MySQL process status" --result "${STATUS_NOT_FOUND}" --color WHITE --debug; fi
            LogText "Result: MySQL process not active"
          else
            Display --indent 2 --text "- MySQL process status" --result "${STATUS_FOUND}" --color GREEN
            LogText "Result: MySQL is active"
            MYSQL_RUNNING=1
            DATABASE_ENGINE_RUNNING=1
            Report "mysql_running=${MYSQL_RUNNING}"
        fi
    fi
#
#################################################################################
#
    # Test        : DBS-1808
    # Description : Check MySQL data directory
    #Register --test-no DBS-1808 --weight L --network NO --category security --description "Checking MySQL data directory"
    #if [ ${SKIPTEST} -eq 0 ]; then
    #fi
#
#################################################################################
#
    # Test        : DBS-1812
    # Description : Check data directory permissions
    #Register --test-no DBS-1812 --weight L --network NO --category security --description "Checking MySQL data directory permissions"
    #if [ ${SKIPTEST} -eq 0 ]; then
    #fi
#
#################################################################################
#
    # Test        : DBS-1816
    # Description : Check empty MySQL root password
    # Notes       : Only perform test when MySQL is running and client is available
    if [ ! "${MYSQLCLIENTBINARY}" = "" -a ${MYSQL_RUNNING} -eq 1 ]; then PREQS_MET="YES"; SKIPREASON=""; else PREQS_MET="NO"; SKIPREASON="MySQL not installed, or not running"; fi
    Register --test-no DBS-1816 --preqs-met ${PREQS_MET} --skip-reason "${SKIPREASON}" --weight L --network NO --category security --description "Checking MySQL root password"
    if [ ${SKIPTEST} -eq 0 ]; then
        LogText "Test: Trying to login to local MySQL server without password"
        FIND=$(${MYSQLCLIENTBINARY} -u root --password= --silent --batch --execute="" 2> /dev/null; echo $?)
        if [ "${FIND}" = "0" ]; then
            LogText "Result: Login succeeded, no MySQL root password set!"
            ReportWarning ${TEST_NO} "No MySQL root password set"
            Display --indent 4 --text "- Checking empty MySQL root password" --result "${STATUS_WARNING}" --color RED
            AddHP 0 5
        else
            LogText "Result: Login did not succeed, so a MySQL root password is set"
            Display --indent 4 --text "- Checking MySQL root password" --result "${STATUS_OK}" --color GREEN
            AddHP 2 2
        fi
      else
        LogText "Test skipped, MySQL daemon not running or no MySQL client available"
    fi
#
#################################################################################
#
    # Test        : DBS-1826
    # Description : Check if PostgreSQL is being used
    Register --test-no DBS-1826 --weight L --network NO --category security --description "Checking active PostgreSQL processes"
    if [ ${SKIPTEST} -eq 0 ]; then
        if IsRunning "postgres:"; then
            Display --indent 2 --text "- PostgreSQL processes status" --result "${STATUS_FOUND}" --color GREEN
            LogText "Result: PostgreSQL is active"
            POSTGRESQL_RUNNING=1
            DATABASE_ENGINE_RUNNING=1
            Report "postgresql_running=${POSTGRESQL_RUNNING}"
        else
            if [ ${DEBUG} -eq 1 ]; then Display --indent 2 --text "- PostgreSQL processes status" --result "${STATUS_NOT_FOUND}" --color WHITE --debug; fi
            LogText "Result: PostgreSQL process not active"
        fi
    fi
#
#################################################################################
#
    # Test        : DBS-1840
    # Description : Check if Oracle is being used
    # Notes       : tnslsnr: Oracle listener
    #               pmon: process monitor
    #               smon: system monitor
    #               dbwr: database writer
    #               lgwr: log writer
    #               arch: archiver (optional)
    #               ckpt: checkpoint (optional)
    #               reco: recovery (optional)
    Register --test-no DBS-1840 --weight L --network NO --category security --description "Checking active Oracle processes"
    if [ ${SKIPTEST} -eq 0 ]; then
        FIND=$(${PSBINARY} ax | ${EGREPBINARY} "ora_pmon|ora_smon|tnslsnr" | ${GREPBINARY} -v "grep")
        if [ "${FIND}" = "" ]; then
            if [ ${DEBUG} -eq 1 ]; then Display --indent 2 --text "- Oracle processes status" --result "${STATUS_NOT_FOUND}" --color WHITE --debug; fi
            LogText "Result: Oracle process(es) not active"
        else
            Display --indent 2 --text "- Oracle processes status" --result "${STATUS_FOUND}" --color GREEN
            LogText "Result: Oracle is active"
            ORACLE_RUNNING=1
            DATABASE_ENGINE_RUNNING=1
            Report "oracle_running=${ORACLE_RUNNING}"
        fi
    fi
#
#################################################################################
#
    # Test        : DBS-1842
    # Description : Check Oracle home paths from oratab
    #Register --test-no DBS-1842 --weight L --network NO --category security --description "Checking Oracle home paths"
    #if [ ${SKIPTEST} -eq 0 ]; then
    # if [ -f /etc/oratab ]; then
    #  FIND=`${GREPBINARY} -v "#" /etc/oratab | ${AWKBINARY} -F: "{ print $2 }"`
    # fi
    #fi
#
#################################################################################
#
    # Test        : DBS-1860
    # Description : Checks if a DB2 instance is currently runnigng
    Register --test-no DBS-1860 --weight L --network NO --category security --description "Checking active DB2 instances"
    if [ ${SKIPTEST} -eq 0 ]; then
        if IsRunning db2sysc; then
            Display --indent 2 --text "- DB2 instance running" --result "${STATUS_FOUND}" --color GREEN
            LogText "Result: At least one DB2 instance is running"
            DB2_RUNNING=1
            DATABASE_ENGINE_RUNNING=1
            Report "db2_running=${DB2_RUNNING}"
        else
            if [ ${DEBUG} -eq 1 ]; then Display --indent 2 --text "- DB2 instance running" --result "${STATUS_NOT_FOUND}" --color WHITE --debug; fi
            LogText "Result: No DB2 instances are running"
        fi
    fi
#
#################################################################################
#
    # Test        : DBS-1880
    # Description : Determine if redis is running
    Register --test-no DBS-1880 --weight L --network NO --category security --description "Check for active Redis server"
    if [ ${SKIPTEST} -eq 0 ]; then
        if IsRunning redis-server; then
            Display --indent 2 --text "- Redis (server) status" --result "${STATUS_FOUND}" --color GREEN
            LogText "Result: Redis is running"
            REDIS_RUNNING=1
            DATABASE_ENGINE_RUNNING=1
            Report "redis_server_running=${REDIS_RUNNING}"
        else
            if [ ${DEBUG} -eq 1 ]; then Display --indent 2 --text "- Redis (server) status" --result "${STATUS_NOT_FOUND}" --color WHITE --debug; fi
            LogText "Result: No Redis processes are running"
        fi
    fi
#
#################################################################################
#
    # Test        : DBS-1882
    # Description : Determine Redis configuration
    if [ ${REDIS_RUNNING} -eq 1 ]; then PREQS_METS="YES"; else PREQS_MET="NO"; SKIPREASON="Redis not running"; fi
    Register --test-no DBS-1882 --weight L --network NO --preqs-met "${PREQS_MET}" --skip-reason "${SKIPREASON}" --category security --description "Redis configuration file"
    if [ ${SKIPTEST} -eq 0 ]; then
        PATHS="${ROOTDIR}etc/redis ${ROOTDIR}usr/local/etc/redis"
        FOUND=0
        for DIR in ${PATHS}; do
            LogText "Action: scanning directory (${DIR}) for Redis configuration files"
            FILES=$(${LSBINARY} ${DIR}/*.conf 2> /dev/null)
            if [ ! -z "${FILES}" ]; then
                for CONFFILE in ${FILES}; do
                    if FileIsReadable ${CONFFILE}; then
                        LogText "Action: checking if ${CONFFILE} is a Sentinel configuration file"
                        # Exclude Sentinel configuration file
                        FIND=$(${GREPBINARY} "^sentinel " ${CONFFILE})
                        if [ ! -z "${FIND}" ]; then
                            LogText "Result: file is a Sentinel configuration file, skipping it"
                        else
                            LogText "Result: file is NOT a Sentinel configuration file. Now scanning if it is a Redis configuration file"
                            FIND=$(${GREPBINARY} "Redis" ${CONFFILE})
                            if [ ! -z "${FIND}" ]; then
                                REDIS_CONFIGURATION_FILES="${REDIS_CONFIGURATION_FILES} ${CONFFILE}"
                                REDIS_CONFIGURATION_FOUND=1
                                LogText "Result: found a Redis configuration file (${CONFFILE})"
                            else
                                LogText "Result: this file does not look like a Redis file  (${CONFFILE})"
                            fi
                        fi
                    else
                        LogText "Could not read this file, so skipping it"
                    fi
                done
            else
                LogText "Result: no configuration files found in this directory"
            fi
        done
        # Sort the list of discovered configuration files so we can make them unique
        REDIS_CONFIGURATION_FILES=$(echo ${REDIS_CONFIGURATION_FILES} | ${SEDBINARY} 's/^ //' | ${TRBINARY} ' ' '\n' | ${SORTBINARY} | ${UNIQBINARY} | ${TRBINARY} '\n' ' ')
        for FILE in ${REDIS_CONFIGURATION_FILES}; do
            if IsWorldReadable ${FILE}; then
                LogText "Result: configuration file ${FILE} is world readable, this might leak sensitive information!"
                ReportWarning "${TEST_NO}" "Redis configuration file ${FILE} is world readable and might leak sensitive details" "${FILE}" "Use chmod 640 to change file permissions"
            else
                LogText "Result: great, configuration file ${FILE} is not world readable"
            fi
        done
        if [ ${REDIS_CONFIGURATION_FOUND} -eq 0 ]; then ReportException "${TEST_NO}" "Found Redis, but no configuration file. Report this if you know where it is located on your system."; fi
    fi
#
#################################################################################
#
    # Test        : DBS-1884
    # Description : Determine Redis configuration option: requirepass
    if [ ${REDIS_RUNNING} -eq 1 -a ${REDIS_CONFIGURATION_FOUND} -eq 1 ]; then PREQS_METS="YES"; else PREQS_MET="NO"; SKIPREASON="Redis not running, or no configuration file found"; fi
    Register --test-no DBS-1884 --weight L --network NO --preqs-met "${PREQS_MET}" --skip-reason "${SKIPREASON}" --category security --description "Redis: requirepass option configured"
    if [ ${SKIPTEST} -eq 0 ]; then
        for FILE in ${REDIS_CONFIGURATION_FILES}; do
            if FileIsReadable ${FILE}; then
                if SearchItem "^requirepass" "${FILE}" "--sensitive"; then
                    LogText "Result: found 'requirepass' configured"
                    AddHP 3 3
                    Display --indent 4 --text "- Redis (requirepass configured)" --result "${STATUS_FOUND}" --color GREEN
                    Report "redis_requirepass=1"
                else
                    AddHP 0 3
                    Display --indent 4 --text "- Redis (requirepass configured)" --result "${STATUS_NOT_FOUND}" --color YELLOW
                    ReportSuggestion "${TEST_NO}" "Configure the 'requirepass' setting for Redis" "${FILE}" "text:configure 'requirepass' setting in ${FILE}"
                    Report "redis_requirepass=0"
                fi
            else
                LogText "Result: test skipped, as we can't read configuration file"
            fi
        done
    fi
#
#################################################################################
#
    # Test        : DBS-1886
    # Description : Determine Redis configuration option: rename-command CONFIG
    if [ ${REDIS_RUNNING} -eq 1 -a ${REDIS_CONFIGURATION_FOUND} -eq 1 ]; then PREQS_METS="YES"; else PREQS_MET="NO"; SKIPREASON="Redis not running, or no configuration found"; fi
    Register --test-no DBS-1886 --weight L --network NO --preqs-met "${PREQS_MET}" --skip-reason "${SKIPREASON}" --category security --description "Redis: rename-command CONFIG used"
    if [ ${SKIPTEST} -eq 0 ]; then
        for FILE in ${REDIS_CONFIGURATION_FILES}; do
            if FileIsReadable ${FILE}; then
                if SearchItem "^rename-command CONFIG" "${FILE}" "--sensitive"; then
                    LogText "Result: found 'rename-command CONFIG' configured"
                    AddHP 3 3
                    Display --indent 4 --text "- Redis (rename of CONFIG command)" --result "${STATUS_FOUND}" --color GREEN
                    Report "redis_rename_command_config=1"
                else
                    AddHP 0 3
                    Display --indent 4 --text "- Redis (rename of CONFIG command)" --result "${STATUS_NOT_FOUND}" --color YELLOW
                    ReportSuggestion "${TEST_NO}" "Use the 'rename-command CONFIG' setting for Redis" "${FILE}" "text:configure 'rename-command CONFIG' in ${FILE}"
                    Report "redis_rename_command_config=0"
                fi
            else
                LogText "Result: test skipped, as we can't read configuration file"
            fi
        done
    fi
#
#################################################################################
#
    # Test        : DBS-1888
    # Description : Determine Redis configuration option: bind on localhost
    if [ ${REDIS_RUNNING} -eq 1 -a ${REDIS_CONFIGURATION_FOUND} -eq 1 ]; then PREQS_METS="YES"; else PREQS_MET="NO"; SKIPREASON="Redis not running, or no configuration found"; fi
    Register --test-no DBS-1888 --weight L --network NO --preqs-met "${PREQS_MET}" --skip-reason "${SKIPREASON}" --category security --description "Redis: bind on localhost"
    if [ ${SKIPTEST} -eq 0 ]; then
        for FILE in ${REDIS_CONFIGURATION_FILES}; do
            if FileIsReadable ${FILE}; then
                if SearchItem "^bind (localhost|127\.)" "${FILE}" "--sensitive"; then
                    LogText "Result: found 'bind on localhost' configured"
                    AddHP 3 3
                    Display --indent 4 --text "- Redis (bind on localhost)" --result "${STATUS_FOUND}" --color GREEN
                    Report "redis_bind_localhost=1"
                else
                    AddHP 0 3
                    Display --indent 4 --text "- Redis (bind on localhost)" --result "${STATUS_NOT_FOUND}" --color YELLOW
                    ReportSuggestion "${TEST_NO}" "Use 'bind' setting to listen on localhost for Redis instance" "${FILE}" "text:configure 'bind localhost' in ${FILE}"
                    Report "redis_bind_localhost=0"
                fi
            else
                LogText "Result: test skipped, as we can't read configuration file"
            fi
        done
    fi
#
#################################################################################
#
    if [ ${DATABASE_ENGINE_RUNNING} -eq 0 ]; then
        Display --indent 4 --text "No database engines found"
    fi
#
#################################################################################
#

WaitForKeyPress

#
#================================================================================
# Lynis - Security Auditing and System Hardening for Linux and UNIX - https://cisofy.com