Files
audit-web/audit_check_script/audit_cis_rhel_new.sh
T
2026-08-26 14:11:37 +07:00

3993 lines
409 KiB
Bash
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
#!/bin/bash
############################################################################
# Lấy thông tin thiết bị
echo "Operating System: $(cat /etc/system-release | cut -d= -f2 | tr -d '"')"
echo "Hostname: $(hostname -I)"
echo "Time: $(date +"%Y-%m-%d %H:%M:%S")"
echo "############################################################################"
##################################################################################################################
# Tự động kiểm tra IPv6 có được sử dụng hay không
IPV6_ENABLED=0
# Kiểm tra IPv6 có được enable trong kernel không
if [ -f /proc/net/if_inet6 ] && [ -s /proc/net/if_inet6 ]; then
# Kiểm tra có interface nào có IPv6 address (ngoài loopback ::1)
if ip -6 addr show 2>/dev/null | grep -q "inet6" && \
ip -6 addr show 2>/dev/null | grep "inet6" | grep -vq "::1/128"; then
IPV6_ENABLED=1
echo "IPv6 Status: ENABLED"
else
echo "IPv6 Status: DISABLED (no IPv6 addresses assigned)"
fi
else
echo "IPv6 Status: DISABLED (kernel support not available)"
fi
echo "############################################################################"
##################################################################################################################
# Chỉnh sửa hoặc tạo một file trong thư mục /etc/modprobe.d/filesystem.conf và thêm vào những dòng sau:
# install cramfs /bin/true
# Thực hiện câu lệnh sau để gỡ bỏ các filesystem không thông dụng khỏi kernel:
# rmmod cramfs
if [[ $(lsmod | grep cramfs | wc -l) -ne 0 || ($(modprobe -n -v cramfs | grep -P "^\h*install /bin/true" 2>/dev/null | wc -l) -eq 0 && ($(modprobe -n -v cramfs 2>/dev/null | grep -P "^\h*install /bin/false" | wc -l) -eq 0 || $(grep -P "^\h*blacklist\s+cramfs" /etc/modprobe.d/*.conf 2>/dev/null | wc -l) -eq 0)) ]]; then
echo "{\"1.1.1.1. Cấu hình vô hiệu hoá cramfs filesystem\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa hoặc tạo một file trong thư mục /etc/modprobe.d/filesystem.conf và thêm vào những dòng sau:
# install cramfs /bin/true
# Thực hiện câu lệnh sau để gỡ bỏ các filesystem không thông dụng khỏi kernel:
# rmmod cramfs"
if [ $(lsmod | grep cramfs | wc -l) -ne 0 ]; then echo "-------------------"; echo "#lsmod | grep cramfs -eq 0 ";lsmod | grep cramfs; fi
if [ $(modprobe -n -v cramfs 2>/dev/null | grep -P "^\h*install /bin/true" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#modprobe -n -v cramfs 2>/dev/null | grep -P \"^\\h*install /bin/true\" -ne 0 ";modprobe -n -v cramfs 2>/dev/null | grep -P "^\h*install /bin/true"; fi
if [ $(modprobe -n -v cramfs 2>/dev/null | grep -P "^\h*install /bin/false" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#modprobe -n -v cramfs 2>/dev/null | grep -P \"^\\h*install /bin/false\" -ne 0 ";modprobe -n -v cramfs 2>/dev/null | grep -P "^\h*install /bin/false"; fi
if [ $(grep -P "^\h*blacklist\s+cramfs" /etc/modprobe.d/*.conf 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*blacklist\s+cramfs\" /etc/modprobe.d/*.conf 2>/dev/null -ne 0 ";grep -P "^\h*blacklist\s+cramfs" /etc/modprobe.d/*.conf 2>/dev/null; fi
echo "######################################"
else
echo "{\"1.1.1.1. Cấu hình vô hiệu hoá cramfs filesystem\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa hoặc tạo một file trong thư mục /etc/modprobe.d/filesystem.conf và thêm vào những dòng sau:
# install freevxfs /bin/true
# Thực hiện câu lệnh sau để gỡ bỏ các filesystem không thông dụng khỏi kernel:
# rmmod freevxfs
if [[ $(lsmod | grep freevxfs | wc -l) -ne 0 || ($(modprobe -n -v freevxfs 2>/dev/null | grep -P "^\h*install /bin/true" | wc -l) -eq 0 && ($(modprobe -n -v freevxfs 2>/dev/null | grep -P "^\h*install /bin/false" | wc -l) -eq 0 || $(grep -P "^\h*blacklist\s+freevxfs" /etc/modprobe.d/* 2>/dev/null | wc -l) -eq 0)) ]]; then
echo "{\"1.1.1.2. Cấu hình vô hiệu hoá freevxfs filesystem\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa hoặc tạo một file trong thư mục /etc/modprobe.d/filesystem.conf và thêm vào những dòng sau:
# install freevxfs /bin/true
# Thực hiện câu lệnh sau để gỡ bỏ các filesystem không thông dụng khỏi kernel:
# rmmod freevxfs"
if [ $(lsmod | grep freevxfs | wc -l) -ne 0 ]; then echo "-------------------"; echo "#lsmod | grep freevxfs -eq 0 ";lsmod | grep freevxfs; fi
if [ $(modprobe -n -v freevxfs 2>/dev/null | grep -P "^\h*install /bin/true" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#modprobe -n -v freevxfs 2>/dev/null | grep -P \"^\\h*install /bin/true\" -ne 0 ";modprobe -n -v freevxfs 2>/dev/null | grep -P "^\h*install /bin/true"; fi
if [ $(modprobe -n -v freevxfs 2>/dev/null | grep -P "^\h*install /bin/false" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#modprobe -n -v freevxfs 2>/dev/null | grep -P \"^\\h*install /bin/false\" -ne 0 ";modprobe -n -v freevxfs 2>/dev/null | grep -P "^\h*install /bin/false"; fi
if [ $(grep -P "^\h*blacklist\s+freevxfs" /etc/modprobe.d/*.conf 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*blacklist\s+freevxfs\" /etc/modprobe.d/*.conf 2>/dev/null -ne 0 ";grep -P "^\h*blacklist\s+freevxfs" /etc/modprobe.d/*.conf 2>/dev/null; fi
echo "######################################"
else
echo "{\"1.1.1.2. Cấu hình vô hiệu hoá freevxfs filesystem\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa hoặc tạo một file trong thư mục /etc/modprobe.d/filesystem.conf và thêm vào những dòng sau:
# install hfs /bin/true
# Thực hiện câu lệnh sau để gỡ bỏ các filesystem không thông dụng khỏi kernel:
# rmmod hfs
if [[ $(lsmod | grep hfs | wc -l) -ne 0 || ($(modprobe -n -v hfs 2>/dev/null | grep -P "^\h*install /bin/true" | wc -l) -eq 0 && ($(modprobe -n -v hfs 2>/dev/null | grep -P "^\h*install /bin/false" | wc -l) -eq 0 || $(grep -P "^\h*blacklist\s+hfs" /etc/modprobe.d/* 2>/dev/null | wc -l) -eq 0)) ]]; then
echo "{\"1.1.1.3. Cấu hình vô hiệu hoá hfs filesystem\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa hoặc tạo một file trong thư mục /etc/modprobe.d/filesystem.conf và thêm vào những dòng sau:
# install hfs /bin/true
# Thực hiện câu lệnh sau để gỡ bỏ các filesystem không thông dụng khỏi kernel:
# rmmod hfs"
if [ $(lsmod | grep hfs | wc -l) -ne 0 ]; then echo "-------------------"; echo "#lsmod | grep hfs -eq 0 ";lsmod | grep hfs; fi
if [ $(modprobe -n -v hfs 2>/dev/null | grep -P "^\h*install /bin/true" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#modprobe -n -v hfs 2>/dev/null | grep -P \"^\\h*install /bin/true\" -ne 0 ";modprobe -n -v hfs 2>/dev/null | grep -P "^\h*install /bin/true"; fi
if [ $(modprobe -n -v hfs 2>/dev/null | grep -P "^\h*install /bin/false" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#modprobe -n -v hfs 2>/dev/null | grep -P \"^\\h*install /bin/false\" -ne 0 ";modprobe -n -v hfs 2>/dev/null | grep -P "^\h*install /bin/false"; fi
if [ $(grep -P "^\h*blacklist\s+hfs" /etc/modprobe.d/*.conf 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*blacklist\s+hfs\" /etc/modprobe.d/*.conf 2>/dev/null -ne 0 ";grep -P "^\h*blacklist\s+hfs" /etc/modprobe.d/*.conf 2>/dev/null; fi
echo "######################################"
else
echo "{\"1.1.1.3. Cấu hình vô hiệu hoá hfs filesystem\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa hoặc tạo một file trong thư mục /etc/modprobe.d/filesystem.conf và thêm vào những dòng sau:
# install hfsplus /bin/true
# Thực hiện câu lệnh sau để gỡ bỏ các filesystem không thông dụng khỏi kernel:
# rmmod hfsplus
if [[ $(lsmod | grep hfsplus | wc -l) -ne 0 || ($(modprobe -n -v hfsplus 2>/dev/null | grep -P "^\h*install /bin/true" | wc -l) -eq 0 && ($(modprobe -n -v hfsplus 2>/dev/null | grep -P "^\h*install /bin/false" | wc -l) -eq 0 || $(grep -P "^\h*blacklist\s+hfsplus" /etc/modprobe.d/* 2>/dev/null | wc -l) -eq 0)) ]]; then
echo "{\"1.1.1.4. Cấu hình vô hiệu hoá hfsplus filesystem\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa hoặc tạo một file trong thư mục /etc/modprobe.d/filesystem.conf và thêm vào những dòng sau:
# install hfsplus /bin/true
# Thực hiện câu lệnh sau để gỡ bỏ các filesystem không thông dụng khỏi kernel:
# rmmod hfsplus"
if [ $(lsmod | grep hfsplus | wc -l) -ne 0 ]; then echo "-------------------"; echo "#lsmod | grep hfsplus -eq 0 ";lsmod | grep hfsplus; fi
if [ $(modprobe -n -v hfsplus 2>/dev/null | grep -P "^\h*install /bin/true" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#modprobe -n -v hfsplus 2>/dev/null | grep -P \"^\\h*install /bin/true\" -ne 0 ";modprobe -n -v hfsplus 2>/dev/null | grep -P "^\h*install /bin/true"; fi
if [ $(modprobe -n -v hfsplus 2>/dev/null | grep -P "^\h*install /bin/false" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#modprobe -n -v hfsplus 2>/dev/null | grep -P \"^\\h*install /bin/false\" -ne 0 ";modprobe -n -v hfsplus 2>/dev/null | grep -P "^\h*install /bin/false"; fi
if [ $(grep -P "^\h*blacklist\s+hfsplus" /etc/modprobe.d/*.conf 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*blacklist\s+hfsplus\" /etc/modprobe.d/*.conf 2>/dev/null -ne 0 ";grep -P "^\h*blacklist\s+hfsplus" /etc/modprobe.d/*.conf 2>/dev/null; fi
echo "######################################"
else
echo "{\"1.1.1.4. Cấu hình vô hiệu hoá hfsplus filesystem\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa hoặc tạo một file trong thư mục /etc/modprobe.d/filesystem.conf và thêm vào những dòng sau:
# install jffs2 /bin/true
# Thực hiện câu lệnh sau để gỡ bỏ các filesystem không thông dụng khỏi kernel:
# rmmod jffs2
if [[ $(lsmod | grep jffs2 | wc -l) -ne 0 || ($(modprobe -n -v jffs2 2>/dev/null | grep -P "^\h*install /bin/true" | wc -l) -eq 0 && ($(modprobe -n -v jffs2 2>/dev/null | grep -P "^\h*install /bin/false" | wc -l) -eq 0 || $(grep -P "^\h*blacklist\s+jffs2" /etc/modprobe.d/* 2>/dev/null | wc -l) -eq 0)) ]]; then
echo "{\"1.1.1.5. Cấu hình vô hiệu hoá jffs2 filesystem\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa hoặc tạo một file trong thư mục /etc/modprobe.d/filesystem.conf và thêm vào những dòng sau:
# install jffs2 /bin/true
# Thực hiện câu lệnh sau để gỡ bỏ các filesystem không thông dụng khỏi kernel:
# rmmod jffs2"
if [ $(lsmod | grep jffs2 | wc -l) -ne 0 ]; then echo "-------------------"; echo "#lsmod | grep jffs2 -eq 0 ";lsmod | grep jffs2; fi
if [ $(modprobe -n -v jffs2 2>/dev/null | grep -P "^\h*install /bin/true" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#modprobe -n -v jffs2 2>/dev/null | grep -P \"^\\h*install /bin/true\" -ne 0 ";modprobe -n -v jffs2 2>/dev/null | grep -P "^\h*install /bin/true"; fi
if [ $(modprobe -n -v jffs2 2>/dev/null | grep -P "^\h*install /bin/false" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#modprobe -n -v jffs2 2>/dev/null | grep -P \"^\\h*install /bin/false\" -ne 0 ";modprobe -n -v jffs2 2>/dev/null | grep -P "^\h*install /bin/false"; fi
if [ $(grep -P "^\h*blacklist\s+jffs2" /etc/modprobe.d/*.conf 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*blacklist\s+jffs2\" /etc/modprobe.d/*.conf 2>/dev/null -ne 0 ";grep -P "^\h*blacklist\s+jffs2" /etc/modprobe.d/*.conf 2>/dev/null; fi
echo "######################################"
else
echo "{\"1.1.1.5. Cấu hình vô hiệu hoá jffs2 filesystem\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa hoặc tạo một file trong thư mục /etc/modprobe.d/filesystem.conf và thêm vào những dòng sau:
# install squashfs /bin/true
# Thực hiện câu lệnh sau để gỡ bỏ các filesystem không thông dụng khỏi kernel:
# rmmod squashfs
if [[ $(lsmod | grep squashfs | wc -l) -ne 0 || ($(modprobe -n -v squashfs 2>/dev/null | grep -P "^\h*install /bin/true" | wc -l) -eq 0 && ($(modprobe -n -v squashfs 2>/dev/null | grep -P "^\h*install /bin/false" | wc -l) -eq 0 || $(grep -P "^\h*blacklist\s+squashfs" /etc/modprobe.d/* 2>/dev/null | wc -l) -eq 0)) ]]; then
echo "{\"1.1.1.6. Cấu hình vô hiệu hoá squashfs filesystem\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa hoặc tạo một file trong thư mục /etc/modprobe.d/filesystem.conf và thêm vào những dòng sau:
# install squashfs /bin/true
# Thực hiện câu lệnh sau để gỡ bỏ các filesystem không thông dụng khỏi kernel:
# rmmod squashfs"
if [ $(lsmod | grep squashfs | wc -l) -ne 0 ]; then echo "-------------------"; echo "#lsmod | grep squashfs -eq 0 ";lsmod | grep squashfs; fi
if [ $(modprobe -n -v squashfs 2>/dev/null | grep -P "^\h*install /bin/true" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#modprobe -n -v squashfs 2>/dev/null | grep -P \"^\\h*install /bin/true\" -ne 0 ";modprobe -n -v squashfs 2>/dev/null | grep -P "^\h*install /bin/true"; fi
if [ $(modprobe -n -v squashfs 2>/dev/null | grep -P "^\h*install /bin/false" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#modprobe -n -v squashfs 2>/dev/null | grep -P \"^\\h*install /bin/false\" -ne 0 ";modprobe -n -v squashfs 2>/dev/null | grep -P "^\h*install /bin/false"; fi
if [ $(grep -P "^\h*blacklist\s+squashfs" /etc/modprobe.d/*.conf 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*blacklist\s+squashfs\" /etc/modprobe.d/*.conf 2>/dev/null -ne 0 ";grep -P "^\h*blacklist\s+squashfs" /etc/modprobe.d/*.conf 2>/dev/null; fi
echo "######################################"
else
echo "{\"1.1.1.6. Cấu hình vô hiệu hoá squashfs filesystem\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa hoặc tạo một file trong thư mục /etc/modprobe.d/filesystem.conf và thêm vào những dòng sau:
# install udf /bin/true
# Thực hiện câu lệnh sau để gỡ bỏ các filesystem không thông dụng khỏi kernel:
# rmmod udf
if [[ $(lsmod | grep udf | wc -l) -ne 0 || ($(modprobe -n -v udf 2>/dev/null | grep -P "^\h*install /bin/true" | wc -l) -eq 0 && ($(modprobe -n -v udf 2>/dev/null | grep -P "^\h*install /bin/false" | wc -l) -eq 0 || $(grep -P "^\h*blacklist\s+udf" /etc/modprobe.d/* 2>/dev/null | wc -l) -eq 0)) ]]; then
echo "{\"1.1.1.7. Cấu hình vô hiệu hoá udf filesystem\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa hoặc tạo một file trong thư mục /etc/modprobe.d/filesystem.conf và thêm vào những dòng sau:
# install udf /bin/true
# Thực hiện câu lệnh sau để gỡ bỏ các filesystem không thông dụng khỏi kernel:
# rmmod udf"
if [ $(lsmod | grep udf | wc -l) -ne 0 ]; then echo "-------------------"; echo "#lsmod | grep udf -eq 0 ";lsmod | grep udf; fi
if [ $(modprobe -n -v udf 2>/dev/null | grep -P "^\h*install /bin/true" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#modprobe -n -v udf 2>/dev/null | grep -P \"^\\h*install /bin/true\" -ne 0 ";modprobe -n -v udf 2>/dev/null | grep -P "^\h*install /bin/true"; fi
if [ $(modprobe -n -v udf 2>/dev/null | grep -P "^\h*install /bin/false" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#modprobe -n -v udf 2>/dev/null | grep -P \"^\\h*install /bin/false\" -ne 0 ";modprobe -n -v udf 2>/dev/null | grep -P "^\h*install /bin/false"; fi
if [ $(grep -P "^\h*blacklist\s+udf" /etc/modprobe.d/*.conf 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*blacklist\s+udf\" /etc/modprobe.d/*.conf 2>/dev/null -ne 0 ";grep -P "^\h*blacklist\s+udf" /etc/modprobe.d/*.conf 2>/dev/null; fi
echo "######################################"
else
echo "{\"1.1.1.7. Cấu hình vô hiệu hoá udf filesystem\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa hoặc tạo một file trong thư mục /etc/modprobe.d/filesystem.conf và thêm vào những dòng sau:
# install usb-storage /bin/true
# Thực hiện câu lệnh sau để gỡ bỏ các filesystem không thông dụng khỏi kernel:
# rmmod usb-storage
if [[ $(lsmod | grep usb-storage | wc -l) -ne 0 || ($(modprobe -n -v usb-storage 2>/dev/null | grep -P "^\h*install /bin/true" | wc -l) -eq 0 && ($(modprobe -n -v usb-storage 2>/dev/null | grep -P "^\h*install /bin/false" | wc -l) -eq 0 || $(grep -P "^\h*blacklist\s+usb-storage" /etc/modprobe.d/* 2>/dev/null | wc -l) -eq 0)) ]]; then
echo "{\"1.1.1.8. Cấu hình vô hiệu hoá usb-storage filesystem\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa hoặc tạo một file trong thư mục /etc/modprobe.d/filesystem.conf và thêm vào những dòng sau:
# install usb-storage /bin/true
# Thực hiện câu lệnh sau để gỡ bỏ các filesystem không thông dụng khỏi kernel:
# rmmod usb-storage"
if [ $(lsmod | grep usb-storage | wc -l) -ne 0 ]; then echo "-------------------"; echo "#lsmod | grep usb-storage -eq 0 ";lsmod | grep usb-storage; fi
if [ $(modprobe -n -v usb-storage 2>/dev/null | grep -P "^\h*install /bin/true" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#modprobe -n -v usb-storage 2>/dev/null | grep -P \"^\\h*install /bin/true\" -ne 0 ";modprobe -n -v usb-storage 2>/dev/null | grep -P "^\h*install /bin/true"; fi
if [ $(modprobe -n -v usb-storage 2>/dev/null | grep -P "^\h*install /bin/false" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#modprobe -n -v usb-storage 2>/dev/null | grep -P \"^\\h*install /bin/false\" -ne 0 ";modprobe -n -v usb-storage 2>/dev/null | grep -P "^\h*install /bin/false"; fi
if [ $(grep -P "^\h*blacklist\s+usb-storage" /etc/modprobe.d/*.conf 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*blacklist\s+usb-storage\" /etc/modprobe.d/*.conf 2>/dev/null -ne 0 ";grep -P "^\h*blacklist\s+usb-storage" /etc/modprobe.d/*.conf 2>/dev/null; fi
echo "######################################"
else
echo "{\"1.1.1.8. Cấu hình vô hiệu hoá usb-storage filesystem\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/fstab và thêm tùy chọn nodev, nosuid, noexec vào trường thứ 4 trong cấu hình của phân vùng /tmp. Ví dụ:
# tmpfs /tmp tmpfs defaults,nodev,nosuid,noexec 0 0
# Thực hiện các lệnh sau để mount phân vùng /tmp và cập nhật cấu hình fstab:
# mount /tmp
# mount -o remount /tmp
# Kiểm tra /tmp có được mount không
if ! findmnt --kernel /tmp >/dev/null 2>&1; then
# /tmp không được mount → PASS
echo "{\"1.1.2.1. Cấu hình tuỳ chọn nodev cho phân vùng /tmp\" : \"PASSED\"}"
echo "######################################"
echo "# /tmp is not mounted - check không áp dụng"
echo "-------------------"
elif [ $(findmnt --kernel /tmp | grep nodev | wc -l) -eq 0 ] || [ $(grep -E "\s+/tmp\s+.*nodev" /etc/fstab | wc -l) -eq 0 ]; then
echo "{\"1.1.2.1. Cấu hình tuỳ chọn nodev cho phân vùng /tmp\" : \"FAILED\"}"
# Log
echo "######################################"
if [ $(findmnt --kernel /tmp | grep nodev | wc -l) -eq 0 ]; then echo "-------------------"; echo "#findmnt --kernel /tmp | grep nodev -ne 0 ";findmnt --kernel /tmp | grep nodev; fi
if [ $(grep -E "\s+/tmp\s+.*nodev" /etc/fstab | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -E \"\s+/tmp\s+.*nodev\" /etc/fstab -ne 0 ";grep -E "\s+/tmp\s+.*nodev" /etc/fstab; fi
echo "-------------------"
else
echo "{\"1.1.2.1. Cấu hình tuỳ chọn nodev cho phân vùng /tmp\" : \"PASSED\"}"
fi
# Kiểm tra /tmp có được mount không
if ! findmnt --kernel /tmp >/dev/null 2>&1; then
# /tmp không được mount → PASS
echo "{\"1.1.2.2. Cấu hình tuỳ chọn nosuid cho phân vùng /tmp\" : \"PASSED\"}"
echo "######################################"
echo "# /tmp is not mounted - check không áp dụng"
echo "-------------------"
elif [ $(findmnt --kernel /tmp | grep nosuid | wc -l) -eq 0 ] || [ $(grep -E "\s+/tmp\s+.*nosuid" /etc/fstab | wc -l) -eq 0 ]; then
echo "{\"1.1.2.2. Cấu hình tuỳ chọn nosuid cho phân vùng /tmp\" : \"FAILED\"}"
# Log
echo "######################################"
if [ $(findmnt --kernel /tmp | grep nosuid | wc -l) -eq 0 ]; then echo "-------------------"; echo "#findmnt --kernel /tmp | grep nosuid -ne 0 ";findmnt --kernel /tmp | grep nosuid; fi
if [ $(grep -E "\s+/tmp\s+.*nosuid" /etc/fstab | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -E \"\s+/tmp\s+.*nosuid\" /etc/fstab -ne 0 ";grep -E "\s+/tmp\s+.*nosuid" /etc/fstab; fi
echo "-------------------"
else
echo "{\"1.1.2.2. Cấu hình tuỳ chọn nosuid cho phân vùng /tmp\" : \"PASSED\"}"
fi
# Kiểm tra /tmp có được mount không
if ! findmnt --kernel /tmp >/dev/null 2>&1; then
# /tmp không được mount → PASS
echo "{\"1.1.2.3. Cấu hình tuỳ chọn noexec cho phân vùng /tmp\" : \"PASSED\"}"
echo "######################################"
echo "# /tmp is not mounted - check không áp dụng"
echo "-------------------"
elif [ $(findmnt --kernel /tmp | grep noexec | wc -l) -eq 0 ] || [ $(grep -E "\s+/tmp\s+.*noexec" /etc/fstab | wc -l) -eq 0 ]; then
echo "{\"1.1.2.3. Cấu hình tuỳ chọn noexec cho phân vùng /tmp\" : \"FAILED\"}"
# Log
echo "######################################"
if [ $(findmnt --kernel /tmp | grep noexec | wc -l) -eq 0 ]; then echo "-------------------"; echo "#findmnt --kernel /tmp | grep noexec -ne 0 ";findmnt --kernel /tmp | grep noexec; fi
if [ $(grep -E "\s+/tmp\s+.*noexec" /etc/fstab | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -E \"\s+/tmp\s+.*noexec\" /etc/fstab -ne 0 ";grep -E "\s+/tmp\s+.*noexec" /etc/fstab; fi
echo "-------------------"
else
echo "{\"1.1.2.3. Cấu hình tuỳ chọn noexec cho phân vùng /tmp\" : \"PASSED\"}"
fi
# Log
echo "-------------------"
echo "# Chỉnh sửa file /etc/fstab và thêm tùy chọn nodev, nosuid, noexec vào trường thứ 4 trong cấu hình của phân vùng /tmp. Ví dụ:
# tmpfs /tmp tmpfs defaults,nodev,nosuid,noexec 0 0
# Thực hiện các lệnh sau để mount phân vùng /tmp và cập nhật cấu hình fstab:
# mount /tmp
# mount -o remount /tmp"
echo "-------------------"
[ $(findmnt --kernel /tmp | wc -l) -ne 0 ] && echo "Directory /tmp is mounted" || echo "Directory /tmp is not mounted"
echo "######################################"
############################################################################
# Chỉnh sửa file /etc/fstab và thêm tùy chọn nodev, nosuid, noexec vào trường thứ 4 trong cấu hình của phân vùng /var/tmp. Ví dụ:
# tmpfs /var/tmp tmpfs defaults,nodev,nosuid,noexec 0 0
# Thực hiện các lệnh sau để mount phân vùng /var/tmp và cập nhật cấu hình fstab:
# mount /var/tmp
# mount -o remount /var/tmp
# Kiểm tra /var/tmp có được mount không
if ! findmnt --kernel /var/tmp >/dev/null 2>&1; then
echo "{\"1.1.3.1. Cấu hình tuỳ chọn nodev cho phân vùng /var/tmp\" : \"PASSED\"}"
echo "######################################"
echo "# /var/tmp is not mounted - check không áp dụng"
echo "-------------------"
elif [ $(findmnt --kernel /var/tmp | grep nodev | wc -l) -eq 0 ] || [ $(grep -E "\s+/var/tmp\s+.*nodev" /etc/fstab | wc -l) -eq 0 ]; then
echo "{\"1.1.3.1. Cấu hình tuỳ chọn nodev cho phân vùng /var/tmp\" : \"FAILED\"}"
# Log
echo "######################################"
if [ $(findmnt --kernel /var/tmp | grep nodev | wc -l) -eq 0 ]; then echo "-------------------"; echo "#findmnt --kernel /var/tmp | grep nodev -ne 0 ";findmnt --kernel /var/tmp | grep nodev; fi
if [ $(grep -E "\s+/var/tmp\s+.*nodev" /etc/fstab | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -E \"\s+/var/tmp\s+.*nodev\" /etc/fstab -ne 0 ";grep -E "\s+/var/tmp\s+.*nodev" /etc/fstab; fi
echo "-------------------"
else
echo "{\"1.1.3.1. Cấu hình tuỳ chọn nodev cho phân vùng /var/tmp\" : \"PASSED\"}"
fi
# Kiểm tra /var/tmp có được mount không
if ! findmnt --kernel /var/tmp >/dev/null 2>&1; then
echo "{\"1.1.3.2. Cấu hình tuỳ chọn nosuid cho phân vùng /var/tmp\" : \"PASSED\"}"
echo "######################################"
echo "# /var/tmp is not mounted - check không áp dụng"
echo "-------------------"
elif [ $(findmnt --kernel /var/tmp | grep nosuid | wc -l) -eq 0 ] || [ $(grep -E "\s+/var/tmp\s+.*nosuid" /etc/fstab | wc -l) -eq 0 ]; then
echo "{\"1.1.3.2. Cấu hình tuỳ chọn nosuid cho phân vùng /var/tmp\" : \"FAILED\"}"
# Log
echo "######################################"
if [ $(findmnt --kernel /var/tmp | grep nosuid | wc -l) -eq 0 ]; then echo "-------------------"; echo "#findmnt --kernel /var/tmp | grep nosuid -ne 0 ";findmnt --kernel /var/tmp | grep nosuid; fi
if [ $(grep -E "\s+/var/tmp\s+.*nosuid" /etc/fstab | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -E \"\s+/var/tmp\s+.*nosuid\" /etc/fstab -ne 0 ";grep -E "\s+/var/tmp\s+.*nosuid" /etc/fstab; fi
echo "-------------------"
else
echo "{\"1.1.3.2. Cấu hình tuỳ chọn nosuid cho phân vùng /var/tmp\" : \"PASSED\"}"
fi
# Kiểm tra /var/tmp có được mount không
if ! findmnt --kernel /var/tmp >/dev/null 2>&1; then
echo "{\"1.1.3.3. Cấu hình tuỳ chọn noexec cho phân vùng /var/tmp\" : \"PASSED\"}"
echo "######################################"
echo "# /var/tmp is not mounted - check không áp dụng"
echo "-------------------"
elif [ $(findmnt --kernel /var/tmp | grep noexec | wc -l) -eq 0 ] || [ $(grep -E "\s+/var/tmp\s+.*noexec" /etc/fstab | wc -l) -eq 0 ]; then
echo "{\"1.1.3.3. Cấu hình tuỳ chọn noexec cho phân vùng /var/tmp\" : \"FAILED\"}"
# Log
echo "######################################"
if [ $(findmnt --kernel /var/tmp | grep noexec | wc -l) -eq 0 ]; then echo "-------------------"; echo "#findmnt --kernel /var/tmp | grep noexec -ne 0 ";findmnt --kernel /var/tmp | grep noexec; fi
if [ $(grep -E "\s+/var/tmp\s+.*noexec" /etc/fstab | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -E \"\s+/var/tmp\s+.*noexec\" /etc/fstab -ne 0 ";grep -E "\s+/var/tmp\s+.*noexec" /etc/fstab; fi
echo "-------------------"
else
echo "{\"1.1.3.3. Cấu hình tuỳ chọn noexec cho phân vùng /var/tmp\" : \"PASSED\"}"
fi
# Log
echo "-------------------"
echo "# Chỉnh sửa file /etc/fstab và thêm tùy chọn nodev, nosuid, noexec vào trường thứ 4 trong cấu hình của phân vùng /var/tmp. Ví dụ:
# tmpfs /var/tmp tmpfs defaults,nodev,nosuid,noexec 0 0
# Thực hiện các lệnh sau để mount phân vùng /var/tmp và cập nhật cấu hình fstab:
# mount /var/tmp
# mount -o remount /var/tmp"
echo "-------------------"
[ $(findmnt --kernel /var/tmp | wc -l) -ne 0 ] && echo "Directory /var/tmp is mounted" || echo "Directory /var/tmp is not mounted"
echo "######################################"
############################################################################
# Chỉnh sửa file /etc/fstab và thêm tùy chọn nodev, nosuid, noexec vào trường thứ 4 trong cấu hình của phân vùng /home. Ví dụ:
# <device> /home <fstype> defaults,nodev,nosuid 0 0
# Thực hiện các lệnh sau để cập nhật cấu hình fstab:
# mount -o remount /home
# Kiểm tra /home có được mount không
if ! findmnt --kernel /home >/dev/null 2>&1; then
echo "{\"1.1.4.1. Cấu hình tuỳ chọn nodev cho phân vùng /home\" : \"PASSED\"}"
echo "######################################"
echo "# /home is not mounted - check không áp dụng"
echo "-------------------"
elif [ $(findmnt --kernel /home | grep nodev | wc -l) -eq 0 ] || [ $(grep -E "\s+/home\s+.*nodev" /etc/fstab | wc -l) -eq 0 ]; then
echo "{\"1.1.4.1. Cấu hình tuỳ chọn nodev cho phân vùng /home\" : \"FAILED\"}"
# Log
echo "######################################"
if [ $(findmnt --kernel /home | grep nodev | wc -l) -eq 0 ]; then echo "-------------------"; echo "#findmnt --kernel /home | grep nodev -ne 0 ";findmnt --kernel /home | grep nodev; fi
if [ $(grep -E "\s+/home\s+.*nodev" /etc/fstab | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -E \"\s+/home\s+.*nodev\" /etc/fstab -ne 0 ";grep -E "\s+/home\s+.*nodev" /etc/fstab; fi
echo "-------------------"
else
echo "{\"1.1.4.1. Cấu hình tuỳ chọn nodev cho phân vùng /home\" : \"PASSED\"}"
fi
# Kiểm tra /home có được mount không
if ! findmnt --kernel /home >/dev/null 2>&1; then
echo "{\"1.1.4.2. Cấu hình tuỳ chọn nosuid cho phân vùng /home\" : \"PASSED\"}"
echo "######################################"
echo "# /home is not mounted - check không áp dụng"
echo "-------------------"
elif [ $(findmnt --kernel /home | grep nosuid | wc -l) -eq 0 ] || [ $(grep -E "\s+/home\s+.*nosuid" /etc/fstab | wc -l) -eq 0 ]; then
echo "{\"1.1.4.2. Cấu hình tuỳ chọn nosuid cho phân vùng /home\" : \"FAILED\"}"
# Log
echo "######################################"
if [ $(findmnt --kernel /home | grep nosuid | wc -l) -eq 0 ]; then echo "-------------------"; echo "#findmnt --kernel /home | grep nosuid -ne 0 ";findmnt --kernel /home | grep nosuid; fi
if [ $(grep -E "\s+/home\s+.*nosuid" /etc/fstab | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -E \"\s+/home\s+.*nosuid\" /etc/fstab -ne 0 ";grep -E "\s+/home\s+.*nosuid" /etc/fstab; fi
echo "-------------------"
else
echo "{\"1.1.4.2. Cấu hình tuỳ chọn nosuid cho phân vùng /home\" : \"PASSED\"}"
fi
# Log
echo "-------------------"
echo "# Chỉnh sửa file /etc/fstab và thêm tùy chọn nodev, nosuid, noexec vào trường thứ 4 trong cấu hình của phân vùng /home. Ví dụ:
# <device> /home <fstype> defaults,nodev,nosuid 0 0
# Thực hiện các lệnh sau để cập nhật cấu hình fstab:
# mount -o remount /home"
echo "-------------------"
[ $(findmnt --kernel /home | wc -l) -ne 0 ] && echo "Directory /home is mounted" || echo "Directory /home is not mounted"
echo "######################################"
############################################################################
# Chỉnh sửa file /etc/fstab và thêm tùy chọn nodev, nosuid, noexec vào trường thứ 4 trong cấu hình của phân vùng /dev/shm. Ví dụ:
# tmpfs /dev/shm tmpfs defaults,nodev,nosuid,noexec 0 0
# Thực hiện các lệnh sau để mount phân vùng /dev/shm và cập nhật cấu hình fstab:
# mount /dev/shm
# mount -o remount /dev/shm
# Kiểm tra /dev/shm có được mount không
if ! findmnt --kernel /dev/shm >/dev/null 2>&1; then
echo "{\"1.1.5.1. Cấu hình tuỳ chọn nodev cho phân vùng /dev/shm\" : \"PASSED\"}"
echo "######################################"
echo "# /dev/shm is not mounted - check không áp dụng"
echo "-------------------"
elif [ $(findmnt --kernel /dev/shm | grep nodev | wc -l) -eq 0 ] || [ $(grep -E "\s+/dev/shm\s+.*nodev" /etc/fstab | wc -l) -eq 0 ]; then
echo "{\"1.1.5.1. Cấu hình tuỳ chọn nodev cho phân vùng /dev/shm\" : \"FAILED\"}"
# Log
echo "######################################"
if [ $(findmnt --kernel /dev/shm | grep nodev | wc -l) -eq 0 ]; then echo "-------------------"; echo "#findmnt --kernel /dev/shm | grep nodev -ne 0 ";findmnt --kernel /dev/shm | grep nodev; fi
if [ $(grep -E "\s+/dev/shm\s+.*nodev" /etc/fstab | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -E \"\s+/dev/shm\s+.*nodev\" /etc/fstab -ne 0 ";grep -E "\s+/dev/shm\s+.*nodev" /etc/fstab; fi
echo "-------------------"
else
echo "{\"1.1.5.1. Cấu hình tuỳ chọn nodev cho phân vùng /dev/shm\" : \"PASSED\"}"
fi
# Kiểm tra /dev/shm có được mount không
if ! findmnt --kernel /dev/shm >/dev/null 2>&1; then
echo "{\"1.1.5.2. Cấu hình tuỳ chọn nosuid cho phân vùng /dev/shm\" : \"PASSED\"}"
echo "######################################"
echo "# /dev/shm is not mounted - check không áp dụng"
echo "-------------------"
elif [ $(findmnt --kernel /dev/shm | grep nosuid | wc -l) -eq 0 ] || [ $(grep -E "\s+/dev/shm\s+.*nosuid" /etc/fstab | wc -l) -eq 0 ]; then
echo "{\"1.1.5.2. Cấu hình tuỳ chọn nosuid cho phân vùng /dev/shm\" : \"FAILED\"}"
# Log
echo "######################################"
if [ $(findmnt --kernel /dev/shm | grep nosuid | wc -l) -eq 0 ]; then echo "-------------------"; echo "#findmnt --kernel /dev/shm | grep nosuid -ne 0 ";findmnt --kernel /dev/shm | grep nosuid; fi
if [ $(grep -E "\s+/dev/shm\s+.*nosuid" /etc/fstab | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -E \"\s+/dev/shm\s+.*nosuid\" /etc/fstab -ne 0 ";grep -E "\s+/dev/shm\s+.*nosuid" /etc/fstab; fi
echo "-------------------"
else
echo "{\"1.1.5.2. Cấu hình tuỳ chọn nosuid cho phân vùng /dev/shm\" : \"PASSED\"}"
fi
# Kiểm tra /dev/shm có được mount không
if ! findmnt --kernel /dev/shm >/dev/null 2>&1; then
echo "{\"1.1.5.3. Cấu hình tuỳ chọn noexec cho phân vùng /dev/shm\" : \"PASSED\"}"
echo "######################################"
echo "# /dev/shm is not mounted - check không áp dụng"
echo "-------------------"
elif [ $(findmnt --kernel /dev/shm | grep noexec | wc -l) -eq 0 ] || [ $(grep -E "\s+/dev/shm\s+.*noexec" /etc/fstab | wc -l) -eq 0 ]; then
echo "{\"1.1.5.3. Cấu hình tuỳ chọn noexec cho phân vùng /dev/shm\" : \"FAILED\"}"
# Log
echo "######################################"
if [ $(findmnt --kernel /dev/shm | grep noexec | wc -l) -eq 0 ]; then echo "-------------------"; echo "#findmnt --kernel /dev/shm | grep noexec -ne 0 ";findmnt --kernel /dev/shm | grep noexec; fi
if [ $(grep -E "\s+/dev/shm\s+.*noexec" /etc/fstab | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -E \"\s+/dev/shm\s+.*noexec\" /etc/fstab -ne 0 ";grep -E "\s+/dev/shm\s+.*noexec" /etc/fstab; fi
echo "-------------------"
else
echo "{\"1.1.5.3. Cấu hình tuỳ chọn noexec cho phân vùng /dev/shm\" : \"PASSED\"}"
fi
# Log
echo "-------------------"
echo "# Chỉnh sửa file /etc/fstab và thêm tùy chọn nodev, nosuid, noexec vào trường thứ 4 trong cấu hình của phân vùng /dev/shm. Ví dụ:
# tmpfs /dev/shm tmpfs defaults,nodev,nosuid,noexec 0 0
# Thực hiện các lệnh sau để mount phân vùng /dev/shm và cập nhật cấu hình fstab:
# mount /dev/shm
# mount -o remount /dev/shm"
echo "-------------------"
[ $(findmnt --kernel /dev/shm | wc -l) -ne 0 ] && echo "Directory /dev/shm is mounted" || echo "Directory /dev/shm is not mounted"
echo "######################################"
############################################################################
# Thực hiện câu lệnh sau để vô hiệu hoá autofs:
# systemctl --now mask autofs
# Thực hiện câu lệnh sau để gỡ bỏ autofs nếu không có thành phần nào yêu cầu gói autofs:
# yum remove autofs
if [ $(rpm -qa autofs | wc -l) -ne 0 ] || [ $(systemctl is-enabled autofs 2>/dev/null | grep "^enabled" | wc -l) -ne 0 ]; then
echo "{\"1.1.6. Cấu hình vô hiệu hoá automounting\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để vô hiệu hoá autofs:
# systemctl --now mask autofs
# Thực hiện câu lệnh sau để gỡ bỏ autofs nếu không có thành phần nào yêu cầu gói autofs:
# yum remove autofs"
if [ $(rpm -qa autofs | wc -l) -ne 0 ]; then echo "-------------------"; echo "#rpm -qa autofs -eq 0";rpm -qa autofs; fi
if [ $(systemctl is-enabled autofs 2>/dev/null | grep "^enabled" | wc -l) -ne 0 ]; then echo "-------------------"; echo "#systemctl is-enabled autofs 2>/dev/null | grep \"^enabled\" -eq 0 ";systemctl is-enabled autofs 2>/dev/null | grep "^enabled"; fi
echo "######################################"
else
echo "{\"1.1.6. Cấu hình vô hiệu hoá automounting\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa hoặc tạo một file trong thư mục /etc/modprobe.d/usb_storage.conf và thêm vào những dòng sau:
# install usb-storage /bin/true
# Thực hiện câu lệnh sau để gỡ bỏ USB Storage:
# rmmod usb-storage
if [ $(modprobe -n -v usb-storage 2>/dev/null | grep "^install.*/bin/true" | wc -l) -eq 0 ] || [ $(lsmod | grep usb-storage | wc -l) -ne 0 ]; then
echo "{\"1.1.7. Cấu hình vô hiệu hoá usb storage\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa hoặc tạo một file trong thư mục /etc/modprobe.d/usb_storage.conf và thêm vào những dòng sau:
# install usb-storage /bin/true
# Thực hiện câu lệnh sau để gỡ bỏ USB Storage:
# rmmod usb-storage"
if [ $(modprobe -n -v usb-storage 2>/dev/null | grep "^install.*/bin/true" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#modprobe -n -v usb-storage 2>/dev/null | grep \"^install.*/bin/true\" -ne 0 ";modprobe -n -v usb-storage 2>/dev/null | grep "^install.*/bin/true"; fi
if [ $(lsmod | grep usb-storage | wc -l) -ne 0 ]; then echo "-------------------"; echo "#lsmod | grep usb-storage -eq 0 ";lsmod | grep usb-storage; fi
echo "######################################"
else
echo "{\"1.1.7. Cấu hình vô hiệu hoá usb storage\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa bất kỳ file nào trong /etc/yum.repos.d/*.conf trả về gpgcheck=0 và đặt tất cả các trường hợp đó thành gpgcheck=1.
# find /etc/yum.repos.d/ -name "*.repo" -exec echo "Checking:" {} \; -exec sed -i 's/^gpgcheck\s*=\s*.*/gpgcheck=1/' {} \;
# Chỉnh sửa file cấu hình /etc/yum.conf và đặt gpgcheck=1 ở mục [main].
# sed -i 's/^gpgcheck\s*=\s*.*/gpgcheck=1/' /etc/yum.conf
if [ $(grep -P "^gpgcheck\h*=\h*[^1].*\h*$" /etc/yum.repos.d/*.conf 2>/dev/null | wc -l) -ne 0 ] || [ $(grep -P "^gpgcheck\h*=\h*[^1].*\h*$" /etc/yum.conf 2>/dev/null | wc -l) -ne 0 ]; then
echo "{\"1.2.1. Cấu hình kích hoạt gpgcheck\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa bất kỳ file nào trong /etc/yum.repos.d/*.conf trả về gpgcheck=0 và đặt tất cả các trường hợp đó thành gpgcheck=1.
# find /etc/yum.repos.d/ -name \"*.repo\" -exec echo \"Checking:\" {} \; -exec sed -i 's/^gpgcheck\s*=\s*.*/gpgcheck=1/' {} \;
# Chỉnh sửa file cấu hình /etc/yum.conf và đặt gpgcheck=1 ở mục [main].
# sed -i 's/^gpgcheck\s*=\s*.*/gpgcheck=1/' /etc/yum.conf"
if [ $(grep -P "^gpgcheck\h*=\h*[^1].*\h*$" /etc/yum.repos.d/*.conf 2>/dev/null | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -P \"^gpgcheck\h*=\h*[^1].*\h*\$\" /etc/yum.repos.d/*.conf 2>/dev/null -eq 0 ";grep -P "^gpgcheck\h*=\h*[^1].*\h*$" /etc/yum.repos.d/*.conf 2>/dev/null; fi
if [ $(grep -P "^gpgcheck\h*=\h*[^1].*\h*$" /etc/yum.conf 2>/dev/null | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -P \"^gpgcheck\h*=\h*[^1].*\h*\$\" /etc/yum.conf 2>/dev/null -eq 0 ";grep -P "^gpgcheck\h*=\h*[^1].*\h*$" /etc/yum.conf 2>/dev/null; fi
echo "######################################"
else
echo "{\"1.2.1. Cấu hình kích hoạt gpgcheck\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện câu lệnh sau và đảm bảo rằng aide được cài đặt:
# yum install aide
# Thực hiện các câu lệnh sau để khởi tạo AIDE:
# aide --init
# mv /var/lib/aide/aide.db.new.gz /var/lib/aide/aide.db.gz
if ! { rpm -q aide >/dev/null 2>&1 || rpm -qa | grep -qi "^aide"; }; then
echo "{\"1.3.1. Kiểm tra cài đặt AIDE\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau và đảm bảo rằng aide được cài đặt:
# yum install aide
# Thực hiện các câu lệnh sau để khởi tạo AIDE:
# aide --init
# mv /var/lib/aide/aide.db.new.gz /var/lib/aide/aide.db.gz"
if [ $(rpm -qa aide | wc -l) -eq 0 ]; then echo "-------------------"; echo "#rpm -qa aide -ne 0 ";rpm -qa aide; fi
echo "######################################"
else
echo "{\"1.3.1. Kiểm tra cài đặt AIDE\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện câu lệnh sau:
# crontab -u root -e
# Đặt dòng sau vào crontab:
# 0 5 * * * /usr/sbin/aide --check
if ! { rpm -q aide >/dev/null 2>&1 || rpm -qa | grep -qi "^aide"; } || ! { crontab -l 2>/dev/null | grep -Eq '^\s*[^#].*\baide\b.*--check' || grep -rsEq '^\s*[^#].*\baide\b.*--check' /etc/cron* /var/spool/cron 2>/dev/null || systemctl is-enabled aidecheck.timer 2>/dev/null | grep -q "^enabled" || systemctl is-enabled aide-check.timer 2>/dev/null | grep -q "^enabled"; }; then
echo "{\"1.3.2. Cấu hình kiểm tra tính toàn vẹn của filesystem\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau:
# crontab -u root -e
# Đặt dòng sau vào crontab:
# 0 5 * * * /usr/sbin/aide --check"
if [ $(grep -Ers "aide(\.wrapper)?\s(--?\S+\s)*(--(check|update)|\$AIDEARGS)\b" /etc/cron.* /etc/crontab /var/spool/cron/ 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ers \"aide(\.wrapper)?\s(--?\S+\s)*(--(check|update)|\\\$AIDEARGS)\b\" /etc/cron.* /etc/crontab /var/spool/cron/ 2>/dev/null -ne 0 ";grep -Ers "aide(\.wrapper)?\s(--?\S+\s)*(--(check|update)|\$AIDEARGS)\b" /etc/cron.* /etc/crontab /var/spool/cron/ 2>/dev/null; fi
echo "######################################"
else
echo "{\"1.3.2. Cấu hình kiểm tra tính toàn vẹn của filesystem\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện các câu lệnh sau để đặt các quyền cho file cấu hình grub:
# grubdir=$(dirname "$(find /boot -type f \( -name 'grubenv' -o -name 'grub.conf' -o -name 'grub.cfg' \) -exec grep -Pl '^\h*(kernelopts=|linux|kernel)' {} \;)")
# chown root:root $grubdir/grub.cfg
# chmod og-rwx $grubdir/grub.cfg
# chown root:root $grubdir/user.cfg
# chmod og-rwx $grubdir/user.cfg
# chown root:root $grubdir/grubenv
# chmod og-rwx $grubdir/grubenv
# Nếu hệ thống sử dụng UEFI, hãy chỉnh sửa /etc/fstab và thêm các tùy chọn fmask=0077, uid=0, và gid=0:
# <device> /boot/efi vfat defaults,umask=0027,fmask=0077,uid=0,gid=0 0 0
grubdir=$(dirname "$(find /boot -type f \( -name 'grubenv' -o -name 'grub.conf' -o -name 'grub.cfg' \) -exec grep -Pl '^\h*(kernelopts=|linux|kernel)' {} \;)")
if [[ $(stat -c "%a:%u:%g" $grubdir/user.cfg 2>/dev/null | grep -P '^\h*[0-7]00:0:0$' | wc -l) -eq 0 || $(stat -c "%a:%u:%g" $grubdir/grubenv 2>/dev/null | grep -P '^\h*[0-7]00:0:0$' | wc -l) -eq 0 || $(stat -c "%a:%u:%g" $grubdir/grub.cfg 2>/dev/null | grep -P '^\h*[0-7]00:0:0$' | wc -l) -eq 0 || ($(find /sys/firmware/efi 2>/dev/null | wc -l) -ne 0 && $(grep "/boot/efi.*vfat.*fmask=0077.*uid=0.*gid=0" /etc/fstab | wc -l) -eq 0) ]]; then
echo "{\"1.4.1. Phân quyền đối với file cấu hình bootloader\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để đặt các quyền cho file cấu hình grub:
# grubdir=\$(dirname \"\$(find /boot -type f \( -name 'grubenv' -o -name 'grub.conf' -o -name 'grub.cfg' \) -exec grep -Pl '^\h*(kernelopts=|linux|kernel)' {} \;)\")
# chown root:root \$grubdir/grub.cfg
# chmod og-rwx \$grubdir/grub.cfg
# chown root:root \$grubdir/user.cfg
# chmod og-rwx \$grubdir/user.cfg
# chown root:root \$grubdir/grubenv
# chmod og-rwx \$grubdir/grubenv
# Nếu hệ thống sử dụng UEFI, hãy chỉnh sửa /etc/fstab và thêm các tùy chọn fmask=0077, uid=0, và gid=0:
# <device> /boot/efi vfat defaults,umask=0027,fmask=0077,uid=0,gid=0 0 0"
if [ $(stat -c "%a:%u:%g" $grubdir/user.cfg 2>/dev/null | grep -P '^\h*[0-7]00:0:0$' | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat -c \"%a:%u:%g\" \$grubdir/user.cfg 2>/dev/null | grep -P '^\h*[0-7]00:0:0\$' -ne 0 ";stat -c "%a:%u:%g" $grubdir/user.cfg 2>/dev/null | grep -P '^\h*[0-7]00:0:0$'; fi
if [ $(stat -c "%a:%u:%g" $grubdir/grubenv 2>/dev/null | grep -P '^\h*[0-7]00:0:0$' | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat -c \"%a:%u:%g\" \$grubdir/grubenv 2>/dev/null | grep -P '^\h*[0-7]00:0:0\$' -ne 0 ";stat -c "%a:%u:%g" $grubdir/grubenv 2>/dev/null | grep -P '^\h*[0-7]00:0:0$'; fi
if [ $(stat -c "%a:%u:%g" $grubdir/grub.cfg 2>/dev/null | grep -P '^\h*[0-7]00:0:0$' | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat -c \"%a:%u:%g\" \$grubdir/grub.cfg 2>/dev/null | grep -P '^\h*[0-7]00:0:0\$' -ne 0 ";stat -c "%a:%u:%g" $grubdir/grub.cfg 2>/dev/null | grep -P '^\h*[0-7]00:0:0$'; fi
if [ $(find /sys/firmware/efi 2>/dev/null | wc -l) -ne 0 ] && [ $(grep "/boot/efi.*vfat.*fmask=0077.*uid=0.*gid=0" /etc/fstab | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep \"/boot/efi.*vfat.*fmask=0077.*uid=0.*gid=0\" /etc/fstab -ne 0 ";grep "/boot/efi.*vfat.*fmask=0077.*uid=0.*gid=0" /etc/fstab; fi
echo "######################################"
else
echo "{\"1.4.1. Phân quyền đối với file cấu hình bootloader\" : \"PASSED\"}"
fi
############################################################################
# Đối với CentOS 7:
# Chỉnh sửa file /usr/lib/systemd/system/rescue.service và /usr/lib/systemd/system/emergency.service và đặt ExecStart sử dụng /sbin/sulogin hoặc /usr/sbin/sulogin:
# [Service]
# ExecStart=-/bin/sh -c "/sbin/sulogin; /usr/bin/systemctl --fail --no-block default"
# Đối với CentOS 8:
# Chỉnh sửa file /usr/lib/systemd/system/rescue.service hoặc /etc/systemd/system/rescue.service.d/* và thêm dòng sau:
# [Service]
# ExecStart=-/usr/lib/systemd/systemd-sulogin-shell rescue
# *Lưu ý: Cấu hình sử dụng /systemd-sulogin-shell phải giống nhau nếu đã có cấu hình ở trong /usr/lib/systemd/system/rescue.service hoặc /etc/systemd/system/rescue.service.d/*
if [[ ($(grep -E "\s[8-9].[0-9]" /etc/system-release | wc -l) -eq 0 && ($(grep /sbin/sulogin /usr/lib/systemd/system/rescue.service 2>/dev/null | wc -l) -eq 0 || $(grep /sbin/sulogin /usr/lib/systemd/system/emergency.service 2>/dev/null | wc -l) -eq 0)) || ($(grep -E "\s[8-9].[0-9]" /etc/system-release | wc -l) -ne 0 && $(grep -Er "^ExecStart.*/systemd-sulogin-shell" /usr/lib/systemd/system/rescue.service /etc/systemd/system/rescue.service.d 2>/dev/null | sort | uniq | wc -l) -ne 1) ]]; then
echo "{\"1.4.2. Cấu hình xác thực khi truy cập rescue mode\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Đối với CentOS 7:
# Chỉnh sửa file /usr/lib/systemd/system/rescue.service và /usr/lib/systemd/system/emergency.service và đặt ExecStart sử dụng /sbin/sulogin hoặc /usr/sbin/sulogin:
# [Service]
# ExecStart=-/bin/sh -c \"/sbin/sulogin; /usr/bin/systemctl --fail --no-block default\"
# Đối với CentOS 8:
# Chỉnh sửa file /usr/lib/systemd/system/rescue.service hoặc /etc/systemd/system/rescue.service.d/* và thêm dòng sau:
# [Service]
# ExecStart=-/usr/lib/systemd/systemd-sulogin-shell rescue
# *Lưu ý: Cấu hình sử dụng /systemd-sulogin-shell phải giống nhau nếu đã có cấu hình ở trong /usr/lib/systemd/system/rescue.service hoặc /etc/systemd/system/rescue.service.d/*"
if [ $(grep -E "\s[8-9].[0-9]" /etc/system-release | wc -l) -eq 0 ] && [ $(grep /sbin/sulogin /usr/lib/systemd/system/rescue.service 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep /sbin/sulogin /usr/lib/systemd/system/rescue.service 2>/dev/null -ne ";grep /sbin/sulogin /usr/lib/systemd/system/rescue.service 2>/dev/null; fi
if [ $(grep -E "\s[8-9].[0-9]" /etc/system-release | wc -l) -eq 0 ] && [ $(grep /sbin/sulogin /usr/lib/systemd/system/emergency.service 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep /sbin/sulogin /usr/lib/systemd/system/emergency.service 2>/dev/null -ne ";grep /sbin/sulogin /usr/lib/systemd/system/emergency.service 2>/dev/null ; fi
if [ $(grep -E "\s[8-9].[0-9]" /etc/system-release | wc -l) -ne 0 ] && [ $(grep -Er "^ExecStart.*/systemd-sulogin-shell" /usr/lib/systemd/system/rescue.service /etc/systemd/system/rescue.service.d 2>/dev/null | sort | uniq | wc -l) -ne 1 ]; then echo "-------------------"; echo "#grep -Er \"^ExecStart.*/systemd-sulogin-shell\" /usr/lib/systemd/system/rescue.service /etc/systemd/system/rescue.service.d 2>/dev/null | sort | uniq -eq 1 ";grep -Er "^ExecStart.*/systemd-sulogin-shell" /usr/lib/systemd/system/rescue.service /etc/systemd/system/rescue.service.d 2>/dev/null | sort | uniq; fi
echo "######################################"
else
echo "{\"1.4.2. Cấu hình xác thực khi truy cập rescue mode\" : \"PASSED\"}"
fi
##################################################################################################################
echo -e "\n######################################"
if [[ $(grep -E "\s[6].[0-9]" /etc/system-release | wc -l) -ne 0 && $(grep "^SINGLE" /etc/sysconfig/init 2>/dev/null | grep "/sbin/sulogin" | wc -l) -eq 0 ]]; then
echo "{\"1.4.3. Cấu hình xác thực khi truy cập single user mode\" : \"FAILED\"}"
else
echo "{\"1.4.3. Cấu hình xác thực khi truy cập single user mode\" : \"PASSED\"}"
fi
# Log
if [ $(grep -E "\s[6].[0-9]" /etc/system-release | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -E \"\\s[6].[0-9]\" /etc/system-release -eq 0"; grep -E "\s[6].[0-9]" /etc/system-release
if [ $(grep "^SINGLE" /etc/sysconfig/init 2>/dev/null | grep "/sbin/sulogin" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep \"^SINGLE\" /etc/sysconfig/init 2>/dev/null | grep \"/sbin/sulogin\" -ne 0"; grep "^SINGLE" /etc/sysconfig/init 2>/dev/null | grep "/sbin/sulogin"
echo "----------LOG----------"
echo "#cat /etc/system-release -eq 6.x"; cat /etc/system-release
echo "#grep \"^SINGLE\" /etc/sysconfig/init"; grep "^SINGLE" /etc/sysconfig/init
##################################################################################################################
echo -e "\n######################################"
if [[ $(grep -E "\s[6].[0-9]" /etc/system-release | wc -l) -ne 0 && $(grep "^PROMPT=" /etc/sysconfig/init 2>/dev/null | grep "no" | wc -l) -eq 0 ]]; then
echo "{\"1.4.4. Cấu hình vô hiệu hoá interactive boot\" : \"FAILED\"}"
else
echo "{\"1.4.4. Cấu hình vô hiệu hoá interactive boot\" : \"PASSED\"}"
fi
# Log
if [ $(grep -E "\s[6].[0-9]" /etc/system-release | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -E \"\\s[6].[0-9]\" /etc/system-release -eq 0"; grep -E "\s[6].[0-9]" /etc/system-release
if [ $(grep "^PROMPT" /etc/sysconfig/init 2>/dev/null | grep "no" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep \"^PROMPT\" /etc/sysconfig/init 2>/dev/null | grep \"no\" -ne 0"; grep "^PROMPT" /etc/sysconfig/init 2>/dev/null | grep "no"
echo "----------LOG----------"
echo "#cat /etc/system-release -eq 6.x"; cat /etc/system-release
echo "#grep \"^PROMPT\" /etc/sysconfig/init"; grep "^PROMPT" /etc/sysconfig/init
############################################################################
# Chỉnh sửa file /etc/security/limits.conf hoặc /etc/security/limits.d/*.conf và thêm dòng sau:
# * hard core 0
# Chỉnh sửa file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf và thêm dòng sau:
# fs.suid_dumpable = 0
# Thực hiện câu lệnh sau để đặt thông số vào kernel đang hoạt động:
# sysctl -w fs.suid_dumpable=0
# Chỉnh sửa file /etc/systemd/coredump.conf và thêm dòng sau để vô hiệu hoá core dump:
# Storage=none
# ProcessSizeMax=0
# Thực hiện câu lệnh sau để tải lại cấu hình của systemd daemon:
# systemctl daemon-reload
if [ $(grep -P "^\h*\*\s+hard\s+core\s+0" /etc/security/limits.conf /etc/security/limits.d/*.conf 2>/dev/null | wc -l) -eq 0 ] || [ $(sysctl fs.suid_dumpable 2>/dev/null | grep 0 | wc -l) -eq 0 ] || [ $(grep "fs\.suid_dumpable.*=.*0" /etc/sysctl.conf /etc/sysctl.d/*.conf 2>/dev/null | wc -l) -eq 0 ] || [ $(grep -Ei '^\h*ProcessSizeMax\s*=\s*0' /etc/systemd/coredump.conf 2>/dev/null | wc -l) -eq 0 ] || [ $(grep -Ei '^\h*storage\s*=\s*none' /etc/systemd/coredump.conf 2>/dev/null | wc -l) -eq 0 ]; then
echo "{\"1.5.1. Cấu hình vô hiệu hoá core dump\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/security/limits.conf hoặc /etc/security/limits.d/*.conf và thêm dòng sau:
# * hard core 0
# Chỉnh sửa file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf và thêm dòng sau:
# fs.suid_dumpable = 0
# Thực hiện câu lệnh sau để đặt thông số vào kernel đang hoạt động:
# sysctl -w fs.suid_dumpable=0
# Chỉnh sửa file /etc/systemd/coredump.conf và thêm dòng sau để vô hiệu hoá core dump:
# Storage=none
# ProcessSizeMax=0
# Thực hiện câu lệnh sau để tải lại cấu hình của systemd daemon:
# systemctl daemon-reload"
if [ $(grep -P "^\h*\*\s+hard\s+core\s+0" /etc/security/limits.conf /etc/security/limits.d/*.conf 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*\h*\*\s+hard\s+core\s+0\" /etc/security/limits.conf /etc/security/limits.d/*.conf 2>/dev/null -ne 0 ";grep -P "^\h*\*\s+hard\s+core\s+0" /etc/security/limits.conf /etc/security/limits.d/*.conf 2>/dev/null; fi
if [ $(sysctl fs.suid_dumpable 2>/dev/null | grep 0 | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sysctl fs.suid_dumpable 2>/dev/null | grep 0 -ne 0 ";sysctl fs.suid_dumpable 2>/dev/null | grep 0; fi
if [ $(grep "fs\.suid_dumpable.*=.*0" /etc/sysctl.conf /etc/sysctl.d/*.conf 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep \"fs\.suid_dumpable.*=.*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf 2>/dev/null -ne 0 ";grep "fs\.suid_dumpable.*=.*0" /etc/sysctl.conf /etc/sysctl.d/*.conf 2>/dev/null; fi
if [ $(grep -Ei '^\h*ProcessSizeMax\s*=\s*0' /etc/systemd/coredump.conf 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ei '^\h*ProcessSizeMax\s*=\s*0' /etc/systemd/coredump.conf 2>/dev/null -ne 0 ";grep -Ei '^\h*ProcessSizeMax\s*=\s*0' /etc/systemd/coredump.conf 2>/dev/null; fi
if [ $(grep -Ei '^\h*storage\s*=\s*none' /etc/systemd/coredump.conf 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ei '^\h*storage\s*=\s*none' /etc/systemd/coredump.conf 2>/dev/null -ne 0 ";grep -Ei '^\h*storage\s*=\s*none' /etc/systemd/coredump.conf 2>/dev/null; fi
echo "######################################"
else
echo "{\"1.5.1. Cấu hình vô hiệu hoá core dump\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa hoặc tạo một file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf và thêm vào dòng sau:
# kernel.randomize_va_space = 2
# Thực hiện câu lệnh sau để đặt thông số vào kernel đang hoạt động:
# sysctl -w kernel.randomize_va_space=2
if [ $(sysctl kernel.randomize_va_space 2>/dev/null | grep 2 | wc -l) -eq 0 ] || [ $(grep -P "^\h*kernel.randomize_va_space.*=.*2" /etc/sysctl.conf /etc/sysctl.d/*.conf 2>/dev/null | wc -l) -eq 0 ]; then
echo "{\"1.5.2. Cấu hình kích hoạt ASLR (address space layout randomization)\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa hoặc tạo một file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf và thêm vào dòng sau:
# kernel.randomize_va_space = 2
# Thực hiện câu lệnh sau để đặt thông số vào kernel đang hoạt động:
# sysctl -w kernel.randomize_va_space=2"
if [ $(sysctl kernel.randomize_va_space 2>/dev/null | grep 2 | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sysctl kernel.randomize_va_space 2>/dev/null | grep 2 -ne 0 ";sysctl kernel.randomize_va_space 2>/dev/null | grep 2; fi
if [ $(grep -P "^\h*kernel.randomize_va_space.*=.*2" /etc/sysctl.conf /etc/sysctl.d/*.conf 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*\h*kernel.randomize_va_space.*=.*2\" /etc/sysctl.conf /etc/sysctl.d/*.conf 2>/dev/null -ne 0 ";grep -P "^\h*kernel.randomize_va_space.*=.*2" /etc/sysctl.conf /etc/sysctl.d/*.conf 2>/dev/null ; fi
echo "######################################"
else
echo "{\"1.5.2. Cấu hình kích hoạt ASLR (address space layout randomization)\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện câu lệnh sau để khôi phục binaries trở về bình thường:
# prelink -ua
# Gỡ cài đặt prelink sử dụng trình quản lý package phù hợp:
# yum remove prelink
if [ $(rpm -qa prelink | wc -l) -ne 0 ]; then
echo "{\"1.5.3. Cấu hình vô hiệu hoá prelink\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để khôi phục binaries trở về bình thường:
# prelink -ua
# Gỡ cài đặt prelink sử dụng trình quản lý package phù hợp:
# yum remove prelink"
if [ $(rpm -qa prelink | wc -l) -ne 0 ]; then echo "-------------------"; echo "#rpm -qa prelink -eq 0 ";rpm -qa prelink; fi
echo "######################################"
else
echo "{\"1.5.3. Cấu hình vô hiệu hoá prelink\" : \"PASSED\"}"
fi
##################################################################################################################
echo -e "\n######################################"
if [ $(grep -E -i "(\\\v|\\\r|\\\m|\\\s|$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/"//g'))" /etc/motd 2>/dev/null | wc -l) -ne 0 ]; then
echo "{\"1.6.1. Kiểm soát nội dung motd (Message Of The Day)\" : \"FAILED\"}"
else
echo "{\"1.6.1. Kiểm soát nội dung motd (Message Of The Day)\" : \"PASSED\"}"
fi
# Log
if [ $(grep -E -i "(\\\v|\\\r|\\\m|\\\s|$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/"//g'))" /etc/motd 2>/dev/null | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -E -i \"(\\\\\\v|\\\\\\r|\\\\\\m|\\\\\\s|\$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/\"//g'))\" /etc/motd 2>/dev/null -eq 0"; grep -E -i "(\\\v|\\\r|\\\m|\\\s|$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/"//g'))" /etc/motd 2>/dev/null
echo "----------LOG----------"
echo "#cat /etc/motd"; cat /etc/motd
##################################################################################################################
echo -e "\n######################################"
if [ $(grep -E -i "(\\\v|\\\r|\\\m|\\\s|$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/"//g'))" /etc/issue 2>/dev/null | wc -l) -ne 0 ]; then
echo "{\"1.6.2. Kiểm soát nội dung thông báo khi đăng nhập\" : \"FAILED\"}"
else
echo "{\"1.6.2. Kiểm soát nội dung thông báo khi đăng nhập\" : \"PASSED\"}"
fi
# Log
if [ $(grep -E -i "(\\\v|\\\r|\\\m|\\\s|$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/"//g'))" /etc/issue 2>/dev/null | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -E -i \"(\\\\\\v|\\\\\\r|\\\\\\m|\\\\\\s|\$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/\"//g'))\" /etc/issue 2>/dev/null -eq 0"; grep -E -i "(\\\v|\\\r|\\\m|\\\s|$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/"//g'))" /etc/issue 2>/dev/null
echo "----------LOG----------"
echo "#cat /etc/issue"; cat /etc/issue
##################################################################################################################
echo -e "\n######################################"
if [ $(grep -E -i "(\\\v|\\\r|\\\m|\\\s|$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/"//g'))" /etc/issue.net 2>/dev/null | wc -l) -ne 0 ]; then
echo "{\"1.6.3. Kiểm soát nội dung thông báo khi đăng nhập từ xa\" : \"FAILED\"}"
else
echo "{\"1.6.3. Kiểm soát nội dung thông báo khi đăng nhập từ xa\" : \"PASSED\"}"
fi
# Log
if [ $(grep -E -i "(\\\v|\\\r|\\\m|\\\s|$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/"//g'))" /etc/issue.net 2>/dev/null | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -E -i \"(\\\\\\v|\\\\\\r|\\\\\\m|\\\\\\s|\$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/\"//g'))\" /etc/issue.net 2>/dev/null -eq 0"; grep -E -i "(\\\v|\\\r|\\\m|\\\s|$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/"//g'))" /etc/issue.net 2>/dev/null
echo "----------LOG----------"
echo "#cat /etc/issue.net"; cat /etc/issue.net
##################################################################################################################
echo -e "\n######################################"
if [ $(stat -c "%a:%u:%g" /etc/motd 2>/dev/null | grep -P "^\h*[0-6][0-4][0-4]:0:0$" | wc -l) -eq 0 ]; then
echo "{\"1.6.4. Cấu hình phân quyền đối với file /etc/motd\" : \"FAILED\"}"
else
echo "{\"1.6.4. Cấu hình phân quyền đối với file /etc/motd\" : \"PASSED\"}"
fi
# Log
if [ $(stat -c "%a:%u:%g" /etc/motd 2>/dev/null | grep -P "^\h*[0-6][0-4][0-4]:0:0$" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#stat -c \"%a:%u:%g\" /etc/motd 2>/dev/null | grep -P \"^\\h*[0-6][0-4][0-4]:0:0\$\" -ne 0"; stat -c "%a:%u:%g" /etc/motd 2>/dev/null | grep -P "^\h*[0-6][0-4][0-4]:0:0$"
echo "----------LOG----------"
echo "#stat -c \"%a:%u:%g\" /etc/motd"; stat -c "%a:%u:%g" /etc/motd
##################################################################################################################
echo -e "\n######################################"
if [ $(stat -c "%a:%u:%g" /etc/issue 2>/dev/null | grep -P "^\h*[0-6][0-4][0-4]:0:0$" | wc -l) -eq 0 ]; then
echo "{\"1.6.5. Cấu hình phân quyền đối với file /etc/issue\" : \"FAILED\"}"
else
echo "{\"1.6.5. Cấu hình phân quyền đối với file /etc/issue\" : \"PASSED\"}"
fi
# Log
if [ $(stat -c "%a:%u:%g" /etc/issue 2>/dev/null | grep -P "^\h*[0-6][0-4][0-4]:0:0$" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#stat -c \"%a:%u:%g\" /etc/issue 2>/dev/null | grep -P \"^\\h*[0-6][0-4][0-4]:0:0\$\" -ne 0"; stat -c "%a:%u:%g" /etc/issue 2>/dev/null | grep -P "^\h*[0-6][0-4][0-4]:0:0$"
echo "----------LOG----------"
echo "#stat -c \"%a:%u:%g\" /etc/issue"; stat -c "%a:%u:%g" /etc/issue
##################################################################################################################
echo -e "\n######################################"
if [ $(stat -c "%a:%u:%g" /etc/issue.net 2>/dev/null | grep -P "^\h*[0-6][0-4][0-4]:0:0$" | wc -l) -eq 0 ]; then
echo "{\"1.6.6. Cấu hình phân quyền đối với file /etc/issue.net\" : \"FAILED\"}"
else
echo "{\"1.6.6. Cấu hình phân quyền đối với file /etc/issue.net\" : \"PASSED\"}"
fi
# Log
if [ $(stat -c "%a:%u:%g" /etc/issue.net 2>/dev/null | grep -P "^\h*[0-6][0-4][0-4]:0:0$" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#stat -c \"%a:%u:%g\" /etc/issue.net 2>/dev/null | grep -P \"^\\h*[0-6][0-4][0-4]:0:0\$\" -ne 0"; stat -c "%a:%u:%g" /etc/issue.net 2>/dev/null | grep -P "^\h*[0-6][0-4][0-4]:0:0$"
echo "----------LOG----------"
echo "#stat -c \"%a:%u:%g\" /etc/issue.net"; stat -c "%a:%u:%g" /etc/issue.net
##################################################################################################################
echo -e "\n######################################"
if [[ $(systemctl get-default | grep multi-user.target | wc -l) -eq 0 && ($(grep -P "^\h*user-db:user" /etc/dconf/profile/gdm 2>/dev/null | wc -l) -eq 0 || $(grep -P "^\h*system-db:gdm" /etc/dconf/profile/gdm 2>/dev/null | wc -l) -eq 0 || $(grep -P "^\h*file-db:/usr/share/gdm/greeter-dconf-defaults" /etc/dconf/profile/gdm 2>/dev/null | wc -l) -eq 0 || $(grep -P "^\h*\[org/gnome/login-screen\]" /etc/dconf/db/gdm.d/* 2>/dev/null | wc -l) -eq 0 || $(grep -P "^\h*banner-message-enable=true" /etc/dconf/db/gdm.d/* 2>/dev/null | wc -l) -eq 0 || $(grep -P "^\h*banner-message-text" /etc/dconf/db/gdm.d/* 2>/dev/null | wc -l) -eq 0 || $(grep -P "^\h*disable-user-list=true" /etc/dconf/db/gdm.d/* 2>/dev/null | wc -l) -eq 0) ]]; then
echo "{\"1.6.7. Kiểm soát nội dung thông báo khi truy cập GNOME\" : \"FAILED\"}"
else
echo "{\"1.6.7. Kiểm soát nội dung thông báo khi truy cập GNOME\" : \"PASSED\"}"
fi
# Log
if [ $(systemctl get-default | grep multi-user.target | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl get-default | grep multi-user.target -ne 0"; systemctl get-default | grep multi-user.target
if [ $(grep -P "^\h*user-db:user" /etc/dconf/profile/gdm 2>/dev/null | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -P \"^\\h*user-db:user\" /etc/dconf/profile/gdm 2>/dev/null -ne 0"; grep -P "^\h*user-db:user" /etc/dconf/profile/gdm 2>/dev/null
if [ $(grep -P "^\h*system-db:gdm" /etc/dconf/profile/gdm 2>/dev/null | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -P \"^\\h*system-db:gdm\" /etc/dconf/profile/gdm 2>/dev/null -ne 0"; grep -P "^\h*system-db:gdm" /etc/dconf/profile/gdm 2>/dev/null
if [ $(grep -P "^\h*file-db:/usr/share/gdm/greeter-dconf-defaults" /etc/dconf/profile/gdm 2>/dev/null | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -P \"^\\h*file-db:/usr/share/gdm/greeter-dconf-defaults\" /etc/dconf/profile/gdm 2>/dev/null -ne 0"; grep -P "^\h*file-db:/usr/share/gdm/greeter-dconf-defaults" /etc/dconf/profile/gdm 2>/dev/null
if [ $(grep -P "^\h*\[org/gnome/login-screen\]" /etc/dconf/db/gdm.d/* 2>/dev/null | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -P \"^\\h*\\[org/gnome/login-screen\\]\" /etc/dconf/db/gdm.d/* 2>/dev/null -ne 0"; grep -P "^\h*\[org/gnome/login-screen\]" /etc/dconf/db/gdm.d/* 2>/dev/null
if [ $(grep -P "^\h*banner-message-enable=true" /etc/dconf/db/gdm.d/* 2>/dev/null | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -P \"^\\h*banner-message-enable=true\" /etc/dconf/db/gdm.d/* 2>/dev/null -ne 0"; grep -P "^\h*banner-message-enable=true" /etc/dconf/db/gdm.d/* 2>/dev/null
if [ $(grep -P "^\h*banner-message-text" /etc/dconf/db/gdm.d/* 2>/dev/null | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -P \"^\\h*banner-message-text\" /etc/dconf/db/gdm.d/* 2>/dev/null -ne 0"; grep -P "^\h*banner-message-text" /etc/dconf/db/gdm.d/* 2>/dev/null
if [ $(grep -P "^\h*disable-user-list=true" /etc/dconf/db/gdm.d/* 2>/dev/null | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -P \"^\\h*disable-user-list=true\" /etc/dconf/db/gdm.d/* 2>/dev/null -ne 0"; grep -P "^\h*disable-user-list=true" /etc/dconf/db/gdm.d/* 2>/dev/null
echo "----------LOG----------"
echo "#systemctl get-default"; systemctl get-default
echo "#grep -P \"^\\h*user-db\" /etc/dconf/profile/gdm"; grep -P "^\h*user-db" /etc/dconf/profile/gdm
echo "#grep -P \"^\\h*system-db\" /etc/dconf/profile/gdm"; grep -P "^\h*system-db" /etc/dconf/profile/gdm
echo "#grep -P \"^\\h*file-db\" /etc/dconf/profile/gdm"; grep -P "^\h*file-db" /etc/dconf/profile/gdm
echo "#grep -P \"^\\h*\\[org/gnome/login-screen\\]\" /etc/dconf/db/gdm.d/*"; grep -P "^\h*\[org/gnome/login-screen\]" /etc/dconf/db/gdm.d/*
echo "#grep -P \"^\\h*banner-message-enable\" /etc/dconf/db/gdm.d/*"; grep -P "^\h*banner-message-enable" /etc/dconf/db/gdm.d/*
echo "#grep -P \"^\\h*banner-message-text\" /etc/dconf/db/gdm.d/*"; grep -P "^\h*banner-message-text" /etc/dconf/db/gdm.d/*
echo "#grep -P \"^\\h*disable-user-list\" /etc/dconf/db/gdm.d/*"; grep -P "^\h*disable-user-list" /etc/dconf/db/gdm.d/*
############################################################################
# Thực hiện câu lệnh sau để cài đặt SELinux:
# yum install libselinux
# Chỉnh sửa file /etc/default/grub và loại bỏ tất cả giá trị selinux=0 và enforcing=0 khỏi các tham số CMDLINE_LINUX. Ví dụ:
# GRUB_CMDLINE_LINUX_DEFAULT="quiet"
# GRUB_CMDLINE_LINUX=""
# Thực hiện câu lệnh sau để cập nhật cấu hình grub2:
# grub2-mkconfig -o /boot/grub2/grub.cfg
efidir=$(find /boot/efi/EFI/* -type d -not -name 'BOOT')
gbdir=$(find /boot -maxdepth 1 -type d -name 'grub*')
if [ $(rpm -qa libselinux | wc -l) -eq 0 ] || [ $(grep "^GRUB_CMDLINE_LINUX" "$efidir"/grub.cfg 2>/dev/null | grep -E "(selinux=0|enforcing=0)" | wc -l) -ne 0 ] || [ $(grep "^GRUB_CMDLINE_LINUX" "$gbdir"/grub.cfg /etc/default/grub 2>/dev/null | grep -E "(selinux=0|enforcing=0)" | wc -l) -ne 0 ]; then
echo "{\"1.6.1.1. Kiểm tra cài đặt SELinux\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để cài đặt SELinux:
# yum install libselinux
# Chỉnh sửa file /etc/default/grub và loại bỏ tất cả giá trị selinux=0 và enforcing=0 khỏi các tham số CMDLINE_LINUX. Ví dụ:
# GRUB_CMDLINE_LINUX_DEFAULT=\"quiet\"
# GRUB_CMDLINE_LINUX=\"\"
# Thực hiện câu lệnh sau để cập nhật cấu hình grub2:
# grub2-mkconfig -o /boot/grub2/grub.cfg"
if [ $(rpm -qa libselinux | wc -l) -eq 0 ]; then echo "-------------------"; echo "#rpm -qa libselinux -ne 0 ";rpm -qa libselinux; fi
if [ $(grep "^GRUB_CMDLINE_LINUX" "$efidir"/grub.cfg 2>/dev/null | grep -E "(selinux=0|enforcing=0)" | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep \"^GRUB_CMDLINE_LINUX\" \"\$efidir\"/grub.cfg 2>/dev/null | grep -E \"(selinux=0|enforcing=0)\" -eq 0 ";grep "^GRUB_CMDLINE_LINUX" "$efidir"/grub.cfg 2>/dev/null | grep -E "(selinux=0|enforcing=0)"; fi
if [ $(grep "^GRUB_CMDLINE_LINUX" "$gbdir"/grub.cfg /etc/default/grub 2>/dev/null | grep -E "(selinux=0|enforcing=0)" | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep \"^GRUB_CMDLINE_LINUX\" \"\$gbdir\"/grub.cfg /etc/default/grub 2>/dev/null | grep -E \"(selinux=0|enforcing=0)\" -eq 0 ";grep "^GRUB_CMDLINE_LINUX" "$gbdir"/grub.cfg /etc/default/grub 2>/dev/null | grep -E "(selinux=0|enforcing=0)"; fi
echo "######################################"
else
echo "{\"1.6.1.1. Kiểm tra cài đặt SELinux\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/selinux/config và chỉnh sửa tham số SELINUXTYPE như sau:
# SELINUXTYPE=targeted
if [ $(grep "^SELINUXTYPE=targeted" /etc/selinux/config 2>/dev/null | wc -l) -eq 0 ]; then
echo "{\"1.6.1.2 Cấu hình chính sách SELinux\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/selinux/config và chỉnh sửa tham số SELINUXTYPE như sau:
# SELINUXTYPE=targeted"
if [ $(grep "^SELINUXTYPE=targeted" /etc/selinux/config 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep \"^SELINUXTYPE=targeted\" /etc/selinux/config 2>/dev/null -ne 0 ";grep "^SELINUXTYPE=targeted" /etc/selinux/config 2>/dev/null ; fi
echo "######################################"
else
echo "{\"1.6.1.2. Cấu hình chính sách SELinux\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện câu lệnh sau để đặt SELinux mode là Permissive (Chế độ chỉ ghi log cảnh báo):
# setenforce 0
# Chỉnh sửa file /etc/selinux/config và đặt tham số SELINUX như sau:
# SELINUX=permissive
if [ $(getenforce | grep Permissive | wc -l) -eq 0 ] || [ $(grep -i SELINUX=permissive /etc/selinux/config 2>/dev/null | wc -l) -eq 0 ]; then
echo "{\"1.6.1.3. Cấu hình SELinux mode\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để đặt SELinux mode là Permissive (Chế độ chỉ ghi log cảnh báo):
# setenforce 0
# Chỉnh sửa file /etc/selinux/config và đặt tham số SELINUX như sau:
# SELINUX=permissive"
if [ $(getenforce | grep Permissive | wc -l) -eq 0 ]; then echo "-------------------"; echo "#getenforce | grep Permissive -ne 0 ";getenforce | grep Permissive; fi
if [ $(grep -i SELINUX=permissive /etc/selinux/config 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -i SELINUX=permissive /etc/selinux/config 2>/dev/null -ne 0 ";grep -i SELINUX=permissive /etc/selinux/config 2>/dev/null ; fi
echo "######################################"
else
echo "{\"1.6.1.3. Cấu hình SELinux mode\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện câu lệnh sau để kiểm tra các tiến trình không giới hạn và tiến hành xử lý theo chính sách của tổ chức:
# ps -eZ | grep unconfined_service_t
if [ $(ps -eZ | grep unconfined_service_t | wc -l) -ne 0 ]; then
echo "{\"1.6.1.4. Đảm bảo không có unconfined services tồn tại\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để kiểm tra các tiến trình không giới hạn và tiến hành xử lý theo chính sách của tổ chức:
# ps -eZ | grep unconfined_service_t"
if [ $(ps -eZ | grep unconfined_service_t | wc -l) -ne 0 ]; then echo "-------------------"; echo "#ps -eZ | grep unconfined_service_t -eq 0 ";ps -eZ | grep unconfined_service_t; fi
echo "######################################"
else
echo "{\"1.6.1.4. Đảm bảo không có unconfined services tồn tại\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện câu lệnh sau để gỡ bỏ SETroubleshoot:
# yum remove setroubleshoot
if [ $(rpm -qa setroubleshoot | wc -l) -ne 0 ]; then
echo "{\"1.6.1.5. Cấu hình vô hiệu hoá SETroubleshoot\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để gỡ bỏ SETroubleshoot:
# yum remove setroubleshoot"
if [ $(rpm -qa setroubleshoot | wc -l) -ne 0 ]; then echo "-------------------"; echo "#rpm -qa setroubleshoot -eq 0 ";rpm -qa setroubleshoot; fi
echo "######################################"
else
echo "{\"1.6.1.5. Cấu hình vô hiệu hoá SETroubleshoot\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện câu lệnh sau để gỡ bỏ MCS Translation Service:
# yum remove mcstrans
if [ $(rpm -qa mcstrans | wc -l) -ne 0 ]; then
echo "{\"1.6.1.6. Cấu hình vô hiệu hoá MCS Translation Service\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để gỡ bỏ MCS Translation Service:
# yum remove mcstrans"
if [ $(rpm -qa mcstrans | wc -l) -ne 0 ]; then echo "-------------------"; echo "#rpm -qa mcstrans -eq 0 ";rpm -qa mcstrans; fi
echo "######################################"
else
echo "{\"1.6.1.6. Cấu hình vô hiệu hoá MCS Translation Service\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/motd với nội dung phù hợp dựa theo chính sách của tổ chức, loại bỏ các trường hợp \m, \r, \s, hoặc \v.
# Nếu không sử dụng motd, thực hiện câu lệnh sau để xoá bỏ file /etc/motd:
# rm /etc/motd
if [ $(grep -E -i "(\\\v|\\\r|\\\m|\\\s|$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/"//g'))" /etc/motd 2>/dev/null | wc -l) -ne 0 ]; then
echo "{\"1.7.1. Kiểm soát nội dung motd (Message Of The Day)\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/motd với nội dung phù hợp dựa theo chính sách của tổ chức, loại bỏ các trường hợp \m, \r, \s, hoặc \v.
# Nếu không sử dụng motd, thực hiện câu lệnh sau để xoá bỏ file /etc/motd:
# rm /etc/motd"
if [ $(grep -E -i "(\\\v|\\\r|\\\m|\\\s|$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/"//g'))" /etc/motd 2>/dev/null | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -E -i \"(\\\v|\\\r|\\\m|\\\s|\$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/\"//g'))\" /etc/motd 2>/dev/null -eq 0 ";grep -E -i "(\\\v|\\\r|\\\m|\\\s|$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/"//g'))" /etc/motd 2>/dev/null ; fi
echo "######################################"
else
echo "{\"1.7.1. Kiểm soát nội dung motd (Message Of The Day)\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện câu lệnh sau để đặt lại nội dung cho file /etc/issue:
# echo "Authorized uses only. All activity may be monitored and reported." > /etc/issue
if [ $(grep -E -i "(\\\v|\\\r|\\\m|\\\s|$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/"//g'))" /etc/issue 2>/dev/null | wc -l) -ne 0 ]; then
echo "{\"1.7.2. Kiểm soát nội dung thông báo khi đăng nhập\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để đặt lại nội dung cho file /etc/issue:
# echo \"Authorized uses only. All activity may be monitored and reported.\" > /etc/issue"
if [ $(grep -E -i "(\\\v|\\\r|\\\m|\\\s|$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/"//g'))" /etc/issue 2>/dev/null | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -E -i \"(\\\v|\\\r|\\\m|\\\s|\$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/\"//g'))\" /etc/issue 2>/dev/null -eq 0 ";grep -E -i "(\\\v|\\\r|\\\m|\\\s|$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/"//g'))" /etc/issue 2>/dev/null ; fi
echo "######################################"
else
echo "{\"1.7.2. Kiểm soát nội dung thông báo khi đăng nhập\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện câu lệnh sau để đặt lại nội dung cho file /etc/issue.net:
# echo "Authorized uses only. All activity may be monitored and reported." > /etc/issue.net
if [ $(grep -E -i "(\\\v|\\\r|\\\m|\\\s|$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/"//g'))" /etc/issue.net 2>/dev/null | wc -l) -ne 0 ]; then
echo "{\"1.7.3. Kiểm soát nội dung thông báo khi đăng nhập từ xa\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để đặt lại nội dung cho file /etc/issue.net:
# echo \"Authorized uses only. All activity may be monitored and reported.\" > /etc/issue.net"
if [ $(grep -E -i "(\\\v|\\\r|\\\m|\\\s|$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/"//g'))" /etc/issue.net 2>/dev/null | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -E -i \"(\\\v|\\\r|\\\m|\\\s|\$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/\"//g'))\" /etc/issue.net 2>/dev/null -eq 0 ";grep -E -i "(\\\v|\\\r|\\\m|\\\s|$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/"//g'))" /etc/issue.net 2>/dev/null ; fi
echo "######################################"
else
echo "{\"1.7.3. Kiểm soát nội dung thông báo khi đăng nhập từ xa\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện các câu lệnh sau để đặt quyền cho file /etc/motd:
# chown root:root /etc/motd
# chmod u-x,go-wx /etc/motd
if [ $(stat -c "%a:%u:%g" /etc/motd 2>/dev/null | grep -P "^\h*[0-6][0-4][0-4]:0:0$" | wc -l) -eq 0 ]; then
echo "{\"1.7.4. Cấu hình phân quyền đối với file /etc/motd\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để đặt quyền cho file /etc/motd:
# chown root:root /etc/motd
# chmod u-x,go-wx /etc/motd"
if [ $(stat -c "%a:%u:%g" /etc/motd 2>/dev/null | grep -P "^\h*[0-6][0-4][0-4]:0:0$" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat -c \"%a:%u:%g\" /etc/motd 2>/dev/null | grep -P \"^\\h*[0-6][0-4][0-4]:0:0\$\" -ne 0 ";stat -c "%a:%u:%g" /etc/motd 2>/dev/null | grep -P "^\h*[0-6][0-4][0-4]:0:0$"; fi
echo "######################################"
else
echo "{\"1.7.4. Cấu hình phân quyền đối với file /etc/motd\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện các câu lệnh sau để đặt quyền cho /etc/issue:
# chown root:root /etc/issue
# chmod u-x,go-wx /etc/issue
if [ $(stat -c "%a:%u:%g" /etc/issue 2>/dev/null | grep -P "^\h*[0-6][0-4][0-4]:0:0$" | wc -l) -eq 0 ]; then
echo "{\"1.7.5. Cấu hình phân quyền đối với file /etc/issue\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để đặt quyền cho /etc/issue:
# chown root:root /etc/issue
# chmod u-x,go-wx /etc/issue"
if [ $(stat -c "%a:%u:%g" /etc/issue 2>/dev/null | grep -P "^\h*[0-6][0-4][0-4]:0:0$" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat -c \"%a:%u:%g\" /etc/issue 2>/dev/null | grep -P \"^\\h*[0-6][0-4][0-4]:0:0\$\" -ne 0 ";stat -c "%a:%u:%g" /etc/issue 2>/dev/null | grep -P "^\h*[0-6][0-4][0-4]:0:0$"; fi
echo "######################################"
else
echo "{\"1.7.5. Cấu hình phân quyền đối với file /etc/issue\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện các câu lệnh sau để đặt quyền cho /etc/issue.net:
# chown root:root /etc/issue.net
# chmod u-x,go-wx /etc/issue.net
if [ $(stat /etc/issue.net 2>/dev/null | grep '0644.*Uid.*0.*root.*Gid.*0.*root' | wc -l) -eq 0 ]; then
echo "{\"1.7.6. Cấu hình phân quyền đối với file /etc/issue.net\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để đặt quyền cho /etc/issue.net:
# chown root:root /etc/issue.net
# chmod u-x,go-wx /etc/issue.net"
if [ $(stat /etc/issue.net 2>/dev/null | grep '0644.*Uid.*0.*root.*Gid.*0.*root' | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat /etc/issue.net 2>/dev/null | grep '0644.*Uid.*0.*root.*Gid.*0.*root' -ne 0 ";stat /etc/issue.net 2>/dev/null | grep '0644.*Uid.*0.*root.*Gid.*0.*root'; fi
echo "######################################"
else
echo "{\"1.7.6. Cấu hình phân quyền đối với file /etc/issue.net\" : \"PASSED\"}"
fi
############################################################################
# Tạo file /etc/dconf/profile/gdm với các nội dung sau:
# user-db:user
# system-db:gdm
# file-db:/usr/share/gdm/greeter-dconf-defaults
# Tạo hoặc chỉnh sửa tùy chọn banner-message-enable và banner-message-text trong file /etc/dconf/db/gdm.d/01-banner-message:
# [org/gnome/login-screen]
# banner-message-enable=true
# banner-message-text='Authorized uses only. All activity may be monitored and reported.'
# disable-user-list=true
# Thực hiện câu lệnh sau để cập nhật dữ liệu hệ thống:
# dconf update
if [ $(grep -P "^\h*user-db:user" /etc/dconf/profile/gdm 2>/dev/null | wc -l) -eq 0 ] || [ $(grep -P "^\h*system-db:gdm" /etc/dconf/profile/gdm 2>/dev/null | wc -l) -eq 0 ] || [ $(grep -P "^\h*file-db:/usr/share/gdm/greeter-dconf-defaults" /etc/dconf/profile/gdm 2>/dev/null | wc -l) -eq 0 ] || [ $(grep -P "^\h*\[org/gnome/login-screen\]" /etc/dconf/db/gdm.d/* 2>/dev/null | wc -l) -eq 0 ] || [ $(grep -P "^\h*banner-message-enable=true" /etc/dconf/db/gdm.d/* 2>/dev/null | wc -l) -eq 0 ] || [ $(grep -P "^\h*banner-message-text" /etc/dconf/db/gdm.d/* 2>/dev/null | wc -l) -eq 0 ] || [ $(grep -P "^\h*disable-user-list=true" /etc/dconf/db/gdm.d/* 2>/dev/null | wc -l) -eq 0 ]; then
echo "{\"1.7.7. Kiểm soát nội dung thông báo khi truy cập GNOME\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Tạo file /etc/dconf/profile/gdm với các nội dung sau:
# user-db:user
# system-db:gdm
# file-db:/usr/share/gdm/greeter-dconf-defaults
# Tạo hoặc chỉnh sửa tùy chọn banner-message-enable và banner-message-text trong file /etc/dconf/db/gdm.d/01-banner-message:
# [org/gnome/login-screen]
# banner-message-enable=true
# banner-message-text='Authorized uses only. All activity may be monitored and reported.'
# disable-user-list=true
# Thực hiện câu lệnh sau để cập nhật dữ liệu hệ thống:
# dconf update"
if [ $(grep -P "^\h*user-db:user" /etc/dconf/profile/gdm 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*user-db:user\" /etc/dconf/profile/gdm 2>/dev/null -ne 0 ";grep -P "^\h*user-db:user" /etc/dconf/profile/gdm 2>/dev/null; fi
if [ $(grep -P "^\h*system-db:gdm" /etc/dconf/profile/gdm 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*system-db:gdm\" /etc/dconf/profile/gdm 2>/dev/null -ne 0 ";grep -P "^\h*system-db:gdm" /etc/dconf/profile/gdm 2>/dev/null; fi
if [ $(grep -P "^\h*file-db:/usr/share/gdm/greeter-dconf-defaults" /etc/dconf/profile/gdm 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*file-db:/usr/share/gdm/greeter-dconf-defaults\" /etc/dconf/profile/gdm 2>/dev/null -ne 0 ";grep -P "^\h*file-db:/usr/share/gdm/greeter-dconf-defaults" /etc/dconf/profile/gdm 2>/dev/null; fi
if [ $(grep -P "^\h*\[org/gnome/login-screen\]" /etc/dconf/db/gdm.d/* 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*\\[org/gnome/login-screen\\]\" /etc/dconf/db/gdm.d/* 2>/dev/null -ne 0 ";grep -P "^\h*\[org/gnome/login-screen\]" /etc/dconf/db/gdm.d/* 2>/dev/null; fi
if [ $(grep -P "^\h*banner-message-enable=true" /etc/dconf/db/gdm.d/* 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*banner-message-enable=true\" /etc/dconf/db/gdm.d/* 2>/dev/null -ne 0 ";grep -P "^\h*banner-message-enable=true" /etc/dconf/db/gdm.d/* 2>/dev/null; fi
if [ $(grep -P "^\h*banner-message-text" /etc/dconf/db/gdm.d/* 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*banner-message-text\" /etc/dconf/db/gdm.d/* 2>/dev/null -ne 0 ";grep -P "^\h*banner-message-text" /etc/dconf/db/gdm.d/* 2>/dev/null; fi
if [ $(grep -P "^\h*disable-user-list=true" /etc/dconf/db/gdm.d/* 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*disable-user-list=true\" /etc/dconf/db/gdm.d/* 2>/dev/null -ne 0 ";grep -P "^\h*disable-user-list=true" /etc/dconf/db/gdm.d/* 2>/dev/null; fi
echo "######################################"
else
echo "{\"1.7.7. Kiểm soát nội dung thông báo khi truy cập GNOME\" : \"PASSED\"}"
fi
##################################################################################################################
# Thực hiện câu lệnh sau để cài đặt chrony:
# yum install chrony
# Thêm và chỉnh sửa dòng server hoặc pool ở file /etc/chrony.conf sao cho phù hợp:
# server <remote-server>
# Thêm hoặc chỉnh sửa OPTIONS trong file /etc/sysconfig/chronyd như sau:
# OPTIONS="-u chrony"
if [ $(rpm -qa chrony | wc -l) -eq 0 ] || [ $(grep -P "^\h*(server|pool)" /etc/chrony.conf 2>/dev/null | wc -l) -eq 0 ] || [ $(grep -E '^OPTIONS="-u chrony"' /etc/sysconfig/chronyd 2>/dev/null | wc -l) -eq 0 ]; then
echo "{\"2.1.1. Cấu hình sử dụng chrony\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để cài đặt chrony:
# yum install chrony
# Thêm và chỉnh sửa dòng server hoặc pool ở file /etc/chrony.conf sao cho phù hợp:
# server <remote-server>
# Thêm hoặc chỉnh sửa OPTIONS trong file /etc/sysconfig/chronyd như sau:
# OPTIONS=\"-u chrony\""
if [ $(rpm -qa chrony | wc -l) -eq 0 ]; then echo "-------------------"; echo "#rpm -qa chrony -ne 0 ";rpm -qa chrony; fi
if [ $(grep -P "^\h*(server|pool)" /etc/chrony.conf 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*(server|pool)\" /etc/chrony.conf 2>/dev/null -ne 0 ";grep -P "^\h*(server|pool)" /etc/chrony.conf 2>/dev/null; fi
if [ $(grep -E '^OPTIONS="-u chrony"' /etc/sysconfig/chronyd 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -E '^OPTIONS=\"-u chrony\"' /etc/sysconfig/chronyd 2>/dev/null -ne 0 ";grep -E '^OPTIONS="-u chrony"' /etc/sysconfig/chronyd 2>/dev/null; fi
echo "######################################"
else
echo "{\"2.1.1. Cấu hình sử dụng chrony\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện câu lệnh sau để cài đặt ntp:
# yum install ntp
# Thêm hoặc chỉnh sửa các dòng restrict trong file /etc/ntp.conf như dưới đây:
# restrict -4 default kod nomodify notrap nopeer noquery
# restrict -6 default kod nomodify notrap nopeer noquery
# Thêm hoặc chỉnh sửa dòng server và pool trên file /etc/ntp.conf phù hợp:
# server <remote-server>
# Thêm hoặc chỉnh sửa OPTIONS trong file /etc/sysconfig/ntpd như sau:
# OPTIONS="-u ntp:ntp"
# Thực hiện câu lệnh sau để tải lại cấu hình của systemd daemon:
# systemctl daemon-reload
# Thực hiện câu lệnh sau để kích hoạt NTP:
# systemctl --now enable ntpd
if [ $(rpm -qa ntp | wc -l) -eq 0 ] || [ $(grep -P "^\h*restrict.*-4.*default.*kod.*nomodify.*notrap.*nopeer.*noquery" /etc/ntp.conf 2>/dev/null | wc -l) -eq 0 ] || [ $(grep -P "^\h*restrict -6.*default.*kod.*nomodify.*notrap.*nopeer.*noquery" /etc/ntp.conf 2>/dev/null | wc -l) -eq 0 ] || [ $(grep -P "^\h*(server|pool)" /etc/ntp.conf 2>/dev/null | wc -l) -eq 0 ] || [ $(grep -E '^OPTIONS="-u.*ntp:ntp"' /etc/sysconfig/ntpd 2>/dev/null | wc -l) -eq 0 ] || [ $(systemctl is-enabled ntpd 2>/dev/null | grep -P "^\h*enabled$" | wc -l) -eq 0 ]; then
echo "{\"2.1.2. Cấu hình sử dụng NTP\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để cài đặt ntp:
# yum install ntp
# Thêm hoặc chỉnh sửa các dòng restrict trong file /etc/ntp.conf như dưới đây:
# restrict -4 default kod nomodify notrap nopeer noquery
# restrict -6 default kod nomodify notrap nopeer noquery
# Thêm hoặc chỉnh sửa dòng server và pool trên file /etc/ntp.conf phù hợp:
# server <remote-server>
# Thêm hoặc chỉnh sửa OPTIONS trong file /etc/sysconfig/ntpd như sau:
# OPTIONS=\"-u ntp:ntp\"
# Thực hiện câu lệnh sau để tải lại cấu hình của systemd daemon:
# systemctl daemon-reload
# Thực hiện câu lệnh sau để kích hoạt NTP:
# systemctl --now enable ntpd"
if [ $(rpm -qa ntp | wc -l) -eq 0 ]; then echo "-------------------"; echo "#rpm -qa ntp -ne 0 ";rpm -qa ntp; fi
if [ $(grep -P "^\h*restrict.*-4.*default.*kod.*nomodify.*notrap.*nopeer.*noquery" /etc/ntp.conf 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*restrict.*-4.*default.*kod.*nomodify.*notrap.*nopeer.*noquery\" /etc/ntp.conf 2>/dev/null -ne 0 ";grep -P "^\h*restrict.*-4.*default.*kod.*nomodify.*notrap.*nopeer.*noquery" /etc/ntp.conf 2>/dev/null ; fi
if [ $(grep -P "^\h*restrict -6.*default.*kod.*nomodify.*notrap.*nopeer.*noquery" /etc/ntp.conf 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*restrict -6.*default.*kod.*nomodify.*notrap.*nopeer.*noquery\" /etc/ntp.conf 2>/dev/null -ne 0 ";grep -P "^\h*restrict -6.*default.*kod.*nomodify.*notrap.*nopeer.*noquery" /etc/ntp.conf 2>/dev/null ; fi
if [ $(grep -P "^\h*(server|pool)" /etc/ntp.conf 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*(server|pool)\" /etc/ntp.conf 2>/dev/null -ne 0 ";grep -P "^\h*(server|pool)" /etc/ntp.conf 2>/dev/null ; fi
if [ $(grep -E '^OPTIONS="-u.*ntp:ntp"' /etc/sysconfig/ntpd 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -E '^OPTIONS=\"-u.*ntp:ntp\"' /etc/sysconfig/ntpd 2>/dev/null -ne 0 ";grep -E '^OPTIONS="-u.*ntp:ntp"' /etc/sysconfig/ntpd 2>/dev/null ; fi
if [ $(systemctl is-enabled ntpd 2>/dev/null | grep -P "^\h*enabled$" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#systemctl is-enabled ntpd 2>/dev/null | grep -P \"^\\h*enabled\$\" -ne 0 ";systemctl is-enabled ntpd 2>/dev/null | grep -P "^\h*enabled$"; fi
echo "######################################"
else
echo "{\"2.1.2. Cấu hình sử dụng NTP\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện các câu lệnh sau để gỡ bỏ xinetd, X Window, Avahi Server, CUPS, DHCP Server, LDAP server, DNS Server, FTP Server, VSFTP Server, TFTP Server, HTTP server, IMAP and POP3 server, Samba, HTTP Proxy Server, net-snmp, NIS server, telnet-server:
# # xinetd
# yum remove xinetd
# # X Window
# yum remove xorg-x11-server*
# # Avahi Server
# systemctl stop avahi-daemon.socket avahi-daemon.service
# yum remove avahi-autoipd avahi
# # CUPS
# yum remove cups
# # DHCP Server
# yum remove dhcp dhcp-server
# # LDAP server
# yum remove openldap-servers
# # DNS Server
# yum remove bind
# # FTP Server
# yum remove ftp
# # VSFTP Server
# yum remove vsftpd
# # TFTP Server
# yum remove tftp-server
# # HTTP server
# yum remove httpd nginx
# # IMAP and POP3 server
# yum remove dovecot cyrus-imapd
# # Samba
# yum remove samba
# # HTTP Proxy Server
# yum remove squid
# # net-snmp
# yum remove net-snmp
# # NIS server
# yum remove ypserv
# # telnet-server
# yum remove telnet-server
##################################################################################################################
echo -e "\n######################################"
if [[ $(rpm -qa xinetd | wc -l) -ne 0 || $(systemctl is-enabled xinetd.service 2>/dev/null | grep '^enabled' | wc -l) -ne 0 || $(systemctl is-active xinetd.service 2>/dev/null | grep '^active' | wc -l) -ne 0 ]]; then
echo "{\"2.2.1. Cấu hình vô hiệu hoá xinetd services\" : \"FAILED\"}"
else
echo "{\"2.2.1. Cấu hình vô hiệu hoá xinetd services\" : \"PASSED\"}"
fi
# Log
if [ $(rpm -qa xinetd | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa xinetd -eq 0"; rpm -qa xinetd
if [ $(systemctl is-enabled xinetd.service 2>/dev/null | grep '^enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled xinetd.service 2>/dev/null | grep '^enabled' -eq 0"; systemctl is-enabled xinetd.service 2>/dev/null | grep '^enabled'
if [ $(systemctl is-active xinetd.service 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active xinetd.service 2>/dev/null | grep '^active' -eq 0"; systemctl is-active xinetd.service 2>/dev/null | grep '^active'
echo "----------LOG----------"
echo "#systemctl is-enabled xinetd.service"; systemctl is-enabled xinetd.service
echo "#systemctl is-active xinetd.service"; systemctl is-active xinetd.service
##################################################################################################################
echo -e "\n######################################"
if [[ $(grep -E "\s[6].[0-9]" /etc/system-release | wc -l) -ne 0 && ($(chkconfig --list 2>/dev/null | grep "chargen-dgram:.*off" | wc -l) -eq 0 || $(chkconfig --list 2>/dev/null | grep "chargen-stream:.*off" | wc -l) -eq 0) ]]; then
echo "{\"2.2.2. Cấu hình vô hiệu hoá chargen services\" : \"FAILED\"}"
else
echo "{\"2.2.2. Cấu hình vô hiệu hoá chargen services\" : \"PASSED\"}"
fi
# Log
if [ $(grep -E "\s[6].[0-9]" /etc/system-release | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -E \"\\s[6].[0-9]\" /etc/system-release -eq 0"; grep -E "\s[6].[0-9]" /etc/system-release
if [ $(chkconfig --list 2>/dev/null | grep "chargen-dgram:.*off" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#chkconfig --list 2>/dev/null | grep \"chargen-dgram:.*off\" -ne 0"; chkconfig --list 2>/dev/null | grep "chargen-dgram:.*off"
if [ $(chkconfig --list 2>/dev/null | grep "chargen-stream:.*off" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#chkconfig --list 2>/dev/null | grep \"chargen-stream:.*off\" -ne 0"; chkconfig --list 2>/dev/null | grep "chargen-stream:.*off"
echo "----------LOG----------"
echo "#cat /etc/system-release -eq 6.x"; cat /etc/system-release
echo "#chkconfig --list 2>/dev/null | grep \"chargen-dgram\""; chkconfig --list 2>/dev/null | grep "chargen-dgram"
echo "#chkconfig --list 2>/dev/null | grep \"chargen-stream\""; chkconfig --list 2>/dev/null | grep "chargen-stream"
##################################################################################################################
echo -e "\n######################################"
if [[ $(grep -E "\s[6].[0-9]" /etc/system-release | wc -l) -ne 0 && ($(chkconfig --list 2>/dev/null | grep "daytime-dgram:.*off" | wc -l) -eq 0 || $(chkconfig --list 2>/dev/null | grep "daytime-stream:.*off" | wc -l) -eq 0) ]]; then
echo "{\"2.2.3. Cấu hình vô hiệu hoá daytime services\" : \"FAILED\"}"
else
echo "{\"2.2.3. Cấu hình vô hiệu hoá daytime services\" : \"PASSED\"}"
fi
# Log
if [ $(grep -E "\s[6].[0-9]" /etc/system-release | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -E \"\\s[6].[0-9]\" /etc/system-release -eq 0"; grep -E "\s[6].[0-9]" /etc/system-release
if [ $(chkconfig --list 2>/dev/null | grep "daytime-dgram:.*off" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#chkconfig --list 2>/dev/null | grep \"daytime-dgram:.*off\" -ne 0"; chkconfig --list 2>/dev/null | grep "daytime-dgram:.*off"
if [ $(chkconfig --list 2>/dev/null | grep "daytime-stream:.*off" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#chkconfig --list 2>/dev/null | grep \"daytime-stream:.*off\" -ne 0"; chkconfig --list 2>/dev/null | grep "daytime-stream:.*off"
echo "----------LOG----------"
echo "#cat /etc/system-release -eq 6.x"; cat /etc/system-release
echo "#chkconfig --list 2>/dev/null | grep \"daytime-dgram\""; chkconfig --list 2>/dev/null | grep "daytime-dgram"
echo "#chkconfig --list 2>/dev/null | grep \"daytime-stream\""; chkconfig --list 2>/dev/null | grep "daytime-stream"
##################################################################################################################
echo -e "\n######################################"
if [[ $(grep -E "\s[6].[0-9]" /etc/system-release | wc -l) -ne 0 && ($(chkconfig --list 2>/dev/null | grep "discard-dgram:.*off" | wc -l) -eq 0 || $(chkconfig --list 2>/dev/null | grep "discard-stream:.*off" | wc -l) -eq 0) ]]; then
echo "{\"2.2.4. Cấu hình vô hiệu hoá discard services\" : \"FAILED\"}"
else
echo "{\"2.2.4. Cấu hình vô hiệu hoá discard services\" : \"PASSED\"}"
fi
# Log
if [ $(grep -E "\s[6].[0-9]" /etc/system-release | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -E \"\\s[6].[0-9]\" /etc/system-release -eq 0"; grep -E "\s[6].[0-9]" /etc/system-release
if [ $(chkconfig --list 2>/dev/null | grep "discard-dgram:.*off" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#chkconfig --list 2>/dev/null | grep \"discard-dgram:.*off\" -ne 0"; chkconfig --list 2>/dev/null | grep "discard-dgram:.*off"
if [ $(chkconfig --list 2>/dev/null | grep "discard-stream:.*off" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#chkconfig --list 2>/dev/null | grep \"discard-stream:.*off\" -ne 0"; chkconfig --list 2>/dev/null | grep "discard-stream:.*off"
echo "----------LOG----------"
echo "#cat /etc/system-release -eq 6.x"; cat /etc/system-release
echo "#chkconfig --list 2>/dev/null | grep \"discard-dgram\""; chkconfig --list 2>/dev/null | grep "discard-dgram"
echo "#chkconfig --list 2>/dev/null | grep \"discard-stream\""; chkconfig --list 2>/dev/null | grep "discard-stream"
##################################################################################################################
echo -e "\n######################################"
if [[ $(grep -E "\s[6].[0-9]" /etc/system-release | wc -l) -ne 0 && ($(chkconfig --list 2>/dev/null | grep "echo-dgram:.*off" | wc -l) -eq 0 || $(chkconfig --list 2>/dev/null | grep "echo-stream:.*off" | wc -l) -eq 0) ]]; then
echo "{\"2.2.5. Cấu hình vô hiệu hoá echo services\" : \"FAILED\"}"
else
echo "{\"2.2.5. Cấu hình vô hiệu hoá echo services\" : \"PASSED\"}"
fi
# Log
if [ $(grep -E "\s[6].[0-9]" /etc/system-release | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -E \"\\s[6].[0-9]\" /etc/system-release -eq 0"; grep -E "\s[6].[0-9]" /etc/system-release
if [ $(chkconfig --list 2>/dev/null | grep "echo-dgram:.*off" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#chkconfig --list 2>/dev/null | grep \"echo-dgram:.*off\" -ne 0"; chkconfig --list 2>/dev/null | grep "echo-dgram:.*off"
if [ $(chkconfig --list 2>/dev/null | grep "echo-stream:.*off" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#chkconfig --list 2>/dev/null | grep \"echo-stream:.*off\" -ne 0"; chkconfig --list 2>/dev/null | grep "echo-stream:.*off"
echo "----------LOG----------"
echo "#cat /etc/system-release -eq 6.x"; cat /etc/system-release
echo "#chkconfig --list 2>/dev/null | grep \"echo-dgram\""; chkconfig --list 2>/dev/null | grep "echo-dgram"
echo "#chkconfig --list 2>/dev/null | grep \"echo-stream\""; chkconfig --list 2>/dev/null | grep "echo-stream"
##################################################################################################################
echo -e "\n######################################"
if [[ $(grep -E "\s[6].[0-9]" /etc/system-release | wc -l) -ne 0 && ($(chkconfig --list 2>/dev/null | grep "time-dgram:.*off" | wc -l) -eq 0 || $(chkconfig --list 2>/dev/null | grep "time-stream:.*off" | wc -l) -eq 0) ]]; then
echo "{\"2.2.6. Cấu hình vô hiệu hoá time services\" : \"FAILED\"}"
else
echo "{\"2.2.6. Cấu hình vô hiệu hoá time services\" : \"PASSED\"}"
fi
# Log
if [ $(grep -E "\s[6].[0-9]" /etc/system-release | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -E \"\\s[6].[0-9]\" /etc/system-release -eq 0"; grep -E "\s[6].[0-9]" /etc/system-release
if [ $(chkconfig --list 2>/dev/null | grep "time-dgram:.*off" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#chkconfig --list 2>/dev/null | grep \"time-dgram:.*off\" -ne 0"; chkconfig --list 2>/dev/null | grep "time-dgram:.*off"
if [ $(chkconfig --list 2>/dev/null | grep "time-stream:.*off" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#chkconfig --list 2>/dev/null | grep \"time-stream:.*off\" -ne 0"; chkconfig --list 2>/dev/null | grep "time-stream:.*off"
echo "----------LOG----------"
echo "#cat /etc/system-release -eq 6.x"; cat /etc/system-release
echo "#chkconfig --list 2>/dev/null | grep \"time-dgram\""; chkconfig --list 2>/dev/null | grep "time-dgram"
echo "#chkconfig --list 2>/dev/null | grep \"time-stream\""; chkconfig --list 2>/dev/null | grep "time-stream"
##################################################################################################################
echo -e "\n######################################"
if [[ $(grep -E "\s[6].[0-9]" /etc/system-release | wc -l) -ne 0 && ($(chkconfig --list 2>/dev/null | grep "rexec:.*off" | wc -l) -eq 0 || $(chkconfig --list 2>/dev/null | grep "rlogin:.*off" | wc -l) -eq 0 || $(chkconfig --list 2>/dev/null | grep "rsh:.*off" | wc -l) -eq 0) ]]; then
echo "{\"2.2.7. Cấu hình vô hiệu hoá rsh server\" : \"FAILED\"}"
else
echo "{\"2.2.7. Cấu hình vô hiệu hoá rsh server\" : \"PASSED\"}"
fi
# Log
if [ $(grep -E "\s[6].[0-9]" /etc/system-release | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -E \"\\s[6].[0-9]\" /etc/system-release -eq 0"; grep -E "\s[6].[0-9]" /etc/system-release
if [ $(chkconfig --list 2>/dev/null | grep "rexec:.*off" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#chkconfig --list 2>/dev/null | grep \"rexec:.*off\" -ne 0"; chkconfig --list 2>/dev/null | grep "rexec:.*off"
if [ $(chkconfig --list 2>/dev/null | grep "rlogin:.*off" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#chkconfig --list 2>/dev/null | grep \"rlogin:.*off\" -ne 0"; chkconfig --list 2>/dev/null | grep "rlogin:.*off"
if [ $(chkconfig --list 2>/dev/null | grep "rsh:.*off" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#chkconfig --list 2>/dev/null | grep \"rsh:.*off\" -ne 0"; chkconfig --list 2>/dev/null | grep "rsh:.*off"
echo "----------LOG----------"
echo "#cat /etc/system-release -eq 6.x"; cat /etc/system-release
echo "#chkconfig --list 2>/dev/null | grep \"rexec\""; chkconfig --list 2>/dev/null | grep "rexec"
echo "#chkconfig --list 2>/dev/null | grep \"rlogin\""; chkconfig --list 2>/dev/null | grep "rlogin"
echo "#chkconfig --list 2>/dev/null | grep \"rsh\""; chkconfig --list 2>/dev/null | grep "rsh"
##################################################################################################################
echo -e "\n######################################"
if [[ $(grep -E "\s[6].[0-9]" /etc/system-release | wc -l) -ne 0 && $(chkconfig --list 2>/dev/null | grep "talk:.*off" | wc -l) -eq 0 ]]; then
echo "{\"2.2.8. Cấu hình vô hiệu hoá talk server\" : \"FAILED\"}"
else
echo "{\"2.2.8. Cấu hình vô hiệu hoá talk server\" : \"PASSED\"}"
fi
# Log
if [ $(grep -E "\s[6].[0-9]" /etc/system-release | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -E \"\\s[6].[0-9]\" /etc/system-release -eq 0"; grep -E "\s[6].[0-9]" /etc/system-release
if [ $(chkconfig --list 2>/dev/null | grep "talk:.*off" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#chkconfig --list 2>/dev/null | grep \"talk:.*off\" -ne 0"; chkconfig --list 2>/dev/null | grep "talk:.*off"
echo "----------LOG----------"
echo "#cat /etc/system-release -eq 6.x"; cat /etc/system-release
echo "#chkconfig --list 2>/dev/null | grep \"talk\""; chkconfig --list 2>/dev/null | grep "talk"
##################################################################################################################
echo -e "\n######################################"
if [[ $(rpm -qa autofs | wc -l) -ne 0 && ($(systemctl is-enabled autofs.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-active autofs.service 2>/dev/null | grep '^active' | wc -l) -ne 0) ]]; then
echo "{\"2.2.9. Cấu hình vô hiệu hoá autofs services\" : \"FAILED\"}"
else
echo "{\"2.2.9. Cấu hình vô hiệu hoá autofs services\" : \"PASSED\"}"
fi
# Log
if [ $(rpm -qa autofs | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa autofs -eq 0"; rpm -qa autofs
if [ $(systemctl is-enabled autofs.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled autofs.service 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled autofs.service 2>/dev/null | grep 'enabled'
if [ $(systemctl is-active autofs.service 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active autofs.service 2>/dev/null | grep '^active' -eq 0"; systemctl is-active autofs.service 2>/dev/null | grep '^active'
echo "----------LOG----------"
echo "#systemctl is-enabled autofs.service"; systemctl is-enabled autofs.service
echo "#systemctl is-active autofs.service"; systemctl is-active autofs.service
##################################################################################################################
echo -e "\n######################################"
if [ $(rpm -qa xorg-x11-server* | wc -l) -ne 0 ]; then
echo "{\"2.2.10. Cấu hình vô hiệu hoá X window server services\" : \"FAILED\"}"
else
echo "{\"2.2.10. Cấu hình vô hiệu hoá X window server services\" : \"PASSED\"}"
fi
# Log
if [ $(rpm -qa xorg-x11-server* | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa xorg-x11-server* -eq 0"; rpm -qa xorg-x11-server*
echo "----------LOG----------"
##################################################################################################################
echo -e "\n######################################"
if [[ $(rpm -qa avahi | wc -l) -ne 0 && ($(systemctl is-enabled avahi-daemon.socket 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-enabled avahi-daemon.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-active avahi-daemon.socket 2>/dev/null | grep '^active' | wc -l) -ne 0 || $(systemctl is-active avahi-daemon.service 2>/dev/null | grep '^active' | wc -l) -ne 0) ]]; then
echo "{\"2.2.11. Cấu hình vô hiệu hoá avahi daemon services\" : \"FAILED\"}"
else
echo "{\"2.2.11. Cấu hình vô hiệu hoá avahi daemon services\" : \"PASSED\"}"
fi
# Log
if [ $(rpm -qa avahi | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa avahi -eq 0"; rpm -qa avahi
if [ $(systemctl is-enabled avahi-daemon.socket 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled avahi-daemon.socket 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled avahi-daemon.socket 2>/dev/null | grep 'enabled'
if [ $(systemctl is-enabled avahi-daemon.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled avahi-daemon.service 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled avahi-daemon.service 2>/dev/null | grep 'enabled'
if [ $(systemctl is-active avahi-daemon.socket 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active avahi-daemon.socket 2>/dev/null | grep '^active' -eq 0"; systemctl is-active avahi-daemon.socket 2>/dev/null | grep '^active'
if [ $(systemctl is-active avahi-daemon.service 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active avahi-daemon.service 2>/dev/null | grep '^active' -eq 0"; systemctl is-active avahi-daemon.service 2>/dev/null | grep '^active'
echo "----------LOG----------"
echo "#systemctl is-enabled avahi-daemon.socket"; systemctl is-enabled avahi-daemon.socket
echo "#systemctl is-enabled avahi-daemon.service"; systemctl is-enabled avahi-daemon.service
echo "#systemctl is-active avahi-daemon.socket"; systemctl is-active avahi-daemon.socket
echo "#systemctl is-active avahi-daemon.service"; systemctl is-active avahi-daemon.service
##################################################################################################################
echo -e "\n######################################"
if [[ $(rpm -qa cups | wc -l) -ne 0 && ($(systemctl is-enabled cups.socket 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-enabled cups.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-active cups.socket 2>/dev/null | grep '^active' | wc -l) -ne 0 || $(systemctl is-active cups.service 2>/dev/null | grep '^active' | wc -l) -ne 0) ]]; then
echo "{\"2.2.12. Cấu hình vô hiệu hoá cups services\" : \"FAILED\"}"
else
echo "{\"2.2.12. Cấu hình vô hiệu hoá cups services\" : \"PASSED\"}"
fi
# Log
if [ $(rpm -qa cups | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa cups -eq 0"; rpm -qa cups
if [ $(systemctl is-enabled cups.socket 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled cups.socket 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled cups.socket 2>/dev/null | grep 'enabled'
if [ $(systemctl is-enabled cups.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled cups.service 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled cups.service 2>/dev/null | grep 'enabled'
if [ $(systemctl is-active cups.socket 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active cups.socket 2>/dev/null | grep '^active' -eq 0"; systemctl is-active cups.socket 2>/dev/null | grep '^active'
if [ $(systemctl is-active cups.service 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active cups.service 2>/dev/null | grep '^active' -eq 0"; systemctl is-active cups.service 2>/dev/null | grep '^active'
echo "----------LOG----------"
echo "#systemctl is-enabled cups.socket"; systemctl is-enabled cups.socket
echo "#systemctl is-enabled cups.service"; systemctl is-enabled cups.service
echo "#systemctl is-active cups.socket"; systemctl is-active cups.socket
echo "#systemctl is-active cups.service"; systemctl is-active cups.service
##################################################################################################################
echo -e "\n######################################"
if [[ $(rpm -qa dhcp-server | wc -l) -ne 0 && ($(systemctl is-enabled dhcpd.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-enabled dhcpd6.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-active dhcpd.service 2>/dev/null | grep '^active' | wc -l) -ne 0 || $(systemctl is-active dhcpd6.service 2>/dev/null | grep '^active' | wc -l) -ne 0) ]]; then
echo "{\"2.2.13. Cấu hình vô hiệu hoá dhcp server services\" : \"FAILED\"}"
else
echo "{\"2.2.13. Cấu hình vô hiệu hoá dhcp server services\" : \"PASSED\"}"
fi
# Log
if [ $(rpm -qa dhcp-server | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa dhcp-server -eq 0"; rpm -qa dhcp-server
if [ $(systemctl is-enabled dhcpd.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled dhcpd.service 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled dhcpd.service 2>/dev/null | grep 'enabled'
if [ $(systemctl is-enabled dhcpd6.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled dhcpd6.service 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled dhcpd6.service 2>/dev/null | grep 'enabled'
if [ $(systemctl is-active dhcpd.service 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active dhcpd.service 2>/dev/null | grep '^active' -eq 0"; systemctl is-active dhcpd.service 2>/dev/null | grep '^active'
if [ $(systemctl is-active dhcpd6.service 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active dhcpd6.service 2>/dev/null | grep '^active' -eq 0"; systemctl is-active dhcpd6.service 2>/dev/null | grep '^active'
echo "----------LOG----------"
echo "#systemctl is-enabled dhcpd.service"; systemctl is-enabled dhcpd.service
echo "#systemctl is-enabled dhcpd6.service"; systemctl is-enabled dhcpd6.service
echo "#systemctl is-active dhcpd.service"; systemctl is-active dhcpd.service
echo "#systemctl is-active dhcpd6.service"; systemctl is-active dhcpd6.service
##################################################################################################################
echo -e "\n######################################"
if [[ $(grep -E "\s[6].[0-9]" /etc/system-release | wc -l) -ne 0 && $(rpm -qa openldap-servers | wc -l) -ne 0 ]]; then
echo "{\"2.2.14. Cấu hình vô hiệu hoá ldap server services\" : \"FAILED\"}"
else
echo "{\"2.2.14. Cấu hình vô hiệu hoá ldap server services\" : \"PASSED\"}"
fi
# Log
if [ $(grep -E "\s[6].[0-9]" /etc/system-release | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -E \"\\s[6].[0-9]\" /etc/system-release -eq 0"; grep -E "\s[6].[0-9]" /etc/system-release
if [ $(rpm -qa openldap-servers | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa openldap-servers -eq 0"; rpm -qa openldap-servers
echo "----------LOG----------"
##################################################################################################################
echo -e "\n######################################"
if [[ $(rpm -qa bind | wc -l) -ne 0 && ($(systemctl is-enabled named.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-active named.service 2>/dev/null | grep '^active' | wc -l) -ne 0) ]]; then
echo "{\"2.2.15. Cấu hình vô hiệu hoá dns server services\" : \"FAILED\"}"
else
echo "{\"2.2.15. Cấu hình vô hiệu hoá dns server services\" : \"PASSED\"}"
fi
# Log
if [ $(rpm -qa bind | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa bind -eq 0"; rpm -qa bind
if [ $(systemctl is-enabled named.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled named.service 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled named.service 2>/dev/null | grep 'enabled'
if [ $(systemctl is-active named.service 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active named.service 2>/dev/null | grep '^active' -eq 0"; systemctl is-active named.service 2>/dev/null | grep '^active'
echo "----------LOG----------"
echo "#systemctl is-enabled named.service"; systemctl is-enabled named.service
echo "#systemctl is-active named.service"; systemctl is-active named.service
##################################################################################################################
echo -e "\n######################################"
if [[ $(grep -E "\s[7-9].[0-9]" /etc/system-release | wc -l) -ne 0 && $(rpm -qa dnsmasq | wc -l) -ne 0 && ($(systemctl is-enabled dnsmasq.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-active dnsmasq.service 2>/dev/null | grep '^active' | wc -l) -ne 0) ]]; then
echo "{\"2.2.16. Cấu hình vô hiệu hoá dnsmasq services\" : \"FAILED\"}"
else
echo "{\"2.2.16. Cấu hình vô hiệu hoá dnsmasq services\" : \"PASSED\"}"
fi
# Log
if [ $(grep -E "\s[7-9].[0-9]" /etc/system-release | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -E \"\\s[7-9].[0-9]\" /etc/system-release -eq 0"; grep -E "\s[7-9].[0-9]" /etc/system-release
if [ $(rpm -qa dnsmasq | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa dnsmasq -eq 0"; rpm -qa dnsmasq
if [ $(systemctl is-enabled dnsmasq.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled dnsmasq.service 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled dnsmasq.service 2>/dev/null | grep 'enabled'
if [ $(systemctl is-active dnsmasq.service 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active dnsmasq.service 2>/dev/null | grep '^active' -eq 0"; systemctl is-active dnsmasq.service 2>/dev/null | grep '^active'
echo "----------LOG----------"
echo "#cat /etc/system-release -ge 7.x"; cat /etc/system-release
echo "#systemctl is-enabled dnsmasq.service"; systemctl is-enabled dnsmasq.service
echo "#systemctl is-active dnsmasq.service"; systemctl is-active dnsmasq.service
##################################################################################################################
echo -e "\n######################################"
if [[ $(rpm -qa vsftpd | wc -l) -ne 0 && ($(systemctl is-enabled vsftpd.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-active vsftpd.service 2>/dev/null | grep '^active' | wc -l) -ne 0) ]]; then
echo "{\"2.2.17. Cấu hình vô hiệu hoá ftp server services\" : \"FAILED\"}"
else
echo "{\"2.2.17. Cấu hình vô hiệu hoá ftp server services\" : \"PASSED\"}"
fi
# Log
if [ $(rpm -qa vsftpd | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa vsftpd -eq 0"; rpm -qa vsftpd
if [ $(systemctl is-enabled vsftpd.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled vsftpd.service 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled vsftpd.service 2>/dev/null | grep 'enabled'
if [ $(systemctl is-active vsftpd.service 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active vsftpd.service 2>/dev/null | grep '^active' -eq 0"; systemctl is-active vsftpd.service 2>/dev/null | grep '^active'
echo "----------LOG----------"
echo "#systemctl is-enabled vsftpd.service"; systemctl is-enabled vsftpd.service
echo "#systemctl is-active vsftpd.service"; systemctl is-active vsftpd.service
##################################################################################################################
echo -e "\n######################################"
if [[ $(grep -E "\s[7-9].[0-9]" /etc/system-release | wc -l) -ne 0 && $(rpm -qa tftp-server | wc -l) -ne 0 && ($(systemctl is-enabled tftp.socket 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-enabled tftp.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-active tftp.socket 2>/dev/null | grep '^active' | wc -l) -ne 0 || $(systemctl is-active tftp.service 2>/dev/null | grep '^active' | wc -l) -ne 0) ]]; then
echo "{\"2.2.18. Cấu hình vô hiệu hoá tftp server services\" : \"FAILED\"}"
else
echo "{\"2.2.18. Cấu hình vô hiệu hoá tftp server services\" : \"PASSED\"}"
fi
# Log
if [ $(grep -E "\s[7-9].[0-9]" /etc/system-release | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -E \"\\s[7-9].[0-9]\" /etc/system-release -eq 0"; grep -E "\s[7-9].[0-9]" /etc/system-release
if [ $(rpm -qa tftp-server | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa tftp-server -eq 0"; rpm -qa tftp-server
if [ $(systemctl is-enabled tftp.socket 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled tftp.socket 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled tftp.socket 2>/dev/null | grep 'enabled'
if [ $(systemctl is-enabled tftp.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled tftp.service 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled tftp.service 2>/dev/null | grep 'enabled'
if [ $(systemctl is-active tftp.socket 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active tftp.socket 2>/dev/null | grep '^active' -eq 0"; systemctl is-active tftp.socket 2>/dev/null | grep '^active'
if [ $(systemctl is-active tftp.service 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active tftp.service 2>/dev/null | grep '^active' -eq 0"; systemctl is-active tftp.service 2>/dev/null | grep '^active'
echo "----------LOG----------"
echo "#cat /etc/system-release -ge 7.x"; cat /etc/system-release
echo "#systemctl is-enabled tftp.socket"; systemctl is-enabled tftp.socket
echo "#systemctl is-enabled tftp.service"; systemctl is-enabled tftp.service
echo "#systemctl is-active tftp.socket"; systemctl is-active tftp.socket
echo "#systemctl is-active tftp.service"; systemctl is-active tftp.service
##################################################################################################################
echo -e "\n######################################"
if [[ ($(rpm -qa httpd | wc -l) -ne 0 && ($(systemctl is-enabled httpd.socket 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-enabled httpd.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-active httpd.socket 2>/dev/null | grep '^active' | wc -l) -ne 0 || $(systemctl is-active httpd.service 2>/dev/null | grep '^active' | wc -l) -ne 0)) || ($(rpm -qa nginx | wc -l) -ne 0 && ($(systemctl is-enabled nginx.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-active nginx.service 2>/dev/null | grep '^active' | wc -l) -ne 0)) ]]; then
echo "{\"2.2.19. Cấu hình vô hiệu hoá web server services\" : \"FAILED\"}"
else
echo "{\"2.2.19. Cấu hình vô hiệu hoá web server services\" : \"PASSED\"}"
fi
# Log
if [ $(grep -E "\s[7-9].[0-9]" /etc/system-release | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -E \"\\s[7-9].[0-9]\" /etc/system-release -eq 0"; grep -E "\s[7-9].[0-9]" /etc/system-release
if [ $(rpm -qa httpd nginx | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa httpd nginx -eq 0"; rpm -qa httpd nginx
if [ $(systemctl is-enabled httpd.socket 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled httpd.socket 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled httpd.socket 2>/dev/null | grep 'enabled'
if [ $(systemctl is-enabled httpd.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled httpd.service 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled httpd.service 2>/dev/null | grep 'enabled'
if [ $(systemctl is-active httpd.socket 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active httpd.socket 2>/dev/null | grep '^active' -eq 0"; systemctl is-active httpd.socket 2>/dev/null | grep '^active'
if [ $(systemctl is-active httpd.service 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active httpd.service 2>/dev/null | grep '^active' -eq 0"; systemctl is-active httpd.service 2>/dev/null | grep '^active'
if [ $(rpm -qa nginx nginx | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa nginx nginx -eq 0"; rpm -qa nginx nginx
if [ $(systemctl is-enabled nginx.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled nginx.service 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled nginx.service 2>/dev/null | grep 'enabled'
if [ $(systemctl is-active nginx.service 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active nginx.service 2>/dev/null | grep '^active' -eq 0"; systemctl is-active nginx.service 2>/dev/null | grep '^active'
echo "----------LOG----------"
echo "#cat /etc/system-release -ge 7.x"; cat /etc/system-release
echo "#systemctl is-enabled httpd.socket"; systemctl is-enabled httpd.socket
echo "#systemctl is-enabled httpd.service"; systemctl is-enabled httpd.service
echo "#systemctl is-active httpd.socket"; systemctl is-active httpd.socket
echo "#systemctl is-active httpd.service"; systemctl is-active httpd.service
echo "#systemctl is-enabled nginx.service"; systemctl is-enabled nginx.service
echo "#systemctl is-active nginx.service"; systemctl is-active nginx.service
##################################################################################################################
echo -e "\n######################################"
if [[ ($(rpm -qa dovecot | wc -l) -ne 0 && ($(systemctl is-enabled dovecot.socket 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-enabled dovecot.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-active dovecot.socket 2>/dev/null | grep '^active' | wc -l) -ne 0 || $(systemctl is-active dovecot.service 2>/dev/null | grep '^active' | wc -l) -ne 0)) || ($(rpm -qa cyrus-imapd | wc -l) -ne 0 && ($(systemctl is-enabled cyrus-imapd.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-active cyrus-imapd.service 2>/dev/null | grep '^active' | wc -l) -ne 0)) ]]; then
echo "{\"2.2.20. Cấu hình vô hiệu hoá imap and pop3 server services\" : \"FAILED\"}"
else
echo "{\"2.2.20. Cấu hình vô hiệu hoá imap and pop3 server services\" : \"PASSED\"}"
fi
# Log
if [ $(grep -E "\s[7-9].[0-9]" /etc/system-release | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -E \"\\s[7-9].[0-9]\" /etc/system-release -eq 0"; grep -E "\s[7-9].[0-9]" /etc/system-release
if [ $(rpm -qa dovecot cyrus-imapd | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa dovecot cyrus-imapd -eq 0"; rpm -qa dovecot cyrus-imapd
if [ $(systemctl is-enabled dovecot.socket 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled dovecot.socket 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled dovecot.socket 2>/dev/null | grep 'enabled'
if [ $(systemctl is-enabled dovecot.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled dovecot.service 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled dovecot.service 2>/dev/null | grep 'enabled'
if [ $(systemctl is-active dovecot.socket 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active dovecot.socket 2>/dev/null | grep '^active' -eq 0"; systemctl is-active dovecot.socket 2>/dev/null | grep '^active'
if [ $(systemctl is-active dovecot.service 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active dovecot.service 2>/dev/null | grep '^active' -eq 0"; systemctl is-active dovecot.service 2>/dev/null | grep '^active'
if [ $(rpm -qa cyrus-imapd cyrus-imapd | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa cyrus-imapd cyrus-imapd -eq 0"; rpm -qa cyrus-imapd cyrus-imapd
if [ $(systemctl is-enabled cyrus-imapd.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled cyrus-imapd.service 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled cyrus-imapd.service 2>/dev/null | grep 'enabled'
if [ $(systemctl is-active cyrus-imapd.service 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active cyrus-imapd.service 2>/dev/null | grep '^active' -eq 0"; systemctl is-active cyrus-imapd.service 2>/dev/null | grep '^active'
echo "----------LOG----------"
echo "#cat /etc/system-release -ge 7.x"; cat /etc/system-release
echo "#systemctl is-enabled dovecot.socket"; systemctl is-enabled dovecot.socket
echo "#systemctl is-enabled dovecot.service"; systemctl is-enabled dovecot.service
echo "#systemctl is-active dovecot.socket"; systemctl is-active dovecot.socket
echo "#systemctl is-active dovecot.service"; systemctl is-active dovecot.service
echo "#systemctl is-enabled cyrus-imapd.service"; systemctl is-enabled cyrus-imapd.service
echo "#systemctl is-active cyrus-imapd.service"; systemctl is-active cyrus-imapd.service
##################################################################################################################
echo -e "\n######################################"
if [[ $(rpm -qa samba | wc -l) -ne 0 && ($(systemctl is-enabled smb.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-active smb.service 2>/dev/null | grep '^active' | wc -l) -ne 0) ]]; then
echo "{\"2.2.21. Cấu hình vô hiệu hoá samba file server services\" : \"FAILED\"}"
else
echo "{\"2.2.21. Cấu hình vô hiệu hoá samba file server services\" : \"PASSED\"}"
fi
# Log
if [ $(rpm -qa samba | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa samba -eq 0"; rpm -qa samba
if [ $(systemctl is-enabled smb.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled smb.service 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled smb.service 2>/dev/null | grep 'enabled'
if [ $(systemctl is-active smb.service 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active smb.service 2>/dev/null | grep '^active' -eq 0"; systemctl is-active smb.service 2>/dev/null | grep '^active'
echo "----------LOG----------"
echo "#systemctl is-enabled smb.service"; systemctl is-enabled smb.service
echo "#systemctl is-active smb.service"; systemctl is-active smb.service
##################################################################################################################
echo -e "\n######################################"
if [[ $(rpm -qa squid | wc -l) -ne 0 && ($(systemctl is-enabled squid.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-active squid.service 2>/dev/null | grep '^active' | wc -l) -ne 0) ]]; then
echo "{\"2.2.22. Cấu hình vô hiệu hoá web proxy server services\" : \"FAILED\"}"
else
echo "{\"2.2.22. Cấu hình vô hiệu hoá web proxy server services\" : \"PASSED\"}"
fi
# Log
if [ $(rpm -qa squid | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa squid -eq 0"; rpm -qa squid
if [ $(systemctl is-enabled squid.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled squid.service 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled squid.service 2>/dev/null | grep 'enabled'
if [ $(systemctl is-active squid.service 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active squid.service 2>/dev/null | grep '^active' -eq 0"; systemctl is-active squid.service 2>/dev/null | grep '^active'
echo "----------LOG----------"
echo "#systemctl is-enabled squid.service"; systemctl is-enabled squid.service
echo "#systemctl is-active squid.service"; systemctl is-active squid.service
##################################################################################################################
echo -e "\n######################################"
if [[ $(rpm -qa net-snmp | wc -l) -ne 0 && ($(systemctl is-enabled snmpd.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-active snmpd.service 2>/dev/null | grep '^active' | wc -l) -ne 0) ]]; then
echo "{\"2.2.23. Cấu hình vô hiệu hoá snmp services\" : \"FAILED\"}"
else
echo "{\"2.2.23. Cấu hình vô hiệu hoá snmp services\" : \"PASSED\"}"
fi
# Log
if [ $(rpm -qa net-snmp | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa net-snmp -eq 0"; rpm -qa net-snmp
if [ $(systemctl is-enabled snmpd.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled snmpd.service 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled snmpd.service 2>/dev/null | grep 'enabled'
if [ $(systemctl is-active snmpd.service 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active snmpd.service 2>/dev/null | grep '^active' -eq 0"; systemctl is-active snmpd.service 2>/dev/null | grep '^active'
echo "----------LOG----------"
echo "#systemctl is-enabled snmpd.service"; systemctl is-enabled snmpd.service
echo "#systemctl is-active snmpd.service"; systemctl is-active snmpd.service
##################################################################################################################
echo -e "\n######################################"
if [[ $(rpm -qa ypserv | wc -l) -ne 0 && ($(systemctl is-enabled ypserv.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-active ypserv.service 2>/dev/null | grep '^active' | wc -l) -ne 0) ]]; then
echo "{\"2.2.24. Cấu hình vô hiệu hoá nis server services\" : \"FAILED\"}"
else
echo "{\"2.2.24. Cấu hình vô hiệu hoá nis server services\" : \"PASSED\"}"
fi
# Log
if [ $(rpm -qa ypserv | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa ypserv -eq 0"; rpm -qa ypserv
if [ $(systemctl is-enabled ypserv.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled ypserv.service 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled ypserv.service 2>/dev/null | grep 'enabled'
if [ $(systemctl is-active ypserv.service 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active ypserv.service 2>/dev/null | grep '^active' -eq 0"; systemctl is-active ypserv.service 2>/dev/null | grep '^active'
echo "----------LOG----------"
echo "#systemctl is-enabled ypserv.service"; systemctl is-enabled ypserv.service
echo "#systemctl is-active ypserv.service"; systemctl is-active ypserv.service
##################################################################################################################
echo -e "\n######################################"
if [[ $(rpm -qa telnet-server | wc -l) -ne 0 && ($(systemctl is-enabled telnet.socket 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-active telnet.socket 2>/dev/null | grep '^active' | wc -l) -ne 0) ]]; then
echo "{\"2.2.25. Cấu hình vô hiệu hoá telnet server services\" : \"FAILED\"}"
else
echo "{\"2.2.25. Cấu hình vô hiệu hoá telnet server services\" : \"PASSED\"}"
fi
# Log
if [ $(rpm -qa telnet-server | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa telnet-server -eq 0"; rpm -qa telnet-server
if [ $(systemctl is-enabled telnet.socket 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled telnet.socket 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled telnet.socket 2>/dev/null | grep 'enabled'
if [ $(systemctl is-active telnet.socket 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active telnet.socket 2>/dev/null | grep '^active' -eq 0"; systemctl is-active telnet.socket 2>/dev/null | grep '^active'
echo "----------LOG----------"
echo "#systemctl is-enabled telnet.socket"; systemctl is-enabled telnet.socket
echo "#systemctl is-active telnet.socket"; systemctl is-active telnet.socket
##################################################################################################################
echo -e "\n######################################"
if [[ $(ss -plntu | grep -P -- ':25\b' | grep -Pv -- '\h+(127\.0\.0\.1|\[?::1\]?):25\b' | wc -l) -ne 0 || $(ss -plntu | grep -P -- ':465\b' | grep -Pv -- '\h+(127\.0\.0\.1|\[?::1\]?):465\b' | wc -l) -ne 0 || $(ss -plntu | grep -P -- ':587\b' | grep -Pv -- '\h+(127\.0\.0\.1|\[?::1\]?):587\b' | wc -l) -ne 0 || $(grep "inet_interfaces.*=.*loopback-only" /etc/postfix/main.cf 2>/dev/null | wc -l) -eq 0 ]]; then
echo "{\"2.2.26. Cấu hình mail transfer agents sang chế độ local-only\" : \"FAILED\"}"
else
echo "{\"2.2.26. Cấu hình mail transfer agents sang chế độ local-only\" : \"PASSED\"}"
fi
# Log
if [ $(ss -plntu | grep -P -- ':25\b' | grep -Pv -- '\h+(127\.0\.0\.1|\[?::1\]?):25\b' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#ss -plntu | grep -P -- ':25\\b' | grep -Pv -- '\\h+(127\\.0\\.0\\.1|\\[?::1\\]?):25\\b' -eq 0"; ss -plntu | grep -P -- ':25\b' | grep -Pv -- '\h+(127\.0\.0\.1|\[?::1\]?):25\b'
if [ $(ss -plntu | grep -P -- ':465\b' | grep -Pv -- '\h+(127\.0\.0\.1|\[?::1\]?):465\b' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#ss -plntu | grep -P -- ':465\\b' | grep -Pv -- '\\h+(127\\.0\\.0\\.1|\\[?::1\\]?):465\\b' -eq 0"; ss -plntu | grep -P -- ':465\b' | grep -Pv -- '\h+(127\.0\.0\.1|\[?::1\]?):465\b'
if [ $(ss -plntu | grep -P -- ':587\b' | grep -Pv -- '\h+(127\.0\.0\.1|\[?::1\]?):587\b' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#ss -plntu | grep -P -- ':587\\b' | grep -Pv -- '\\h+(127\\.0\\.0\\.1|\\[?::1\\]?):587\\b' -eq 0"; ss -plntu | grep -P -- ':587\b' | grep -Pv -- '\h+(127\.0\.0\.1|\[?::1\]?):587\b'
if [ $(grep "inet_interfaces.*=.*loopback-only" /etc/postfix/main.cf 2>/dev/null | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep \"inet_interfaces.*=.*loopback-only\" /etc/postfix/main.cf 2>/dev/null -ne 0"; grep "inet_interfaces.*=.*loopback-only" /etc/postfix/main.cf 2>/dev/null
echo "----------LOG----------"
echo "#grep \"inet_interfaces\" /etc/postfix/main.cf"; grep "inet_interfaces" /etc/postfix/main.cf
##################################################################################################################
echo -e "\n######################################"
if [[ $(rpm -qa nfs-utils | wc -l) -ne 0 && ($(systemctl is-enabled nfs-server.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-active nfs-server.service 2>/dev/null | grep '^active' | wc -l) -ne 0) ]]; then
echo "{\"2.2.27. Cấu hình vô hiệu hoá network file system services\" : \"FAILED\"}"
else
echo "{\"2.2.27. Cấu hình vô hiệu hoá network file system services\" : \"PASSED\"}"
fi
# Log
if [ $(rpm -qa nfs-utils | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa nfs-utils -eq 0"; rpm -qa nfs-utils
if [ $(systemctl is-enabled nfs-server.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled nfs-server.service 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled nfs-server.service 2>/dev/null | grep 'enabled'
if [ $(systemctl is-active nfs-server.service 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active nfs-server.service 2>/dev/null | grep '^active' -eq 0"; systemctl is-active nfs-server.service 2>/dev/null | grep '^active'
echo "----------LOG----------"
echo "#systemctl is-enabled nfs-server.service"; systemctl is-enabled nfs-server.service
echo "#systemctl is-active nfs-server.service"; systemctl is-active nfs-server.service
##################################################################################################################
echo -e "\n######################################"
if [[ $(rpm -qa rpcbind | wc -l) -ne 0 && ($(systemctl is-enabled rpcbind.socket 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-enabled rpcbind.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-active rpcbind.socket 2>/dev/null | grep '^active' | wc -l) -ne 0 || $(systemctl is-active rpcbind.service 2>/dev/null | grep '^active' | wc -l) -ne 0) ]]; then
echo "{\"2.2.28. Cấu hình vô hiệu hoá rpcbind services\" : \"FAILED\"}"
else
echo "{\"2.2.28. Cấu hình vô hiệu hoá rpcbind services\" : \"PASSED\"}"
fi
# Log
if [ $(rpm -qa rpcbind | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa rpcbind -eq 0"; rpm -qa rpcbind
if [ $(systemctl is-enabled rpcbind.socket 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled rpcbind.socket 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled rpcbind.socket 2>/dev/null | grep 'enabled'
if [ $(systemctl is-enabled rpcbind.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled rpcbind.service 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled rpcbind.service 2>/dev/null | grep 'enabled'
if [ $(systemctl is-active rpcbind.socket 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active rpcbind.socket 2>/dev/null | grep '^active' -eq 0"; systemctl is-active rpcbind.socket 2>/dev/null | grep '^active'
if [ $(systemctl is-active rpcbind.service 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active rpcbind.service 2>/dev/null | grep '^active' -eq 0"; systemctl is-active rpcbind.service 2>/dev/null | grep '^active'
echo "----------LOG----------"
echo "#systemctl is-enabled rpcbind.socket"; systemctl is-enabled rpcbind.socket
echo "#systemctl is-enabled rpcbind.service"; systemctl is-enabled rpcbind.service
echo "#systemctl is-active rpcbind.socket"; systemctl is-active rpcbind.socket
echo "#systemctl is-active rpcbind.service"; systemctl is-active rpcbind.service
##################################################################################################################
echo -e "\n######################################"
if [[ $(rpm -qa rsync-daemon | wc -l) -ne 0 && ($(systemctl is-enabled rsyncd.socket 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-enabled rsyncd.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 || $(systemctl is-active rsyncd.socket 2>/dev/null | grep '^active' | wc -l) -ne 0 || $(systemctl is-active rsyncd.service 2>/dev/null | grep '^active' | wc -l) -ne 0) ]]; then
echo "{\"2.2.29. Cấu hình vô hiệu hoá rsync services\" : \"FAILED\"}"
else
echo "{\"2.2.29. Cấu hình vô hiệu hoá rsync services\" : \"PASSED\"}"
fi
# Log
if [ $(rpm -qa rsync-daemon | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa rsync-daemon -eq 0"; rpm -qa rsync-daemon
if [ $(systemctl is-enabled rsyncd.socket 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled rsyncd.socket 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled rsyncd.socket 2>/dev/null | grep 'enabled'
if [ $(systemctl is-enabled rsyncd.service 2>/dev/null | grep 'enabled' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-enabled rsyncd.service 2>/dev/null | grep 'enabled' -eq 0"; systemctl is-enabled rsyncd.service 2>/dev/null | grep 'enabled'
if [ $(systemctl is-active rsyncd.socket 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active rsyncd.socket 2>/dev/null | grep '^active' -eq 0"; systemctl is-active rsyncd.socket 2>/dev/null | grep '^active'
if [ $(systemctl is-active rsyncd.service 2>/dev/null | grep '^active' | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#systemctl is-active rsyncd.service 2>/dev/null | grep '^active' -eq 0"; systemctl is-active rsyncd.service 2>/dev/null | grep '^active'
echo "----------LOG----------"
echo "#systemctl is-enabled rsyncd.socket"; systemctl is-enabled rsyncd.socket
echo "#systemctl is-enabled rsyncd.service"; systemctl is-enabled rsyncd.service
echo "#systemctl is-active rsyncd.socket"; systemctl is-active rsyncd.socket
echo "#systemctl is-active rsyncd.service"; systemctl is-active rsyncd.service
############################################################################
# Thực hiện các câu lệnh sau để gỡ bỏ NIS Client, rsh client, talk client, telnet client, LDAP client, TFTP Client:
# # NIS Client
# yum remove ypbind
# # rsh client
# yum remove rsh
# # talk client
# yum remove talk
# # telnet client
# yum remove telnet
# # LDAP client
# yum remove openldap-clients
# # TFTP Client
# yum remove tftp
######################################
if [ $(rpm -qa ypbind | wc -l) -ne 0 ]; then
echo "{\"2.3.1. Cấu hình vô hiệu hoá NIS Client\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để gỡ bỏ NIS Client:
# yum remove ypbind"
if [ $(rpm -qa ypbind | wc -l) -ne 0 ]; then echo "-------------------"; echo "#rpm -qa ypbind -eq 0 ";rpm -qa ypbind; fi
echo "######################################"
else
echo "{\"2.3.1. Cấu hình vô hiệu hoá NIS Client\" : \"PASSED\"}"
fi
######################################
if [ $(rpm -qa rsh | wc -l) -ne 0 ]; then
echo "{\"2.3.2. Cấu hình vô hiệu hoá rsh client\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để gỡ bỏ rsh client:
# yum remove rsh"
if [ $(rpm -qa rsh | wc -l) -ne 0 ]; then echo "-------------------"; echo "#rpm -qa rsh -eq 0 ";rpm -qa rsh; fi
echo "######################################"
else
echo "{\"2.3.2. Cấu hình vô hiệu hoá rsh client\" : \"PASSED\"}"
fi
######################################
if [ $(rpm -qa talk | wc -l) -ne 0 ]; then
echo "{\"2.3.3. Cấu hình vô hiệu hoá talk client\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để gỡ bỏ talk client:
# yum remove talk"
if [ $(rpm -qa talk | wc -l) -ne 0 ]; then echo "-------------------"; echo "#rpm -qa talk -eq 0 ";rpm -qa talk; fi
echo "######################################"
else
echo "{\"2.3.3. Cấu hình vô hiệu hoá talk client\" : \"PASSED\"}"
fi
######################################
if [ $(rpm -qa telnet | wc -l) -ne 0 ]; then
echo "{\"2.3.4. Cấu hình vô hiệu hoá telnet client\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để gỡ bỏ telnet client:
# yum remove telnet"
if [ $(rpm -qa telnet | wc -l) -ne 0 ]; then echo "-------------------"; echo "#rpm -qa telnet -eq 0 ";rpm -qa telnet; fi
echo "######################################"
else
echo "{\"2.3.4. Cấu hình vô hiệu hoá telnet client\" : \"PASSED\"}"
fi
######################################
if [ $(rpm -qa openldap-clients | wc -l) -ne 0 ]; then
echo "{\"2.3.5. Cấu hình vô hiệu hoá LDAP client\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để gỡ bỏ LDAP client:
# yum remove openldap-clients"
if [ $(rpm -qa openldap-clients | wc -l) -ne 0 ]; then echo "-------------------"; echo "#rpm -qa openldap-clients -eq 0 ";rpm -qa openldap-clients; fi
echo "######################################"
else
echo "{\"2.3.5. Cấu hình vô hiệu hoá LDAP client\" : \"PASSED\"}"
fi
##################################################################################################################
echo -e "\n######################################"
if [[ $(grep -E "\s[7-9].[0-9]" /etc/system-release | wc -l) -ne 0 && $(rpm -qa ftp | wc -l) -ne 0 ]]; then
echo "{\"2.3.6. Cấu hình vô hiệu hoá ftp client\" : \"FAILED\"}"
else
echo "{\"2.3.6. Cấu hình vô hiệu hoá ftp client\" : \"PASSED\"}"
fi
# Log
if [ $(grep -E "\s[7-9].[0-9]" /etc/system-release | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -E \"\\s[7-9].[0-9]\" /etc/system-release -eq 0"; grep -E "\s[7-9].[0-9]" /etc/system-release
if [ $(rpm -qa ftp | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa ftp -eq 0"; rpm -qa ftp
echo "----------LOG----------"
##################################################################################################################
echo -e "\n######################################"
if [[ $(grep -E "\s[7-9].[0-9]" /etc/system-release | wc -l) -ne 0 && $(rpm -qa tftp | wc -l) -ne 0 ]]; then
echo "{\"2.3.7. Cấu hình vô hiệu hoá tftp client\" : \"FAILED\"}"
else
echo "{\"2.3.7. Cấu hình vô hiệu hoá tftp client\" : \"PASSED\"}"
fi
# Log
if [ $(grep -E "\s[7-9].[0-9]" /etc/system-release | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -E \"\\s[7-9].[0-9]\" /etc/system-release -eq 0"; grep -E "\s[7-9].[0-9]" /etc/system-release
if [ $(rpm -qa tftp | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#rpm -qa tftp -eq 0"; rpm -qa tftp
echo "----------LOG----------"
##################################################################################################################
# IPv6
output=""; grubfile=$(find /boot -type f \( -name 'grubenv' -o -name 'grub.conf' -o -name 'grub.cfg' \) -exec grep -Pl -- '^\h*(kernelopts=|linux|kernel)' {} \;); searchloc="/run/sysctl.d/*.conf /etc/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /lib/sysctl.d/*.conf /etc/sysctl.conf"; if [ -s "$grubfile" ]; then ! grep -P -- "^\h*(kernelopts=|linux|kernel)" "$grubfile" | grep -vq -- ipv6.disable=1 && output="disabled"; fi; if grep -Pqs -- "^\h*net\.ipv6\.conf\.all\.disable_ipv6\h*=\h*1\h*(#.*)?$" $searchloc && \ grep -Pqs -- "^\h*net\.ipv6\.conf\.default\.disable_ipv6\h*=\h*1\h*(#.*)?$" $searchloc && \ sysctl net.ipv6.conf.all.disable_ipv6 | grep -Pqs -- "^\h*net\.ipv6\.conf\.all\.disable_ipv6\h*=\h*1\h*(#.*)?$" && \ sysctl net.ipv6.conf.default.disable_ipv6 | grep -Pqs -- "^\h*net\.ipv6\.conf\.default\.disable_ipv6\h*=\h*1\h*(#.*)?$"; then [ -n "$output" ] || output="disabled"; fi; [ -n "$output" ] || output="enabled";
echo -e "\n######################################"
# Check IPv4 forwarding (luôn check)
ipv4_forward_fail=0
if [[ $(sysctl net.ipv4.ip_forward 2>/dev/null | grep "0" | wc -l) -eq 0 \
|| $(grep -Ps "^\h*net\.ipv4\.ip_forward\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -eq 0 \
|| $(grep -Ps "^\h*net\.ipv4\.ip_forward\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -ne 0 ]]; then
ipv4_forward_fail=1
fi
# Check IPv6 forwarding (chỉ khi IPv6 enabled)
ipv6_forward_fail=0
if [ $IPV6_ENABLED -eq 1 ]; then
if [[ $(sysctl net.ipv6.conf.all.forwarding 2>/dev/null | grep "0" | wc -l) -eq 0 \
|| $(grep -Ps "^\h*net\.ipv6\.conf\.all\.forwarding\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -eq 0 \
|| $(grep -Ps "^\h*net\.ipv6\.conf\.all\.forwarding\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -ne 0 ]]; then
ipv6_forward_fail=1
fi
fi
# Kết luận: FAIL nếu IPv4 fail HOẶC (IPv6 enabled VÀ IPv6 fail)
if [ $ipv4_forward_fail -eq 1 ] || [ $ipv6_forward_fail -eq 1 ]; then
echo "{\"3.1.1. Cấu hình vô hiệu hoá IP forwarding\" : \"FAILED\"}"
else
echo "{\"3.1.1. Cấu hình vô hiệu hoá IP forwarding\" : \"PASSED\"}"
fi
# Log
if [ $(sysctl net.ipv4.ip_forward 2>/dev/null | grep "0" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#sysctl net.ipv4.ip_forward 2>/dev/null | grep \"0\" -ne 0"; sysctl net.ipv4.ip_forward 2>/dev/null | grep "0"
if [ $(grep -Ps "^\h*net\.ipv4\.ip_forward\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.ip_forward\\s*=\\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null -ne 0"; grep -Ps "^\h*net\.ipv4\.ip_forward\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null
if [ $(grep -Ps "^\h*net\.ipv4\.ip_forward\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.ip_forward\\s*=\\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null -eq 0"; grep -Ps "^\h*net\.ipv4\.ip_forward\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#echo \$output | grep \"enabled\" -eq 0"; echo $output | grep "enabled"
if [ $(sysctl net.ipv6.conf.all.forwarding 2>/dev/null | grep "0" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#sysctl net.ipv6.conf.all.forwarding 2>/dev/null | grep \"0\" -ne 0"; sysctl net.ipv6.conf.all.forwarding 2>/dev/null | grep "0"
if [ $(grep -Ps "^\h*net\.ipv6\.conf\.all\.forwarding\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv6\\.conf\\.all\\.forwarding\\s*=\\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null -ne 0"; grep -Ps "^\h*net\.ipv6\.conf\.all\.forwarding\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null
if [ $(grep -Ps "^\h*net\.ipv6\.conf\.all\.forwarding\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv6\\.conf\\.all\\.forwarding\\s*=\\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null -eq 0"; grep -Ps "^\h*net\.ipv6\.conf\.all\.forwarding\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null
echo "----------LOG----------"
echo "#sysctl net.ipv4.ip_forward"; sysctl net.ipv4.ip_forward
echo "#grep -Ps \"^\\h*net\\.ipv4\\.ip_forward\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf"; grep -Ps "^\h*net\.ipv4\.ip_forward" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
echo "#grep -Ps \"^\\h*net\\.ipv4\\.ip_forward\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf"; grep -Ps "^\h*net\.ipv4\.ip_forward" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
echo "#echo \"IPV6: \$output\""; echo "IPV6: $output"
echo "#sysctl net.ipv6.conf.all.forwarding"; sysctl net.ipv6.conf.all.forwarding
echo "#grep -Ps \"^\\h*net\\.ipv6\\.conf\\.all\\.forwarding\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf"; grep -Ps "^\h*net\.ipv6\.conf\.all\.forwarding" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
echo "#grep -Ps \"^\\h*net\\.ipv6\\.conf\\.all\\.forwarding\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf"; grep -Ps "^\h*net\.ipv6\.conf\.all\.forwarding" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
##################################################################################################################
echo -e "\n######################################"
if [[ $(sysctl net.ipv4.conf.all.send_redirects | grep "0" | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv4\.conf\.all\.send_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv4\.conf\.all\.send_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 || $(sysctl net.ipv4.conf.default.send_redirects | grep "0" | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv4\.conf\.default\.send_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv4\.conf\.default\.send_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]]; then
echo "{\"3.1.2. Cấu hình vô hiệu hoá tính năng chuyển hướng gói tin (packet redirect)\" : \"FAILED\"}"
else
echo "{\"3.1.2. Cấu hình vô hiệu hoá tính năng chuyển hướng gói tin (packet redirect)\" : \"PASSED\"}"
fi
# Log
if [ $(sysctl net.ipv4.conf.all.send_redirects | grep "0" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#sysctl net.ipv4.conf.all.send_redirects | grep \"0\" -ne 0"; sysctl net.ipv4.conf.all.send_redirects | grep "0"
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.send_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.all\\.send_redirects\\s*=\\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0"; grep -Ps "^\h*net\.ipv4\.conf\.all\.send_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.send_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.all\\.send_redirects\\s*=\\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0"; grep -Ps "^\h*net\.ipv4\.conf\.all\.send_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(sysctl net.ipv4.conf.default.send_redirects | grep "0" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#sysctl net.ipv4.conf.default.send_redirects | grep \"0\" -ne 0"; sysctl net.ipv4.conf.default.send_redirects | grep "0"
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.send_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.default\\.send_redirects\\s*=\\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0"; grep -Ps "^\h*net\.ipv4\.conf\.default\.send_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.send_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.default\\.send_redirects\\s*=\\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0"; grep -Ps "^\h*net\.ipv4\.conf\.default\.send_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
echo "----------LOG----------"
echo "#sysctl net.ipv4.conf.all.send_redirects"; sysctl net.ipv4.conf.all.send_redirects
echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.all\\.send_redirects\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf"; grep -Ps "^\h*net\.ipv4\.conf\.all\.send_redirects" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
echo "#sysctl net.ipv4.conf.default.send_redirects"; sysctl net.ipv4.conf.default.send_redirects
echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.default\\.send_redirects\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf"; grep -Ps "^\h*net\.ipv4\.conf\.default\.send_redirects" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
# Log
######################################
# IPv6
##################################################################################################################
output=""; grubfile=$(find /boot -type f \( -name 'grubenv' -o -name 'grub.conf' -o -name 'grub.cfg' \) -exec grep -Pl -- '^\h*(kernelopts=|linux|kernel)' {} \;); searchloc="/run/sysctl.d/*.conf /etc/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /lib/sysctl.d/*.conf /etc/sysctl.conf"; if [ -s "$grubfile" ]; then ! grep -P -- "^\h*(kernelopts=|linux|kernel)" "$grubfile" | grep -vq -- ipv6.disable=1 && output="disabled"; fi; if grep -Pqs -- "^\h*net\.ipv6\.conf\.all\.disable_ipv6\h*=\h*1\h*(#.*)?$" $searchloc && \ grep -Pqs -- "^\h*net\.ipv6\.conf\.default\.disable_ipv6\h*=\h*1\h*(#.*)?$" $searchloc && \ sysctl net.ipv6.conf.all.disable_ipv6 | grep -Pqs -- "^\h*net\.ipv6\.conf\.all\.disable_ipv6\h*=\h*1\h*(#.*)?$" && \ sysctl net.ipv6.conf.default.disable_ipv6 | grep -Pqs -- "^\h*net\.ipv6\.conf\.default\.disable_ipv6\h*=\h*1\h*(#.*)?$"; then [ -n "$output" ] || output="disabled"; fi; [ -n "$output" ] || output="enabled";
echo -e "\n######################################"
# Check IPv4 accept_source_route (luôn check)
ipv4_source_route_fail=0
if [[ $(sysctl net.ipv4.conf.all.accept_source_route 2>/dev/null | grep "0" | wc -l) -eq 0 \
|| $(grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -eq 0 \
|| $(grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -ne 0 \
|| $(sysctl net.ipv4.conf.default.accept_source_route 2>/dev/null | grep "0" | wc -l) -eq 0 \
|| $(grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -eq 0 \
|| $(grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -ne 0 ]]; then
ipv4_source_route_fail=1
fi
# Check IPv6 accept_source_route (chỉ khi IPv6 enabled)
ipv6_source_route_fail=0
if [ $IPV6_ENABLED -eq 1 ]; then
if [[ $(sysctl net.ipv6.conf.all.accept_source_route 2>/dev/null | grep "0" | wc -l) -eq 0 \
|| $(grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -eq 0 \
|| $(grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -ne 0 \
|| $(sysctl net.ipv6.conf.default.accept_source_route 2>/dev/null | grep "0" | wc -l) -eq 0 \
|| $(grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -eq 0 \
|| $(grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -ne 0 ]]; then
ipv6_source_route_fail=1
fi
fi
# Kết luận
if [ $ipv4_source_route_fail -eq 1 ] || [ $ipv6_source_route_fail -eq 1 ]; then
echo "{\"3.2.1. Cấu hình từ chối các gói tin với nguồn được định tuyến trước\" : \"FAILED\"}"
else
echo "{\"3.2.1. Cấu hình từ chối các gói tin với nguồn được định tuyến trước\" : \"PASSED\"}"
fi
# Log
if [ $(sysctl net.ipv4.conf.all.accept_source_route | grep "0" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#sysctl net.ipv4.conf.all.accept_source_route | grep \"0\" -ne 0"; sysctl net.ipv4.conf.all.accept_source_route | grep "0"
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.all\\.accept_source_route\\s*=\\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0"; grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.all\\.accept_source_route\\s*=\\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0"; grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(sysctl net.ipv4.conf.default.accept_source_route | grep "0" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#sysctl net.ipv4.conf.default.accept_source_route | grep \"0\" -ne 0"; sysctl net.ipv4.conf.default.accept_source_route | grep "0"
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.default\\.accept_source_route\\s*=\\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0"; grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.default\\.accept_source_route\\s*=\\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0"; grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#echo \$output | grep \"enabled\" -eq 0"; echo $output | grep "enabled"
if [ $(sysctl net.ipv6.conf.all.accept_source_route | grep "0" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#sysctl net.ipv6.conf.all.accept_source_route | grep \"0\" -ne 0"; sysctl net.ipv6.conf.all.accept_source_route | grep "0"
if [ $(grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv6\\.conf\\.all\\.accept_source_route\\s*=\\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0"; grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv6\\.conf\\.all\\.accept_source_route\\s*=\\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0"; grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(sysctl net.ipv6.conf.default.accept_source_route | grep "0" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#sysctl net.ipv6.conf.default.accept_source_route | grep \"0\" -ne 0"; sysctl net.ipv6.conf.default.accept_source_route | grep "0"
if [ $(grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv6\\.conf\\.default\\.accept_source_route\\s*=\\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0"; grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv6\\.conf\\.default\\.accept_source_route\\s*=\\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0"; grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
echo "----------LOG----------"
echo "#sysctl net.ipv4.conf.all.accept_source_route"; sysctl net.ipv4.conf.all.accept_source_route
echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.all\\.accept_source_route\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf"; grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_source_route" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
echo "#sysctl net.ipv4.conf.default.accept_source_route"; sysctl net.ipv4.conf.default.accept_source_route
echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.default\\.accept_source_route\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf"; grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_source_route" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
echo "#echo \"IPV6: \$output\""; echo "IPV6: $output"
echo "#sysctl net.ipv6.conf.all.accept_source_route"; sysctl net.ipv6.conf.all.accept_source_route
echo "#grep -Ps \"^\\h*net\\.ipv6\\.conf\\.all\\.accept_source_route\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf"; grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_source_route" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
echo "#sysctl net.ipv6.conf.default.accept_source_route"; sysctl net.ipv6.conf.default.accept_source_route
echo "#grep -Ps \"^\\h*net\\.ipv6\\.conf\\.default\\.accept_source_route\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf"; grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_source_route" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
##################################################################################################################
# IPv6
output=""; grubfile=$(find /boot -type f \( -name 'grubenv' -o -name 'grub.conf' -o -name 'grub.cfg' \) -exec grep -Pl -- '^\h*(kernelopts=|linux|kernel)' {} \;); searchloc="/run/sysctl.d/*.conf /etc/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /lib/sysctl.d/*.conf /etc/sysctl.conf"; if [ -s "$grubfile" ]; then ! grep -P -- "^\h*(kernelopts=|linux|kernel)" "$grubfile" | grep -vq -- ipv6.disable=1 && output="disabled"; fi; if grep -Pqs -- "^\h*net\.ipv6\.conf\.all\.disable_ipv6\h*=\h*1\h*(#.*)?$" $searchloc && \ grep -Pqs -- "^\h*net\.ipv6\.conf\.default\.disable_ipv6\h*=\h*1\h*(#.*)?$" $searchloc && \ sysctl net.ipv6.conf.all.disable_ipv6 | grep -Pqs -- "^\h*net\.ipv6\.conf\.all\.disable_ipv6\h*=\h*1\h*(#.*)?$" && \ sysctl net.ipv6.conf.default.disable_ipv6 | grep -Pqs -- "^\h*net\.ipv6\.conf\.default\.disable_ipv6\h*=\h*1\h*(#.*)?$"; then [ -n "$output" ] || output="disabled"; fi; [ -n "$output" ] || output="enabled";
echo -e "\n######################################"
# Check IPv4 accept_redirects (luôn check)
ipv4_redirects_fail=0
if [[ $(sysctl net.ipv4.conf.all.accept_redirects 2>/dev/null | grep "0" | wc -l) -eq 0 \
|| $(grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -eq 0 \
|| $(grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -ne 0 \
|| $(sysctl net.ipv4.conf.default.accept_redirects 2>/dev/null | grep "0" | wc -l) -eq 0 \
|| $(grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -eq 0 \
|| $(grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -ne 0 ]]; then
ipv4_redirects_fail=1
fi
# Check IPv6 accept_redirects (chỉ khi IPv6 enabled)
ipv6_redirects_fail=0
if [ $IPV6_ENABLED -eq 1 ]; then
if [[ $(sysctl net.ipv6.conf.all.accept_redirects 2>/dev/null | grep "0" | wc -l) -eq 0 \
|| $(grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -eq 0 \
|| $(grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -ne 0 \
|| $(sysctl net.ipv6.conf.default.accept_redirects 2>/dev/null | grep "0" | wc -l) -eq 0 \
|| $(grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -eq 0 \
|| $(grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf 2>/dev/null | wc -l) -ne 0 ]]; then
ipv6_redirects_fail=1
fi
fi
# Kết luận
if [ $ipv4_redirects_fail -eq 1 ] || [ $ipv6_redirects_fail -eq 1 ]; then
echo "{\"3.2.2. Cấu hình từ chối các ICMP redirect message\" : \"FAILED\"}"
else
echo "{\"3.2.2. Cấu hình từ chối các ICMP redirect message\" : \"PASSED\"}"
fi
# Log
if [ $(sysctl net.ipv4.conf.all.accept_redirects | grep "0" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#sysctl net.ipv4.conf.all.accept_redirects | grep \"0\" -ne 0"; sysctl net.ipv4.conf.all.accept_redirects | grep "0"
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.all\\.accept_redirects\\s*=\\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0"; grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.all\\.accept_redirects\\s*=\\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0"; grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(sysctl net.ipv4.conf.default.accept_redirects | grep "0" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#sysctl net.ipv4.conf.default.accept_redirects | grep \"0\" -ne 0"; sysctl net.ipv4.conf.default.accept_redirects | grep "0"
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.default\\.accept_redirects\\s*=\\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0"; grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.default\\.accept_redirects\\s*=\\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0"; grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#echo \$output | grep \"enabled\" -eq 0"; echo $output | grep "enabled"
if [ $(sysctl net.ipv6.conf.all.accept_redirects | grep "0" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#sysctl net.ipv6.conf.all.accept_redirects | grep \"0\" -ne 0"; sysctl net.ipv6.conf.all.accept_redirects | grep "0"
if [ $(grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv6\\.conf\\.all\\.accept_redirects\\s*=\\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0"; grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv6\\.conf\\.all\\.accept_redirects\\s*=\\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0"; grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(sysctl net.ipv6.conf.default.accept_redirects | grep "0" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#sysctl net.ipv6.conf.default.accept_redirects | grep \"0\" -ne 0"; sysctl net.ipv6.conf.default.accept_redirects | grep "0"
if [ $(grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv6\\.conf\\.default\\.accept_redirects\\s*=\\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0"; grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv6\\.conf\\.default\\.accept_redirects\\s*=\\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0"; grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
echo "----------LOG----------"
echo "#sysctl net.ipv4.conf.all.accept_redirects"; sysctl net.ipv4.conf.all.accept_redirects
echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.all\\.accept_redirects\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf"; grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_redirects" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
echo "#sysctl net.ipv4.conf.default.accept_redirects"; sysctl net.ipv4.conf.default.accept_redirects
echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.default\\.accept_redirects\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf"; grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_redirects" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
echo "#echo \"IPV6: \$output\""; echo "IPV6: $output"
echo "#sysctl net.ipv6.conf.all.accept_redirects"; sysctl net.ipv6.conf.all.accept_redirects
echo "#grep -Ps \"^\\h*net\\.ipv6\\.conf\\.all\\.accept_redirects\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf"; grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_redirects" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
echo "#sysctl net.ipv6.conf.default.accept_redirects"; sysctl net.ipv6.conf.default.accept_redirects
echo "#grep -Ps \"^\\h*net\\.ipv6\\.conf\\.default\\.accept_redirects\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf"; grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_redirects" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
##################################################################################################################
echo -e "\n######################################"
if [[ $(sysctl net.ipv4.conf.all.secure_redirects | grep "0" | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv4\.conf\.all\.secure_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv4\.conf\.all\.secure_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 || $(sysctl net.ipv4.conf.default.secure_redirects | grep "0" | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv4\.conf\.default\.secure_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv4\.conf\.default\.secure_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]]; then
echo "{\"3.2.3. Cấu hình từ chối các secure ICMP redirect message\" : \"FAILED\"}"
else
echo "{\"3.2.3. Cấu hình từ chối các secure ICMP redirect message\" : \"PASSED\"}"
fi
# Log
if [ $(sysctl net.ipv4.conf.all.secure_redirects | grep "0" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#sysctl net.ipv4.conf.all.secure_redirects | grep \"0\" -ne 0"; sysctl net.ipv4.conf.all.secure_redirects | grep "0"
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.secure_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.all\\.secure_redirects\\s*=\\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0"; grep -Ps "^\h*net\.ipv4\.conf\.all\.secure_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.secure_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.all\\.secure_redirects\\s*=\\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0"; grep -Ps "^\h*net\.ipv4\.conf\.all\.secure_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(sysctl net.ipv4.conf.default.secure_redirects | grep "0" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#sysctl net.ipv4.conf.default.secure_redirects | grep \"0\" -ne 0"; sysctl net.ipv4.conf.default.secure_redirects | grep "0"
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.secure_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.default\\.secure_redirects\\s*=\\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0"; grep -Ps "^\h*net\.ipv4\.conf\.default\.secure_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.secure_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.default\\.secure_redirects\\s*=\\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0"; grep -Ps "^\h*net\.ipv4\.conf\.default\.secure_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
echo "----------LOG----------"
echo "#sysctl net.ipv4.conf.all.secure_redirects"; sysctl net.ipv4.conf.all.secure_redirects
echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.all\\.secure_redirects\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf"; grep -Ps "^\h*net\.ipv4\.conf\.all\.secure_redirects" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
echo "#sysctl net.ipv4.conf.default.secure_redirects"; sysctl net.ipv4.conf.default.secure_redirects
echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.default\\.secure_redirects\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf"; grep -Ps "^\h*net\.ipv4\.conf\.default\.secure_redirects" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
##################################################################################################################
echo -e "\n######################################"
if [[ $(sysctl net.ipv4.icmp_echo_ignore_broadcasts | grep "1" | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv4\.icmp_echo_ignore_broadcasts\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv4\.icmp_echo_ignore_broadcasts\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]]; then
echo "{\"3.2.4. Cấu hình từ chối các gói tin ICMP request broadcast\" : \"FAILED\"}"
else
echo "{\"3.2.4. Cấu hình từ chối các gói tin ICMP request broadcast\" : \"PASSED\"}"
fi
# Log
if [ $(sysctl net.ipv4.icmp_echo_ignore_broadcasts | grep "1" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#sysctl net.ipv4.icmp_echo_ignore_broadcasts | grep \"1\" -ne 0"; sysctl net.ipv4.icmp_echo_ignore_broadcasts | grep "1"
if [ $(grep -Ps "^\h*net\.ipv4\.icmp_echo_ignore_broadcasts\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.icmp_echo_ignore_broadcasts\\s*=\\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0"; grep -Ps "^\h*net\.ipv4\.icmp_echo_ignore_broadcasts\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(grep -Ps "^\h*net\.ipv4\.icmp_echo_ignore_broadcasts\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.icmp_echo_ignore_broadcasts\\s*=\\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0"; grep -Ps "^\h*net\.ipv4\.icmp_echo_ignore_broadcasts\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
echo "----------LOG----------"
echo "#sysctl net.ipv4.icmp_echo_ignore_broadcasts"; sysctl net.ipv4.icmp_echo_ignore_broadcasts
echo "#grep -Ps \"^\\h*net\\.ipv4\\.icmp_echo_ignore_broadcasts\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf"; grep -Ps "^\h*net\.ipv4\.icmp_echo_ignore_broadcasts" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
##################################################################################################################
echo -e "\n######################################"
if [[ $(sysctl net.ipv4.icmp_ignore_bogus_error_responses | grep "1" | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv4\.icmp_ignore_bogus_error_responses\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv4\.icmp_ignore_bogus_error_responses\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]]; then
echo "{\"3.2.5. Cấu hình bỏ qua phản hồi ICMP không hợp lệ\" : \"FAILED\"}"
else
echo "{\"3.2.5. Cấu hình bỏ qua phản hồi ICMP không hợp lệ\" : \"PASSED\"}"
fi
# Log
if [ $(sysctl net.ipv4.icmp_ignore_bogus_error_responses | grep "1" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#sysctl net.ipv4.icmp_ignore_bogus_error_responses | grep \"1\" -ne 0"; sysctl net.ipv4.icmp_ignore_bogus_error_responses | grep "1"
if [ $(grep -Ps "^\h*net\.ipv4\.icmp_ignore_bogus_error_responses\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.icmp_ignore_bogus_error_responses\\s*=\\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0"; grep -Ps "^\h*net\.ipv4\.icmp_ignore_bogus_error_responses\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(grep -Ps "^\h*net\.ipv4\.icmp_ignore_bogus_error_responses\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.icmp_ignore_bogus_error_responses\\s*=\\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0"; grep -Ps "^\h*net\.ipv4\.icmp_ignore_bogus_error_responses\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
echo "----------LOG----------"
echo "#sysctl net.ipv4.icmp_ignore_bogus_error_responses"; sysctl net.ipv4.icmp_ignore_bogus_error_responses
echo "#grep -Ps \"^\\h*net\\.ipv4\\.icmp_ignore_bogus_error_responses\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf"; grep -Ps "^\h*net\.ipv4\.icmp_ignore_bogus_error_responses" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
##################################################################################################################
echo -e "\n######################################"
if [[ $(sysctl net.ipv4.conf.all.rp_filter | grep "1" | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv4\.conf\.all\.rp_filter\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv4\.conf\.all\.rp_filter\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 || $(sysctl net.ipv4.conf.default.rp_filter | grep "1" | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv4\.conf\.default\.rp_filter\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv4\.conf\.default\.rp_filter\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]]; then
echo "{\"3.2.6. Cấu hình Reverse Path Filtering\" : \"FAILED\"}"
else
echo "{\"3.2.6. Cấu hình Reverse Path Filtering\" : \"PASSED\"}"
fi
# Log
if [ $(sysctl net.ipv4.conf.all.rp_filter | grep "1" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#sysctl net.ipv4.conf.all.rp_filter | grep \"1\" -ne 0"; sysctl net.ipv4.conf.all.rp_filter | grep "1"
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.rp_filter\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.all\\.rp_filter\\s*=\\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0"; grep -Ps "^\h*net\.ipv4\.conf\.all\.rp_filter\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.rp_filter\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.all\\.rp_filter\\s*=\\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0"; grep -Ps "^\h*net\.ipv4\.conf\.all\.rp_filter\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(sysctl net.ipv4.conf.default.rp_filter | grep "1" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#sysctl net.ipv4.conf.default.rp_filter | grep \"1\" -ne 0"; sysctl net.ipv4.conf.default.rp_filter | grep "1"
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.rp_filter\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.default\\.rp_filter\\s*=\\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0"; grep -Ps "^\h*net\.ipv4\.conf\.default\.rp_filter\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.rp_filter\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.default\\.rp_filter\\s*=\\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0"; grep -Ps "^\h*net\.ipv4\.conf\.default\.rp_filter\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
echo "----------LOG----------"
echo "#sysctl net.ipv4.conf.all.rp_filter"; sysctl net.ipv4.conf.all.rp_filter
echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.all\\.rp_filter\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf"; grep -Ps "^\h*net\.ipv4\.conf\.all\.rp_filter" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
echo "#sysctl net.ipv4.conf.default.rp_filter"; sysctl net.ipv4.conf.default.rp_filter
echo "#grep -Ps \"^\\h*net\\.ipv4\\.conf\\.default\\.rp_filter\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf"; grep -Ps "^\h*net\.ipv4\.conf\.default\.rp_filter" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
##################################################################################################################
echo -e "\n######################################"
if [[ $(sysctl net.ipv4.tcp_syncookies | grep "1" | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv4\.tcp_syncookies\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv4\.tcp_syncookies\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]]; then
echo "{\"3.2.7. Cấu hình TCP SYN Cookies\" : \"FAILED\"}"
else
echo "{\"3.2.7. Cấu hình TCP SYN Cookies\" : \"PASSED\"}"
fi
# Log
if [ $(sysctl net.ipv4.tcp_syncookies | grep "1" | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#sysctl net.ipv4.tcp_syncookies | grep \"1\" -ne 0"; sysctl net.ipv4.tcp_syncookies | grep "1"
if [ $(grep -Ps "^\h*net\.ipv4\.tcp_syncookies\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.tcp_syncookies\\s*=\\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0"; grep -Ps "^\h*net\.ipv4\.tcp_syncookies\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
if [ $(grep -Ps "^\h*net\.ipv4\.tcp_syncookies\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -Ps \"^\\h*net\\.ipv4\\.tcp_syncookies\\s*=\\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0"; grep -Ps "^\h*net\.ipv4\.tcp_syncookies\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
echo "----------LOG----------"
echo "#sysctl net.ipv4.tcp_syncookies"; sysctl net.ipv4.tcp_syncookies
echo "#grep -Ps \"^\\h*net\\.ipv4\\.tcp_syncookies\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf"; grep -Ps "^\h*net\.ipv4\.tcp_syncookies" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
############################################################################
# Đặt các thông số sau vào file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf:
# net.ipv4.conf.all.accept_source_route = 0
# net.ipv4.conf.default.accept_source_route = 0
# Thực hiện các câu lệnh sau để đặt các tham số vào kernel đang hoạt động:
# sysctl -w net.ipv4.conf.all.accept_source_route=0
# sysctl -w net.ipv4.conf.default.accept_source_route=0
# Nếu sử dụng Ipv6:
# Đặt các thông số sau vào file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf:
# net.ipv6.conf.all.accept_source_route = 0
# net.ipv6.conf.default.accept_source_route = 0
# Thực hiện các câu lệnh sau để đặt các tham số vào kernel đang hoạt động:
# sysctl -w net.ipv6.conf.all.accept_source_route=0
# sysctl -w net.ipv6.conf.default.accept_source_route=0
if [[ $(sysctl net.ipv4.conf.all.accept_source_route | grep "0" | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 || $(sysctl net.ipv4.conf.default.accept_source_route | grep "0" | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 || ($(echo $output | grep "enabled" | wc -l) -ne 0 && ($(sysctl net.ipv6.conf.all.accept_source_route | grep "0" | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 || $(sysctl net.ipv6.conf.default.accept_source_route | grep "0" | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0)) ]]; then
echo "{\"3.3.1. Cấu hình từ chối các gói tin với nguồn được định tuyến trước (Source Routed Packet Acceptance)\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Đặt các thông số sau vào file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf:
# net.ipv4.conf.all.accept_source_route = 0
# net.ipv4.conf.default.accept_source_route = 0
# Thực hiện các câu lệnh sau để đặt các tham số vào kernel đang hoạt động:
# sysctl -w net.ipv4.conf.all.accept_source_route=0
# sysctl -w net.ipv4.conf.default.accept_source_route=0
# Nếu sử dụng Ipv6:
# Đặt các thông số sau vào file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf:
# net.ipv6.conf.all.accept_source_route = 0
# net.ipv6.conf.default.accept_source_route = 0
# Thực hiện các câu lệnh sau để đặt các tham số vào kernel đang hoạt động:
# sysctl -w net.ipv6.conf.all.accept_source_route=0
# sysctl -w net.ipv6.conf.default.accept_source_route=0"
if [ $(sysctl net.ipv4.conf.all.accept_source_route | grep "0" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sysctl net.ipv4.conf.all.accept_source_route | grep \"0\" -ne 0 ";sysctl net.ipv4.conf.all.accept_source_route | grep "0"; fi
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv4\.conf\.all\.accept_source_route\s*=\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0 ";grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv4\.conf\.all\.accept_source_route\s*=\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0 ";grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(sysctl net.ipv4.conf.default.accept_source_route | grep "0" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sysctl net.ipv4.conf.default.accept_source_route | grep \"0\" -ne 0 ";sysctl net.ipv4.conf.default.accept_source_route | grep "0"; fi
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv4\.conf\.default\.accept_source_route\s*=\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0 ";grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv4\.conf\.default\.accept_source_route\s*=\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0 ";grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ] && [ $(sysctl net.ipv6.conf.all.accept_source_route | grep "0" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sysctl net.ipv6.conf.all.accept_source_route | grep \"0\" -ne 0 ";sysctl net.ipv6.conf.all.accept_source_route | grep "0"; fi
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ] && [ $(grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv6\.conf\.all\.accept_source_route\s*=\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0 ";grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ] && [ $(grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv6\.conf\.all\.accept_source_route\s*=\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0 ";grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ] && [ $(sysctl net.ipv6.conf.default.accept_source_route | grep "0" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sysctl net.ipv6.conf.default.accept_source_route | grep \"0\" -ne 0 ";sysctl net.ipv6.conf.default.accept_source_route | grep "0"; fi
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ] && [ $(grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv6\.conf\.default\.accept_source_route\s*=\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0 ";grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_source_route\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ] && [ $(grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv6\.conf\.default\.accept_source_route\s*=\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0 ";grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_source_route\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
echo "######################################"
else
echo "{\"3.3.1. Cấu hình từ chối các gói tin với nguồn được định tuyến trước (Source Routed Packet Acceptance)\" : \"PASSED\"}"
fi
############################################################################
# Đặt các tham số sau và file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf:
# net.ipv4.conf.all.accept_redirects = 0
# net.ipv4.conf.default.accept_redirects = 0
# Thực hiện các câu lệnh sau để đặt các tham số vào kernel đang hoạt động:
# sysctl -w net.ipv4.conf.all.accept_redirects=0
# sysctl -w net.ipv4.conf.default.accept_redirects=0
# Nếu sử dụng Ipv6:
# Đặt các tham số sau và file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf:
# net.ipv6.conf.all.accept_redirects = 0
# net.ipv6.conf.default.accept_redirects = 0
# Thực hiện các câu lệnh sau để đặt các tham số vào kernel đang hoạt động:
# sysctl -w net.ipv6.conf.all.accept_redirects=0
# sysctl -w net.ipv6.conf.default.accept_redirects=0
if [ $(sysctl net.ipv4.conf.all.accept_redirects | grep "0" | wc -l) -eq 0 ] || [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ] || [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ] || [ $(sysctl net.ipv4.conf.default.accept_redirects | grep "0" | wc -l) -eq 0 ] || [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ] || [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ] || [[ ($(echo $output | grep "enabled" | wc -l) -ne 0 && ($(sysctl net.ipv6.conf.all.accept_redirects | grep "0" | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 || $(sysctl net.ipv6.conf.default.accept_redirects | grep "0" | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0)) ]]; then
echo "{\"3.3.2. Cấu hình từ chối các ICMP redirect message\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Đặt các tham số sau và file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf:
# net.ipv4.conf.all.accept_redirects = 0
# net.ipv4.conf.default.accept_redirects = 0
# Thực hiện các câu lệnh sau để đặt các tham số vào kernel đang hoạt động:
# sysctl -w net.ipv4.conf.all.accept_redirects=0
# sysctl -w net.ipv4.conf.default.accept_redirects=0
# Nếu sử dụng Ipv6:
# Đặt các tham số sau và file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf:
# net.ipv6.conf.all.accept_redirects = 0
# net.ipv6.conf.default.accept_redirects = 0
# Thực hiện các câu lệnh sau để đặt các tham số vào kernel đang hoạt động:
# sysctl -w net.ipv6.conf.all.accept_redirects=0
# sysctl -w net.ipv6.conf.default.accept_redirects=0"
if [ $(sysctl net.ipv4.conf.all.accept_redirects | grep "0" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sysctl net.ipv4.conf.all.accept_redirects | grep \"0\" -ne 0 ";sysctl net.ipv4.conf.all.accept_redirects | grep "0"; fi
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv4\.conf\.all\.accept_redirects\s*=\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0 ";grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv4\.conf\.all\.accept_redirects\s*=\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0 ";grep -Ps "^\h*net\.ipv4\.conf\.all\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(sysctl net.ipv4.conf.default.accept_redirects | grep "0" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sysctl net.ipv4.conf.default.accept_redirects | grep \"0\" -ne 0 ";sysctl net.ipv4.conf.default.accept_redirects | grep "0"; fi
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv4\.conf\.default\.accept_redirects\s*=\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0 ";grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv4\.conf\.default\.accept_redirects\s*=\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0 ";grep -Ps "^\h*net\.ipv4\.conf\.default\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ] && [ $(sysctl net.ipv6.conf.all.accept_redirects | grep "0" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sysctl net.ipv6.conf.all.accept_redirects | grep \"0\" -ne 0 ";sysctl net.ipv6.conf.all.accept_redirects | grep "0"; fi
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ] && [ $(grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv6\.conf\.all\.accept_redirects\s*=\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0 ";grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ] && [ $(grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv6\.conf\.all\.accept_redirects\s*=\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0 ";grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ] && [ $(sysctl net.ipv6.conf.default.accept_redirects | grep "0" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sysctl net.ipv6.conf.default.accept_redirects | grep \"0\" -ne 0 ";sysctl net.ipv6.conf.default.accept_redirects | grep "0"; fi
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ] && [ $(grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv6\.conf\.default\.accept_redirects\s*=\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0 ";grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ] && [ $(grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv6\.conf\.default\.accept_redirects\s*=\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0 ";grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
echo "######################################"
else
echo "{\"3.3.2. Cấu hình từ chối các ICMP redirect message\" : \"PASSED\"}"
fi
############################################################################
# Đặt các tham số sau vào file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf:
# net.ipv4.conf.all.secure_redirects = 0
# net.ipv4.conf.default.secure_redirects = 0
# Thực hiện các câu lệnh sau để đặt các tham số vào kernel đang hoạt động:
# sysctl -w net.ipv4.conf.all.secure_redirects=0
# sysctl -w net.ipv4.conf.default.secure_redirects=0
if [ $(sysctl net.ipv4.conf.all.secure_redirects | grep "0" | wc -l) -eq 0 ] || [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.secure_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ] || [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.secure_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ] || [ $(sysctl net.ipv4.conf.default.secure_redirects | grep "0" | wc -l) -eq 0 ] || [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.secure_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ] || [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.secure_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then
echo "{\"3.3.3. Cấu hình từ chối các secure ICMP redirect message\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Đặt các tham số sau vào file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf:
# net.ipv4.conf.all.secure_redirects = 0
# net.ipv4.conf.default.secure_redirects = 0
# Thực hiện các câu lệnh sau để đặt các tham số vào kernel đang hoạt động:
# sysctl -w net.ipv4.conf.all.secure_redirects=0
# sysctl -w net.ipv4.conf.default.secure_redirects=0"
if [ $(sysctl net.ipv4.conf.all.secure_redirects | grep "0" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sysctl net.ipv4.conf.all.secure_redirects | grep \"0\" -ne 0 ";sysctl net.ipv4.conf.all.secure_redirects | grep "0"; fi
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.secure_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv4\.conf\.all\.secure_redirects\s*=\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0 ";grep -Ps "^\h*net\.ipv4\.conf\.all\.secure_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.secure_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv4\.conf\.all\.secure_redirects\s*=\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0 ";grep -Ps "^\h*net\.ipv4\.conf\.all\.secure_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(sysctl net.ipv4.conf.default.secure_redirects | grep "0" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sysctl net.ipv4.conf.default.secure_redirects | grep \"0\" -ne 0 ";sysctl net.ipv4.conf.default.secure_redirects | grep "0"; fi
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.secure_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv4\.conf\.default\.secure_redirects\s*=\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0 ";grep -Ps "^\h*net\.ipv4\.conf\.default\.secure_redirects\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.secure_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv4\.conf\.default\.secure_redirects\s*=\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0 ";grep -Ps "^\h*net\.ipv4\.conf\.default\.secure_redirects\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
echo "######################################"
else
echo "{\"3.3.3. Cấu hình từ chối các secure ICMP redirect message\" : \"PASSED\"}"
fi
############################################################################
# Đặt tham số sau vào file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf:
# net.ipv4.icmp_echo_ignore_broadcasts = 1
# Thực hiện các câu lệnh sau để đặt tham số vào kernel đang hoạt động:
# sysctl -w net.ipv4.icmp_echo_ignore_broadcasts=1
if [ $(sysctl net.ipv4.icmp_echo_ignore_broadcasts | grep "1" | wc -l) -eq 0 ] || [ $(grep -Ps "^\h*net\.ipv4\.icmp_echo_ignore_broadcasts\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ] || [ $(grep -Ps "^\h*net\.ipv4\.icmp_echo_ignore_broadcasts\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then
echo "{\"3.3.4. Cấu hình từ chối các gói tin ICMP request broadcast\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Đặt tham số sau vào file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf:
# net.ipv4.icmp_echo_ignore_broadcasts = 1
# Thực hiện các câu lệnh sau để đặt tham số vào kernel đang hoạt động:
# sysctl -w net.ipv4.icmp_echo_ignore_broadcasts=1"
if [ $(sysctl net.ipv4.icmp_echo_ignore_broadcasts | grep "1" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sysctl net.ipv4.icmp_echo_ignore_broadcasts | grep \"0\" -ne 0 ";sysctl net.ipv4.icmp_echo_ignore_broadcasts | grep "1"; fi
if [ $(grep -Ps "^\h*net\.ipv4\.icmp_echo_ignore_broadcasts\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv4\.icmp_echo_ignore_broadcasts\s*=\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0 ";grep -Ps "^\h*net\.ipv4\.icmp_echo_ignore_broadcasts\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(grep -Ps "^\h*net\.ipv4\.icmp_echo_ignore_broadcasts\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv4\.icmp_echo_ignore_broadcasts\s*=\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0 ";grep -Ps "^\h*net\.ipv4\.icmp_echo_ignore_broadcasts\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
echo "######################################"
else
echo "{\"3.3.4. Cấu hình từ chối các gói tin ICMP request broadcast\" : \"PASSED\"}"
fi
############################################################################
# Đặt tham số sau vào file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf:
# net.ipv4.icmp_ignore_bogus_error_responses = 1
# Thực hiện các câu lệnh sau để đặt tham số vào kernel đang hoạt động:
# sysctl -w net.ipv4.icmp_ignore_bogus_error_responses=1
if [ $(sysctl net.ipv4.icmp_ignore_bogus_error_responses | grep "1" | wc -l) -eq 0 ] || [ $(grep -Ps "^\h*net\.ipv4\.icmp_ignore_bogus_error_responses\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ] || [ $(grep -Ps "^\h*net\.ipv4\.icmp_ignore_bogus_error_responses\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then
echo "{\"3.3.5. Cấu hình bỏ qua phản hồi ICMP không hợp lệ\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Đặt tham số sau vào file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf:
# net.ipv4.icmp_ignore_bogus_error_responses = 1
# Thực hiện các câu lệnh sau để đặt tham số vào kernel đang hoạt động:
# sysctl -w net.ipv4.icmp_ignore_bogus_error_responses=1"
if [ $(sysctl net.ipv4.icmp_ignore_bogus_error_responses | grep "1" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sysctl net.ipv4.icmp_ignore_bogus_error_responses | grep \"0\" -ne 0 ";sysctl net.ipv4.icmp_ignore_bogus_error_responses | grep "1"; fi
if [ $(grep -Ps "^\h*net\.ipv4\.icmp_ignore_bogus_error_responses\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv4\.icmp_ignore_bogus_error_responses\s*=\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0 ";grep -Ps "^\h*net\.ipv4\.icmp_ignore_bogus_error_responses\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(grep -Ps "^\h*net\.ipv4\.icmp_ignore_bogus_error_responses\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv4\.icmp_ignore_bogus_error_responses\s*=\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0 ";grep -Ps "^\h*net\.ipv4\.icmp_ignore_bogus_error_responses\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
echo "######################################"
else
echo "{\"3.3.5. Cấu hình bỏ qua phản hồi ICMP không hợp lệ\" : \"PASSED\"}"
fi
############################################################################
# Đặt các tham số sau vào file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf:
# net.ipv4.conf.all.rp_filter = 1
# net.ipv4.conf.default.rp_filter = 1
# Thực hiện các câu lệnh sau để đặt các tham số vào kernel đang hoạt động:
# sysctl -w net.ipv4.conf.all.rp_filter=1
# sysctl -w net.ipv4.conf.default.rp_filter=1
if [ $(sysctl net.ipv4.conf.all.rp_filter | grep "1" | wc -l) -eq 0 ] || [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.rp_filter\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ] || [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.rp_filter\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ] || [ $(sysctl net.ipv4.conf.default.rp_filter | grep "1" | wc -l) -eq 0 ] || [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.rp_filter\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ] || [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.rp_filter\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then
echo "{\"3.3.6. Cấu hình Reverse Path Filtering\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Đặt các tham số sau vào file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf:
# net.ipv4.conf.all.rp_filter = 1
# net.ipv4.conf.default.rp_filter = 1
# Thực hiện các câu lệnh sau để đặt các tham số vào kernel đang hoạt động:
# sysctl -w net.ipv4.conf.all.rp_filter=1
# sysctl -w net.ipv4.conf.default.rp_filter=1"
if [ $(sysctl net.ipv4.conf.all.rp_filter | grep "1" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sysctl net.ipv4.conf.all.rp_filter | grep \"0\" -ne 0 ";sysctl net.ipv4.conf.all.rp_filter | grep "1"; fi
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.rp_filter\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv4\.conf\.all\.rp_filter\s*=\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0 ";grep -Ps "^\h*net\.ipv4\.conf\.all\.rp_filter\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.all\.rp_filter\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv4\.conf\.all\.rp_filter\s*=\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0 ";grep -Ps "^\h*net\.ipv4\.conf\.all\.rp_filter\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(sysctl net.ipv4.conf.default.rp_filter | grep "1" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sysctl net.ipv4.conf.default.rp_filter | grep \"0\" -ne 0 ";sysctl net.ipv4.conf.default.rp_filter | grep "1"; fi
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.rp_filter\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv4\.conf\.default\.rp_filter\s*=\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0 ";grep -Ps "^\h*net\.ipv4\.conf\.default\.rp_filter\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(grep -Ps "^\h*net\.ipv4\.conf\.default\.rp_filter\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv4\.conf\.default\.rp_filter\s*=\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0 ";grep -Ps "^\h*net\.ipv4\.conf\.default\.rp_filter\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
echo "######################################"
else
echo "{\"3.3.6. Cấu hình Reverse Path Filtering\" : \"PASSED\"}"
fi
############################################################################
# Đặt tham số sau và file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf:
# net.ipv4.tcp_syncookies = 1
# Thực hiện các câu lệnh sau để đặt các tham số vào kernel đang hoạt động:
# sysctl -w net.ipv4.tcp_syncookies=1
# sysctl -w net.ipv4.route.flush=1
if [ $(sysctl net.ipv4.tcp_syncookies | grep "1" | wc -l) -eq 0 ] || [ $(grep -Ps "^\h*net\.ipv4\.tcp_syncookies\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ] || [ $(grep -Ps "^\h*net\.ipv4\.tcp_syncookies\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then
echo "{\"3.3.7. Cấu hình TCP SYN Cookies\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Đặt tham số sau và file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf:
# net.ipv4.tcp_syncookies = 1
# Thực hiện các câu lệnh sau để đặt các tham số vào kernel đang hoạt động:
# sysctl -w net.ipv4.tcp_syncookies=1
# sysctl -w net.ipv4.route.flush=1"
if [ $(sysctl net.ipv4.tcp_syncookies | grep "1" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sysctl net.ipv4.tcp_syncookies | grep \"0\" -ne 0 ";sysctl net.ipv4.tcp_syncookies | grep "1"; fi
if [ $(grep -Ps "^\h*net\.ipv4\.tcp_syncookies\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv4\.tcp_syncookies\s*=\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0 ";grep -Ps "^\h*net\.ipv4\.tcp_syncookies\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(grep -Ps "^\h*net\.ipv4\.tcp_syncookies\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv4\.tcp_syncookies\s*=\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0 ";grep -Ps "^\h*net\.ipv4\.tcp_syncookies\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
echo "######################################"
else
echo "{\"3.3.7. Cấu hình TCP SYN Cookies\" : \"PASSED\"}"
fi
############################################################################
# Đặt tham số sau và file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf:
# net.ipv6.conf.all.accept_ra = 0
# net.ipv6.conf.default.accept_ra = 0
# Thực hiện các câu lệnh sau để đặt các tham số vào kernel đang hoạt động:
# sysctl -w net.ipv6.conf.all.accept_ra=0
# sysctl -w net.ipv6.conf.default.accept_ra=0
# *Lưu ý: Mục này chỉ áp dụng nếu sử dụng IPv6
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ] && [[ ($(sysctl net.ipv6.conf.all.accept_ra | grep "0" | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_ra\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_ra\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 || $(sysctl net.ipv6.conf.default.accept_ra | grep "0" | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_ra\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 || $(grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_ra\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0) ]]; then
echo "{\"3.3.8. Cấu hình từ chối IPv6 router advertisements\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Đặt tham số sau và file /etc/sysctl.conf hoặc /etc/sysctl.d/*.conf:
# net.ipv6.conf.all.accept_ra = 0
# net.ipv6.conf.default.accept_ra = 0
# Thực hiện các câu lệnh sau để đặt các tham số vào kernel đang hoạt động:
# sysctl -w net.ipv6.conf.all.accept_ra=0
# sysctl -w net.ipv6.conf.default.accept_ra=0
# *Lưu ý: Mục này chỉ áp dụng nếu sử dụng IPv6"
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ] && [ $(sysctl net.ipv6.conf.all.accept_ra | grep "0" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sysctl net.ipv6.conf.all.accept_ra | grep \"0\" -ne 0 ";sysctl net.ipv6.conf.all.accept_ra | grep "0"; fi
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ] && [ $(grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_ra\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv6\.conf\.all\.accept_ra\s*=\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0 ";grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_ra\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ] && [ $(grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_ra\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv6\.conf\.all\.accept_ra\s*=\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0 ";grep -Ps "^\h*net\.ipv6\.conf\.all\.accept_ra\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ] && [ $(sysctl net.ipv6.conf.default.accept_ra | grep "0" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sysctl net.ipv6.conf.default.accept_ra | grep \"0\" -ne 0 ";sysctl net.ipv6.conf.default.accept_ra | grep "0"; fi
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ] && [ $(grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_ra\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv6\.conf\.default\.accept_ra\s*=\s*0\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -ne 0 ";grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_ra\s*=\s*0" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ] && [ $(grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_ra\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ps \"^\\h*net\.ipv6\.conf\.default\.accept_ra\s*=\s*1\" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf -eq 0 ";grep -Ps "^\h*net\.ipv6\.conf\.default\.accept_ra\s*=\s*1" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; fi
echo "######################################"
else
echo "{\"3.3.8. Cấu hình từ chối IPv6 router advertisements\" : \"PASSED\"}"
fi
############################################################################
# FIREWALL DETECTION - Kiểm tra hệ thống đang dùng firewall nào
############################################################################
FIREWALLD_ENABLED=0
IPTABLES_ENABLED=0
# Kiểm tra firewalld có enabled không
if [ $(rpm -qa firewalld 2>/dev/null | wc -l) -ne 0 ] && [ $(systemctl is-enabled firewalld 2>/dev/null | grep "^enabled$" | wc -l) -ne 0 ]; then
FIREWALLD_ENABLED=1
fi
# Kiểm tra iptables có enabled không
if [ $(rpm -qa iptables-services 2>/dev/null | wc -l) -ne 0 ] && [ $(systemctl is-enabled iptables 2>/dev/null | grep "^enabled$" | wc -l) -ne 0 ]; then
IPTABLES_ENABLED=1
fi
############################################################################
# 3.4.1.1. Cấu hình kích hoạt firewalld
############################################################################
# Nếu iptables đã enabled → tự động PASSED
if [ $IPTABLES_ENABLED -eq 1 ]; then
echo "{\"3.4.1.1. Cấu hình kích hoạt firewalld\" : \"PASSED\"}"
echo "######################################"
echo "# Hệ thống đang sử dụng iptables - bỏ qua check firewalld"
echo "######################################"
elif [ $FIREWALLD_ENABLED -eq 1 ]; then
echo "{\"3.4.1.1. Cấu hình kích hoạt firewalld\" : \"PASSED\"}"
else
echo "{\"3.4.1.1. Cấu hình kích hoạt firewalld\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để cài đặt firewalld:
# yum install firewalld
# Thực hiện các câu lệnh sau để kích hoạt firewalld:
# systemctl unmask firewalld
# systemctl --now enable firewalld"
if [ $(rpm -qa firewalld 2>/dev/null | wc -l) -ne 0 ]; then echo "-------------------"; echo "#rpm -qa firewalld -eq 0 ";rpm -qa firewalld; fi
if [ $(systemctl is-enabled firewalld 2>/dev/null | grep "^enabled$" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#systemctl is-enabled firewalld | grep \"^enabled\$\" -ne 0 ";systemctl is-enabled firewalld 2>/dev/null | grep "^enabled$"; fi
echo "######################################"
fi
############################################################################
# 3.4.1.2. Cấu hình vô hiệu hoá iptables-services, nftables khi sử dụng firewalld
############################################################################
# Nếu iptables đã enabled → tự động PASSED
if [ $IPTABLES_ENABLED -eq 1 ]; then
echo "{\"3.4.1.2. Cấu hình vô hiệu hoá iptables-services, nftables khi sử dụng firewalld\" : \"PASSED\"}"
echo "######################################"
echo "# Hệ thống đang sử dụng iptables - bỏ qua check firewalld"
echo "######################################"
elif [[ ($(rpm -qa iptables-services 2>/dev/null | wc -l) -ne 0 && $(systemctl is-enabled iptables 2>/dev/null | grep "^disabled$" | wc -l) -eq 0) ]] || [[ ($(rpm -qa ip6tables-services 2>/dev/null | wc -l) -ne 0 && $(systemctl is-enabled ip6tables 2>/dev/null | grep "^disabled$" | wc -l) -eq 0) ]] || [[ ($(rpm -qa nftables 2>/dev/null | wc -l) -ne 0 && $(systemctl is-enabled nftables 2>/dev/null | grep "^masked$" | wc -l) -eq 0) ]]; then
echo "{\"3.4.1.2. Cấu hình vô hiệu hoá iptables-services, nftables khi sử dụng firewalld\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để gỡ bỏ iptables-services:
# systemctl stop iptables
# systemctl stop ip6tables
# yum remove iptables-services
# Thực hiện câu lệnh sau để vô hiệu hoá nftables:
# systemctl --now mask nftables"
if [ $(rpm -qa iptables-services 2>/dev/null | wc -l) -ne 0 ]; then echo "-------------------"; echo "#rpm -qa iptables-services -eq 0 ";rpm -qa iptables-services; fi
if [ $(rpm -qa ip6tables-services 2>/dev/null | wc -l) -ne 0 ] && [ $(systemctl is-enabled iptables 2>/dev/null | grep "^disabled$" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#systemctl is-enabled iptables | grep \"^disabled\$\" -ne 0 ";systemctl is-enabled iptables 2>/dev/null | grep "^disabled$"; fi
if [ $(rpm -qa ip6tables-services 2>/dev/null | wc -l) -ne 0 ]; then echo "-------------------"; echo "#rpm -qa ip6tables-services -eq 0 ";rpm -qa ip6tables-services; fi
if [ $(rpm -qa ip6tables-services 2>/dev/null | wc -l) -ne 0 ] && [ $(systemctl is-enabled ip6tables 2>/dev/null | grep "^disabled$" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#systemctl is-enabled ip6tables | grep \"^disabled\$\" -ne 0 ";systemctl is-enabled ip6tables 2>/dev/null | grep "^disabled$"; fi
if [ $(rpm -qa nftables 2>/dev/null | wc -l) -ne 0 ]; then echo "-------------------"; echo "#rpm -qa nftables -eq 0 ";rpm -qa nftables; fi
if [ $(rpm -qa nftables 2>/dev/null | wc -l) -ne 0 ] && [ $(systemctl is-enabled nftables 2>/dev/null | grep "^masked$" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#systemctl is-enabled nftables | grep \"^masked\$\" -ne 0 ";systemctl is-enabled nftables 2>/dev/null | grep "^masked$"; fi
echo "######################################"
else
echo "{\"3.4.1.2. Cấu hình vô hiệu hoá iptables-services, nftables khi sử dụng firewalld\" : \"PASSED\"}"
fi
############################################################################
# 3.4.1.3. Cấu hình firewalld rule cho tất cả các port và protocol đang mở
############################################################################
# Nếu iptables đã enabled → tự động PASSED
if [ $IPTABLES_ENABLED -eq 1 ]; then
echo "{\"3.4.1.3. Cấu hình firewalld rule cho tất cả các port và protocol đang mở\" : \"PASSED\"}"
echo "######################################"
echo "# Hệ thống đang sử dụng iptables - bỏ qua check firewalld"
echo "######################################"
elif ! command -v firewall-cmd >/dev/null 2>&1; then
echo "{\"3.4.1.3. Cấu hình firewalld rule cho tất cả các port và protocol đang mở\" : \"FAILED\"}"
echo "######################################"
echo "# firewalld không được cài đặt"
echo "######################################"
elif ! systemctl is-active --quiet firewalld; then
echo "{\"3.4.1.3. Cấu hình firewalld rule cho tất cả các port và protocol đang mở\" : \"FAILED\"}"
echo "######################################"
echo "# firewalld không đang chạy"
echo "######################################"
else
# firewalld đang active - Hiển thị rules và để admin tự kiểm tra (MANUAL)
echo "{\"3.4.1.3. Cấu hình firewalld rule cho tất cả các port và protocol đang mở\" : \"MANUAL\"}"
echo "######################################"
echo "# Cần kiểm tra thủ công các rule firewalld hiện tại:"
echo "-------------------"
echo "# Active zone:"
firewall-cmd --get-active-zones 2>/dev/null || true
echo "-------------------"
echo "# Default zone:"
firewall-cmd --get-default-zone 2>/dev/null || true
echo "-------------------"
echo "# Services được phép:"
firewall-cmd --list-services 2>/dev/null || echo " (Không có services)"
echo "-------------------"
echo "# Ports được phép:"
firewall-cmd --list-ports 2>/dev/null || echo " (Không có ports)"
echo "-------------------"
echo "# Protocols được phép:"
firewall-cmd --list-protocols 2>/dev/null || echo " (Không có protocols)"
echo "-------------------"
echo "# Tất cả rules (chi tiết):"
firewall-cmd --list-all 2>/dev/null || true
echo "######################################"
fi
############################################################################
# 3.4.1.4. Cấu hình chính sách từ chối mặc định cho firewalld
############################################################################
# Nếu iptables đã enabled → tự động PASSED
if [ $IPTABLES_ENABLED -eq 1 ]; then
echo "{\"3.4.1.4. Cấu hình chính sách từ chối mặc định cho firewalld\" : \"PASSED\"}"
echo "######################################"
echo "# Hệ thống đang sử dụng iptables - bỏ qua check firewalld"
echo "######################################"
elif [ $(firewall-cmd --get-target --permanent 2>/dev/null | grep "DROP" | wc -l) -eq 0 ]; then
echo "{\"3.4.1.4. Cấu hình chính sách từ chối mặc định cho firewalld\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để cài đặt chính sách mặc định là DROP:
# firewall-cmd --set-target=DROP --permanent
# Thực hiện câu lệnh sau để áp dụng cấu hình mới của zone:
# firewall-cmd --reload
# *Lưu ý: Thực hiện việc cấu hình chính sách ở mục 2.3.4.1.3 trước để tránh kết nối bị gián đoạn."
if [ $(firewall-cmd --get-target --permanent 2>/dev/null | grep "DROP" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#firewall-cmd --get-target --permanent | grep \"DROP\" -ne 0 ";firewall-cmd --get-target --permanent 2>/dev/null | grep "DROP"; fi
echo "######################################"
else
echo "{\"3.4.1.4. Cấu hình chính sách từ chối mặc định cho firewalld\" : \"PASSED\"}"
fi
############################################################################
# 3.4.2.1. Cấu hình kích hoạt Iptables
############################################################################
# Nếu firewalld đã enabled → tự động PASSED
if [ $FIREWALLD_ENABLED -eq 1 ]; then
echo "{\"3.4.2.1. Cấu hình kích hoạt Iptables\" : \"PASSED\"}"
echo "######################################"
echo "# Hệ thống đang sử dụng firewalld - bỏ qua check iptables"
echo "######################################"
elif [ $IPTABLES_ENABLED -eq 1 ]; then
echo "{\"3.4.2.1. Cấu hình kích hoạt Iptables\" : \"PASSED\"}"
else
echo "{\"3.4.2.1. Cấu hình kích hoạt Iptables\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để cài đặt iptables và iptables-services:
# yum install iptables iptables-services
# Thực hiện câu lệnh sau để kích hoạt iptables:
# systemctl --now enable iptables"
if [ $(rpm -qa iptables 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#rpm -qa iptables -ne 0 ";rpm -qa iptables; fi
if [ $(rpm -qa iptables-services 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#rpm -qa iptables-services -ne 0 ";rpm -qa iptables-services; fi
if [ $(systemctl is-enabled iptables 2>/dev/null | grep "^enabled$" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#systemctl is-enabled iptables 2>/dev/null | grep \"^enabled\$\" -ne 0 ";systemctl is-enabled iptables 2>/dev/null | grep "^enabled$"; fi
echo "######################################"
fi
############################################################################
# 3.4.2.2. Cấu hình vô hiệu hoá firewalld, nftables khi sử dụng iptables
############################################################################
# Nếu firewalld đã enabled → tự động PASSED
if [ $FIREWALLD_ENABLED -eq 1 ]; then
echo "{\"3.4.2.2. Cấu hình vô hiệu hoá firewalld, nftables khi sử dụng iptables\" : \"PASSED\"}"
echo "######################################"
echo "# Hệ thống đang sử dụng firewalld - bỏ qua check iptables"
echo "######################################"
elif [[ ($(rpm -qa firewalld 2>/dev/null | wc -l) -ne 0 && $(systemctl is-enabled firewalld 2>/dev/null | grep "masked" | wc -l) -eq 0) ]] || [[ ($(rpm -qa nftables 2>/dev/null | wc -l) -ne 0 && $(systemctl is-enabled nftables 2>/dev/null | grep "masked" | wc -l) -eq 0) ]]; then
echo "{\"3.4.2.2. Cấu hình vô hiệu hoá firewalld, nftables khi sử dụng iptables\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để vô hiệu hoá firewalld:
# systemctl --now mask firewalld
# Thực hiện câu lệnh sau để vô hiệu hoá nftables:
# systemctl --now mask nftables"
if [ $(systemctl is-enabled firewalld 2>/dev/null | grep "masked" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#systemctl is-enabled firewalld | grep \"masked\" -ne 0 ";systemctl is-enabled firewalld 2>/dev/null | grep "masked"; fi
if [ $(systemctl is-enabled nftables 2>/dev/null | grep "masked" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#systemctl is-enabled nftables | grep \"masked\" -ne 0 ";systemctl is-enabled nftables 2>/dev/null | grep "masked"; fi
echo "######################################"
else
echo "{\"3.4.2.2. Cấu hình vô hiệu hoá firewalld, nftables khi sử dụng iptables\" : \"PASSED\"}"
fi
############################################################################
# 3.4.2.3. Cấu hình iptables loopback traffic
############################################################################
# Nếu firewalld đã enabled → tự động PASSED
if [ $FIREWALLD_ENABLED -eq 1 ]; then
echo "{\"3.4.2.3. Cấu hình iptables loopback traffic\" : \"PASSED\"}"
echo "######################################"
echo "# Hệ thống đang sử dụng firewalld - bỏ qua check iptables"
echo "######################################"
elif [ $(iptables -L INPUT -v -n 2>/dev/null | grep "ACCEPT.*lo" | wc -l) -eq 0 ] || [ $(iptables -L OUTPUT -v -n 2>/dev/null | grep "ACCEPT.*lo" | wc -l) -eq 0 ] || [ $(iptables -L INPUT -v -n 2>/dev/null | grep "DROP.*127\.0\.0\.0/8" | wc -l) -eq 0 ] || [[ ($IPV6_ENABLED -eq 1 && ($(ip6tables -L INPUT -v -n 2>/dev/null | grep "ACCEPT.*lo" | wc -l) -eq 0 || $(ip6tables -L OUTPUT -v -n 2>/dev/null | grep "ACCEPT.*lo" | wc -l) -eq 0 || $(ip6tables -L INPUT -v -n 2>/dev/null | grep "DROP.*::1" | wc -l) -eq 0 )) ]]; then
echo "{\"3.4.2.3. Cấu hình iptables loopback traffic\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để cài đặt các luật cho đường truyền loopback:
# iptables -A INPUT -i lo -j ACCEPT
# iptables -A OUTPUT -o lo -j ACCEPT
# iptables -A INPUT -s 127.0.0.0/8 -j DROP
# Nếu sử dụng IPv6:
# Thực hiện các câu lệnh sau để cài đặt các luật cho đường truyền loopback:
# ip6tables -A INPUT -i lo -j ACCEPT
# ip6tables -A OUTPUT -o lo -j ACCEPT
# ip6tables -A INPUT -s ::1 -j DROP"
if [ $(iptables -L INPUT -v -n | grep "ACCEPT.*lo" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#iptables -L INPUT -v -n | grep \"ACCEPT.*lo\" -ne 0 ";iptables -L INPUT -v -n | grep "ACCEPT.*lo"; fi
if [ $(iptables -L OUTPUT -v -n | grep "ACCEPT.*lo" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#iptables -L OUTPUT -v -n | grep \"ACCEPT.*lo\" -ne 0 ";iptables -L OUTPUT -v -n | grep "ACCEPT.*lo"; fi
if [ $(iptables -L INPUT -v -n | grep "DROP.*127\.0\.0\.0/8" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#iptables -L INPUT -v -n | grep \"DROP.*127\\.0\\.0\\.0/8\" -ne 0 ";iptables -L INPUT -v -n | grep "DROP.*127\.0\.0\.0/8"; fi
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ] && [ $(ip6tables -L INPUT -v -n | grep "ACCEPT.*lo" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#ip6tables -L INPUT -v -n | grep \"ACCEPT.*lo\" -ne 0 ";ip6tables -L INPUT -v -n | grep "ACCEPT.*lo"; fi
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ] && [ $(ip6tables -L OUTPUT -v -n | grep "ACCEPT.*lo" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#ip6tables -L OUTPUT -v -n | grep \"ACCEPT.*lo\" -ne 0 ";ip6tables -L OUTPUT -v -n | grep "ACCEPT.*lo"; fi
if [ $(echo $output | grep "enabled" | wc -l) -ne 0 ] && [ $(ip6tables -L INPUT -v -n | grep "DROP.*::1" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#ip6tables -L INPUT -v -n | grep \"DROP.*::1\" -ne 0 ";ip6tables -L INPUT -v -n | grep "DROP.*::1"; fi
echo "######################################"
else
echo "{\"3.4.2.3. Cấu hình iptables loopback traffic\" : \"PASSED\"}"
PASSED=$((PASSED + 1))
fi
############################################################################
# 3.4.2.4. Cấu hình iptables rule cho tất cả các port và protocol đang mở
############################################################################
# Nếu firewalld đã enabled → tự động PASSED
if [ $FIREWALLD_ENABLED -eq 1 ]; then
echo "{\"3.4.2.4. Cấu hình iptables rule cho tất cả các port và protocol đang mở\" : \"PASSED\"}"
echo "######################################"
echo "# Hệ thống đang sử dụng firewalld - bỏ qua check iptables"
echo "######################################"
elif ! command -v iptables >/dev/null 2>&1; then
echo "{\"3.4.2.4. Cấu hình iptables rule cho tất cả các port và protocol đang mở\" : \"FAILED\"}"
echo "######################################"
echo "# iptables không được cài đặt"
echo "######################################"
else
# Hiển thị rules và để admin tự kiểm tra (MANUAL)
echo "{\"3.4.2.4. Cấu hình iptables rule cho tất cả các port và protocol đang mở\" : \"MANUAL\"}"
echo "######################################"
echo "# Các rule iptables IPv4 hiện tại:"
echo "-------------------"
echo "# INPUT chain:"
iptables -L INPUT -v -n --line-numbers 2>/dev/null || true
echo "-------------------"
echo "# OUTPUT chain:"
iptables -L OUTPUT -v -n --line-numbers 2>/dev/null || true
echo "-------------------"
echo "# FORWARD chain:"
iptables -L FORWARD -v -n --line-numbers 2>/dev/null || true
# Hiển thị các TCP ports đang ACCEPT trong INPUT
echo "-------------------"
echo "# Các TCP ports được phép (INPUT ACCEPT):"
iptables -L INPUT -v -n 2>/dev/null | grep -P 'ACCEPT.*\btcp\b.*\bdpt:' | awk '{
for(i=1;i<=NF;i++) {
if($i ~ /dpt:[0-9]+/) {
port = $i
gsub(/dpt:/, "", port)
print " - Port " port "/tcp"
}
}
}' | sort -u || echo " (Không tìm thấy rules)"
# Hiển thị các UDP ports đang ACCEPT trong INPUT
echo "-------------------"
echo "# Các UDP ports được phép (INPUT ACCEPT):"
iptables -L INPUT -v -n 2>/dev/null | grep -P 'ACCEPT.*\budp\b.*\bdpt:' | awk '{
for(i=1;i<=NF;i++) {
if($i ~ /dpt:[0-9]+/) {
port = $i
gsub(/dpt:/, "", port)
print " - Port " port "/udp"
}
}
}' | sort -u || echo " (Không tìm thấy rules)"
# Kiểm tra IPv6
if [ $IPV6_ENABLED -eq 1 ] && command -v ip6tables >/dev/null 2>&1 && ip6tables -L -v -n >/dev/null 2>&1; then
echo "-------------------"
echo "# Các rule iptables IPv6 hiện tại:"
echo "-------------------"
echo "# INPUT chain (IPv6):"
ip6tables -L INPUT -v -n --line-numbers 2>/dev/null || true
echo "-------------------"
echo "# OUTPUT chain (IPv6):"
ip6tables -L OUTPUT -v -n --line-numbers 2>/dev/null || true
# Hiển thị các TCP ports đang ACCEPT trong INPUT (IPv6)
echo "-------------------"
echo "# Các TCP ports được phép IPv6 (INPUT ACCEPT):"
ip6tables -L INPUT -v -n 2>/dev/null | grep -P 'ACCEPT.*\btcp\b.*\bdpt:' | awk '{
for(i=1;i<=NF;i++) {
if($i ~ /dpt:[0-9]+/) {
port = $i
gsub(/dpt:/, "", port)
print " - Port " port "/tcp (v6)"
}
}
}' | sort -u || echo " (Không tìm thấy rules)"
fi
echo "######################################"
fi
############################################################################
# 3.4.2.5. Cấu hình chính sách từ chối mặc định cho iptables
############################################################################
# Nếu firewalld đã enabled → tự động PASSED
if [ $FIREWALLD_ENABLED -eq 1 ]; then
echo "{\"3.4.2.5. Cấu hình chính sách từ chối mặc định cho iptables\" : \"PASSED\"}"
echo "######################################"
echo "# Hệ thống đang sử dụng firewalld - bỏ qua check iptables"
echo "######################################"
elif [ $(iptables -L 2>/dev/null | grep "INPUT.*DROP" | wc -l) -eq 0 ] || [ $(iptables -L 2>/dev/null | grep "FORWARD.*DROP" | wc -l) -eq 0 ] || [ $(iptables -L 2>/dev/null | grep "OUTPUT.*DROP" | wc -l) -eq 0 ] || [[ ($IPV6_ENABLED -eq 1 && ($(ip6tables -L 2>/dev/null | grep "INPUT.*DROP" | wc -l) -eq 0 || $(ip6tables -L 2>/dev/null | grep "FORWARD.*DROP" | wc -l) -eq 0 || $(ip6tables -L 2>/dev/null | grep "OUTPUT.*DROP" | wc -l) -eq 0)) ]]; then
echo "{\"3.4.2.5. Cấu hình chính sách từ chối mặc định cho iptables\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để cài đặt chính sách mặc định là DROP:
# iptables -P INPUT DROP
# iptables -P OUTPUT DROP
# iptables -P FORWARD DROP
# Thực hiện câu lệnh sau để lưu cấu hình iptables:
# service iptables save
# Nếu sử dụng IPv6:
# Thực hiện các câu lệnh sau để cài đặt chính sách mặc định là DROP:
# ip6tables -P INPUT DROP
# ip6tables -P OUTPUT DROP
# ip6tables -P FORWARD DROP
# Thực hiện câu lệnh sau để lưu cấu hình ip6tables
# service ip6tables save
# *Lưu ý: Thực hiện việc cấu hình chính sách ở mục 2.3.4.2.3 và 2.3.4.2.4 trước để tránh kết nối bị gián đoạn."
if [ $(iptables -L | grep "INPUT.*DROP" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#iptables -L | grep \"INPUT.*DROP\" -ne 0 ";iptables -L | grep "INPUT.*DROP"; fi
if [ $(iptables -L | grep "FORWARD.*DROP" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#iptables -L | grep \"FORWARD.*DROP\" -ne 0 ";iptables -L | grep "FORWARD.*DROP"; fi
if [ $(iptables -L | grep "OUTPUT.*DROP" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#iptables -L | grep \"OUTPUT.*DROP\" -ne 0 ";iptables -L | grep "OUTPUT.*DROP"; fi
if [ $(ip6tables -L | grep "INPUT.*DROP" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#ip6tables -L | grep \"INPUT.*DROP\" -ne 0 ";ip6tables -L | grep "INPUT.*DROP"; fi
if [ $(ip6tables -L | grep "FORWARD.*DROP" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#ip6tables -L | grep \"FORWARD.*DROP\" -ne 0 ";ip6tables -L | grep "FORWARD.*DROP"; fi
if [ $(ip6tables -L | grep "OUTPUT.*DROP" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#ip6tables -L | grep \"OUTPUT.*DROP\" -ne 0 ";ip6tables -L | grep "OUTPUT.*DROP"; fi
echo "######################################"
else
echo "{\"3.4.2.5. Cấu hình chính sách từ chối mặc định cho iptables\" : \"PASSED\"}"
fi
##################################################################################################################
# Thực hiện câu lệnh sau để cài đặt rsyslog:
# yum install rsyslog
# Thực hiện câu lệnh sau để kích hoạt rsyslog:
# systemctl --now enable rsyslog
if [ $(rpm -qa rsyslog | wc -l) -eq 0 ] || [ $(systemctl is-enabled rsyslog | grep "^enabled$" | wc -l) -eq 0 ]; then
echo "{\"4.1.1.1. Cấu hình kích hoạt rsyslog service\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để cài đặt rsyslog:
# yum install rsyslog
# Thực hiện câu lệnh sau để kích hoạt rsyslog:
# systemctl --now enable rsyslog"
if [ $(rpm -qa rsyslog | wc -l) -eq 0 ]; then echo "-------------------"; echo "#rpm -qa rsyslog -ne 0 ";rpm -qa rsyslog; fi
if [ $(systemctl is-enabled rsyslog | grep "^enabled$" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#systemctl is-enabled rsyslog | grep \"^enabled\$\" -ne 0 ";systemctl is-enabled rsyslog | grep "^enabled$"; fi
echo "######################################"
else
echo "{\"4.1.1.1. Cấu hình kích hoạt rsyslog service\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/rsyslog.conf hoặc /etc/rsyslog.d/*.conf và đặt $FileCreateMode là 0640 hoặc nghiêm ngặt hơn:
# $FileCreateMode 0640
# Thực hiện câu lệnh sau để khởi động lại rsyslog:
# systemctl restart rsyslog
# *Lưu ý: Đảm bảo cấu hình này không bị viết đè bởi các thiết lập kém nghiêm ngặt hơn ở bất kỳ file conf nào trong /etc/rsyslog.d/*.
if [ $(grep "^\$FileCreateMode" /etc/rsyslog.conf /etc/rsyslog.d/* 2>/dev/null | grep -E "0[6-7][0-4]0" | wc -l) -eq 0 ] || [ $(grep -Ev "FileCreateMode.*0[6-7][0-4]0" /etc/rsyslog.conf /etc/rsyslog.d/* 2>/dev/null | grep "^\$FileCreateMode" | wc -l) -ne 0 ]; then
echo "{\"4.1.1.2. Phân quyền đối với file log sinh ra từ rsyslog\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/rsyslog.conf hoặc /etc/rsyslog.d/*.conf và đặt \$FileCreateMode là 0640 hoặc nghiêm ngặt hơn:
# \$FileCreateMode 0640
# Thực hiện câu lệnh sau để khởi động lại rsyslog:
# systemctl restart rsyslog
# *Lưu ý: Đảm bảo cấu hình này không bị viết đè bởi các thiết lập kém nghiêm ngặt hơn ở bất kỳ file conf nào trong /etc/rsyslog.d/*."
if [ $(grep "^\$FileCreateMode" /etc/rsyslog.conf /etc/rsyslog.d/* 2>/dev/null | grep -E "0[6-7][0-4]0" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*\\\$FileCreateMode\" /etc/rsyslog.conf /etc/rsyslog.d/* 2>/dev/null | grep -E \"0[6-7][0-4]0\" -ne 0 ";grep -P "^\h*\$FileCreateMode.*0[6-7][0-4]0" /etc/rsyslog.conf /etc/rsyslog.d/* 2>/dev/null | grep -E "0[6-7][0-4]0"; fi
if [ $(grep -Ev "FileCreateMode.*0[6-7][0-4]0" /etc/rsyslog.conf /etc/rsyslog.d/* 2>/dev/null | grep "^\$FileCreateMode" | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ev \"FileCreateMode.*0[6-7][0-4]0\" /etc/rsyslog.conf /etc/rsyslog.d/* 2>/dev/null | grep \"^\\\$FileCreateMode\" -eq 0 ";grep -Ev "FileCreateMode.*0[6-7][0-4]0" /etc/rsyslog.conf /etc/rsyslog.d/* 2>/dev/null | grep "^\$FileCreateMode"; fi
echo "######################################"
else
echo "{\"4.1.1.2. Phân quyền đối với file log sinh ra từ rsyslog\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/rsyslog.conf và /etc/rsyslog.d/*.conf và thêm vào 1 trong các dòng sau:
# <files to sent to the remote log server> action(type="omfwd" target="<FQDN or ip of loghost>" port="<port number>" protocol="tcp" action.resumeRetryCount="<number of re-tries>" queue.type="LinkedList" queue.size=<number of messages to queue>") # Hoặc
# *.* @@< FQDN or ip of loghost >
# Thực hiện câu lệnh sau để khởi động lại rsyslog:
# systemctl restart rsyslog
if [ $(grep -P "^\h*\*\.\*[^I][^I]*@" /etc/rsyslog.conf /etc/rsyslog.d/*.conf 2>/dev/null | wc -l) -eq 0 ] && [ $(grep -P '^\h*([^#]+\s+)?action\(([^#]+\s+)?\btarget=\"?[^#"]+\"?\b' /etc/rsyslog.conf /etc/rsyslog.d/*.conf 2>/dev/null | wc -l) -eq 0 ]; then
echo "{\"4.1.1.3. Cấu hình lưu trữ log sinh ra từ rsyslog tập trung\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/rsyslog.conf và /etc/rsyslog.d/*.conf và thêm vào 1 trong các dòng sau:
# <files to sent to the remote log server> action(type=\"omfwd\" target=\"<FQDN or ip of loghost>\" port=\"<port number>\" protocol=\"tcp\" action.resumeRetryCount=\"<number of re-tries>\" queue.type=\"LinkedList\" queue.size=<number of messages to queue>\") # Hoặc
# *.* @@< FQDN or ip of loghost >
# Thực hiện câu lệnh sau để khởi động lại rsyslog:
# systemctl restart rsyslog"
if [ $(grep -P "^\h*\*\.\*[^I][^I]*@" /etc/rsyslog.conf /etc/rsyslog.d/*.conf 2>/dev/null | wc -l) -eq 0 ] && [ $(grep -E '^\h*([^#]+\s+)?action\(([^#]+\s+)?\btarget=\"?[^#"]+\"?\b' /etc/rsyslog.conf /etc/rsyslog.d/*.conf 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*\\*\\.\\*[^I][^I]*@\" /etc/rsyslog.conf /etc/rsyslog.d/*.conf 2>/dev/null -ne 0 ";grep -P "^\h*\*\.\*[^I][^I]*@" /etc/rsyslog.conf /etc/rsyslog.d/*.conf 2>/dev/null; fi
if [ $(grep -P "^\h*\*\.\*[^I][^I]*@" /etc/rsyslog.conf /etc/rsyslog.d/*.conf 2>/dev/null | wc -l) -eq 0 ] && [ $(grep -E '^\h*([^#]+\s+)?action\(([^#]+\s+)?\btarget=\"?[^#"]+\"?\b' /etc/rsyslog.conf /etc/rsyslog.d/*.conf 2>/dev/null | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -E '^\h*([^#]+\s+)?action\(([^#]+\s+)?\btarget=\\"?[^#\"]+\\"?\b' /etc/rsyslog.conf /etc/rsyslog.d/*.conf 2>/dev/null -ne 0 ";grep -E '^\h*([^#]+\s+)?action\(([^#]+\s+)?\btarget=\"?[^#"]+\"?\b' /etc/rsyslog.conf /etc/rsyslog.d/*.conf 2>/dev/null; fi
echo "######################################"
else
echo "{\"4.1.1.3. Cấu hình lưu trữ log sinh ra từ rsyslog tập trung\" : \"PASSED\"}"
fi
##################################################################################################################
echo -e "\n######################################"
if [[ $(grep -E "\s[6].[0-9]" /etc/system-release | wc -l) -ne 0 && $(find /var/log -type f -perm /g+wx,o+rwx -ls | wc -l) -ne 0 ]]; then
echo "{\"4.1.1.4. Phân quyền đối với tất cả các file log\" : \"FAILED\"}"
else
echo "{\"4.1.1.4. Phân quyền đối với tất cả các file log\" : \"PASSED\"}"
fi
# Log
if [ $(grep -E "\s[6].[0-9]" /etc/system-release | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#grep -E \"\\s[6].[0-9]\" /etc/system-release -eq 0"; grep -E "\s[6].[0-9]" /etc/system-release
if [ $(find /var/log -type f -perm /g+wx,o+rwx -ls | wc -l) -ne 0 ]; then echo "----------[FAILED]----------"; else echo "----------[PASSED]----------"; fi; echo "#find /var/log -type f -perm /g+wx,o+rwx -ls | wc -l -eq 0"; find /var/log -type f -perm /g+wx,o+rwx -ls | wc -l
echo "----------LOG----------"
############################################################################
# Thực hiện câu lệnh sau để đặt quyền cho toàn bộ file log:
# find /var/log -type f -exec chmod g-wx,o-rwx {} +
if [ $(find /var/log -type f -perm /g+wx,o+rwx -ls | wc -l) -ne 0 ]; then
echo "{\"4.1.2. Phân quyền đối với tất cả các file log\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để đặt quyền cho toàn bộ file log:
# find /var/log -type f -exec chmod g-wx,o-rwx {} +"
if [ $(find /var/log -type f -perm /g+wx,o+rwx -ls | wc -l) -ne 0 ]; then echo "-------------------"; echo "#find /var/log -type f -perm /g+wx,o+rwx -ls -eq 0 ";find /var/log -type f -perm /g+wx,o+rwx -ls; fi
echo "######################################"
else
echo "{\"4.1.2. Phân quyền đối với tất cả các file log\" : \"PASSED\"}"
fi
##################################################################################################################
# Thực hiện câu lệnh sau để kích hoạt cron:
# systemctl --now enable crond
if [ $(systemctl is-enabled crond | grep "^enabled$" | wc -l) -eq 0 ]; then
echo "{\"5.1.1. Cấu hình kích hoạt cron daemon\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để kích hoạt cron:
# systemctl --now enable crond"
if [ $(systemctl is-enabled crond | grep "^enabled$" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#systemctl is-enabled crond | grep \"^enabled\$\" -ne 0 ";systemctl is-enabled crond | grep "^enabled$"; fi
echo "######################################"
else
echo "{\"5.1.1. Cấu hình kích hoạt cron daemon\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện các câu lệnh sau để đảm bảo rằng để đặt chủ sở hữu và quyền cho file /etc/crontab:
# chown root:root /etc/crontab
# chmod og-rwx /etc/crontab
if [ $(stat /etc/crontab | grep "0*00.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then
echo "{\"5.1.2. Cấu hình phân quyền cho file /etc/crontab\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để đảm bảo rằng để đặt chủ sở hữu và quyền cho file /etc/crontab:
# chown root:root /etc/crontab
# chmod og-rwx /etc/crontab"
if [ $(stat /etc/crontab | grep "0*00.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat /etc/crontab | grep \"0*00.*Uid:.*0/.*root.*Gid:.*0/.*root\" -ne 0 ";stat /etc/crontab | grep "0*00.*Uid:.*0/.*root.*Gid:.*0/.*root"; fi
echo "######################################"
else
echo "{\"5.1.2. Cấu hình phân quyền cho file /etc/crontab\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện các câu lệnh sau để đặt chủ sở hữu và quyền cho file /etc/cron.hourly:
# chown root:root /etc/cron.hourly
# chmod og-rwx /etc/cron.hourly
if [ $(stat /etc/cron.hourly | grep "0*00.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then
echo "{\"5.1.3. Cấu hình phân quyền cho file /etc/cron.hourly\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để đặt chủ sở hữu và quyền cho file /etc/cron.hourly:
# chown root:root /etc/cron.hourly
# chmod og-rwx /etc/cron.hourly"
if [ $(stat /etc/cron.hourly | grep "0*00.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat /etc/cron.hourly | grep \"0*00.*Uid:.*0/.*root.*Gid:.*0/.*root\" -ne 0 ";stat /etc/cron.hourly | grep "0*00.*Uid:.*0/.*root.*Gid:.*0/.*root"; fi
echo "######################################"
else
echo "{\"5.1.3. Cấu hình phân quyền cho file /etc/cron.hourly\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện các câu lệnh sau và đặt chủ sở hữu và quyền cho file /etc/cron.daily:
# chown root:root /etc/cron.daily
# chmod og-rwx /etc/cron.daily
if [ $(stat /etc/cron.daily | grep "0*00.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then
echo "{\"5.1.4. Cấu hình phân quyền cho file /etc/cron.daily\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau và đặt chủ sở hữu và quyền cho file /etc/cron.daily:
# chown root:root /etc/cron.daily
# chmod og-rwx /etc/cron.daily"
if [ $(stat /etc/cron.daily | grep "0*00.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat /etc/cron.daily | grep \"0*00.*Uid:.*0/.*root.*Gid:.*0/.*root\" -ne 0 ";stat /etc/cron.daily | grep "0*00.*Uid:.*0/.*root.*Gid:.*0/.*root"; fi
echo "######################################"
else
echo "{\"5.1.4. Cấu hình phân quyền cho file /etc/cron.daily\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện các câu lệnh sau để đặt chủ sở hữu và quyền cho file /etc/cron.weekly:
# chown root:root /etc/cron.weekly
# chmod og-rwx /etc/cron.weekly
if [ $(stat /etc/cron.weekly | grep "0*00.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then
echo "{\"5.1.5. Cấu hình phân quyền cho file /etc/cron.weekly\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để đặt chủ sở hữu và quyền cho file /etc/cron.weekly:
# chown root:root /etc/cron.weekly
# chmod og-rwx /etc/cron.weekly"
if [ $(stat /etc/cron.weekly | grep "0*00.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat /etc/cron.weekly | grep \"0*00.*Uid:.*0/.*root.*Gid:.*0/.*root\" -ne 0 ";stat /etc/cron.weekly | grep "0*00.*Uid:.*0/.*root.*Gid:.*0/.*root"; fi
echo "######################################"
else
echo "{\"5.1.5. Cấu hình phân quyền cho file /etc/cron.weekly\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện các câu lệnh sau để đặt chủ sở hữu và quyền cho file /etc/cron.monthly:
# chown root:root /etc/cron.monthly
# chmod og-rwx /etc/cron.monthly
if [ $(stat /etc/cron.monthly | grep "0*00.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then
echo "{\"5.1.6. Cấu hình phân quyền cho file /etc/cron.monthly\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để đặt chủ sở hữu và quyền cho file /etc/cron.monthly:
# chown root:root /etc/cron.monthly
# chmod og-rwx /etc/cron.monthly"
if [ $(stat /etc/cron.monthly | grep "0*00.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat /etc/cron.monthly | grep \"0*00.*Uid:.*0/.*root.*Gid:.*0/.*root\" -ne 0 ";stat /etc/cron.monthly | grep "0*00.*Uid:.*0/.*root.*Gid:.*0/.*root"; fi
echo "######################################"
else
echo "{\"5.1.6. Cấu hình phân quyền cho file /etc/cron.monthly\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện câu lệnh sau để đặt chủ sở hữu và quyền cho file /etc/cron.d:
# chown root:root /etc/cron.d
# chmod og-rwx /etc/cron.d
if [ $(stat /etc/cron.d | grep "0*00.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then
echo "{\"5.1.7. Cấu hình phân quyền cho file /etc/cron.d\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để đặt chủ sở hữu và quyền cho file /etc/cron.d:
# chown root:root /etc/cron.d
# chmod og-rwx /etc/cron.d"
if [ $(stat /etc/cron.d | grep "0*00.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat /etc/cron.d | grep \"0*00.*Uid:.*0/.*root.*Gid:.*0/.*root\" -ne 0 ";stat /etc/cron.d | grep "0*00.*Uid:.*0/.*root.*Gid:.*0/.*root"; fi
echo "######################################"
else
echo "{\"5.1.7. Cấu hình phân quyền cho file /etc/cron.d\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện các câu lệnh sau để xóa /etc/cron.deny và /etc/at.deny, tạo và đặt quyền và chủ sở hữu cho /etc/cron.allow và /etc/at.allow:
# rm /etc/cron.deny
# rm /etc/at.deny
# touch /etc/cron.allow
# touch /etc/at.allow
# chmod o-rwx /etc/cron.allow
# chmod g-wx /etc/cron.allow
# chmod o-rwx /etc/at.allow
# chmod g-wx /etc/at.allow
# chown root:root /etc/cron.allow
# chown root:root /etc/at.allow
if [ -e "/etc/cron.deny" ] || [ -e "/etc/at.deny" ] || [ $(stat /etc/cron.allow 2>/dev/null | grep "0*[04]0.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ] || [ $(stat /etc/at.allow 2>/dev/null | grep "0*[04]0.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then
echo "{\"5.1.8. Cấu hình at/cron hạn chế chỉ cho người dùng được ủy quyền\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để xóa /etc/cron.deny và /etc/at.deny, tạo và đặt quyền và chủ sở hữu cho /etc/cron.allow và /etc/at.allow:
# rm /etc/cron.deny
# rm /etc/at.deny
# touch /etc/cron.allow
# touch /etc/at.allow
# chmod o-rwx /etc/cron.allow
# chmod g-wx /etc/cron.allow
# chmod o-rwx /etc/at.allow
# chmod g-wx /etc/at.allow
# chown root:root /etc/cron.allow
# chown root:root /etc/at.allow"
if [ -e "/etc/cron.deny" ]; then echo "-------------------";echo "Directory /etc/cron.deny exists"; fi
if [ -e "/etc/at.deny" ]; then echo "-------------------";echo "Directory /etc/at.deny exists"; fi
if [ $(stat /etc/cron.allow 2>/dev/null | grep "0*[04]0.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat /etc/cron.allow 2>/dev/null | grep \"0*[04]0.*Uid:.*0/.*root.*Gid:.*0/.*root\" -ne 0 ";stat /etc/cron.allow 2>/dev/null | grep "0*[04]0.*Uid:.*0/.*root.*Gid:.*0/.*root"; fi
if [ $(stat /etc/at.allow 2>/dev/null | grep "0*[04]0.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat /etc/at.allow 2>/dev/null | grep \"0*[04]0.*Uid:.*0/.*root.*Gid:.*0/.*root\" -ne 0 ";stat /etc/at.allow 2>/dev/null | grep "0*[04]0.*Uid:.*0/.*root.*Gid:.*0/.*root"; fi
echo "######################################"
else
echo "{\"5.1.8. Cấu hình at/cron hạn chế chỉ cho người dùng được ủy quyền\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện các câu lệnh sau để đặt chủ sở hữu và quyền cho file /etc/ssh/sshd_config:
# chown root:root /etc/ssh/sshd_config
# chmod og-rwx /etc/ssh/sshd_config
if [ $(stat /etc/ssh/sshd_config | grep "0*00.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then
echo "{\"5.2.1. Cấu hình phân quyền cho file /etc/ssh/sshd_config\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để đặt chủ sở hữu và quyền cho file /etc/ssh/sshd_config:
# chown root:root /etc/ssh/sshd_config
# chmod og-rwx /etc/ssh/sshd_config"
if [ $(stat /etc/ssh/sshd_config | grep "0*00.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat /etc/ssh/sshd_config | grep \"0*00.*Uid:.*0/.*root.*Gid:.*0/.*root\" -ne 0 ";stat /etc/ssh/sshd_config | grep "0*00.*Uid:.*0/.*root.*Gid:.*0/.*root"; fi
echo "######################################"
else
echo "{\"5.2.1. Cấu hình phân quyền cho file /etc/ssh/sshd_config\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện các câu lệnh sau để đặt chủ sở hữu và quyền cho các file SSH host private key:
# find /etc/ssh -xdev -type f -name 'ssh_host_*_key' -exec chmod u-x,g-wx,o-rwx {} \;
# find /etc/ssh -xdev -type f -name 'ssh_host_*_key' -exec chown root:ssh_keys {} \;
if [ $(find /etc/ssh -xdev -type f -name 'ssh_host_*_key' -exec stat {} \; | grep -E "Access:.*\(06[0-4]0.*Uid: \( *0/ +root\).*Gid: \( .*/( +root|ssh_keys)\)" | wc -l) -eq 0 ] || [ $(find /etc/ssh -xdev -type f -name 'ssh_host_*_key' -exec stat {} \; | grep -Ev "Access:.*\(06[0-4]0.*Uid: \( *0/ +root\).*Gid: \( .*/( +root|ssh_keys)\)" | grep "Access:.*Uid.*Gid" | wc -l) -ne 0 ]; then
echo "{\"5.2.2. Cấu hình phân quyền cho các file SSH private host key\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để đặt chủ sở hữu và quyền cho các file SSH host private key:
# find /etc/ssh -xdev -type f -name 'ssh_host_*_key' -exec chmod u-x,g-wx,o-rwx {} \;
# find /etc/ssh -xdev -type f -name 'ssh_host_*_key' -exec chown root:ssh_keys {} \;"
if [ $(find /etc/ssh -xdev -type f -name 'ssh_host_*_key' -exec stat {} \; | grep -E "Access:.*\(06[0-4]0.*Uid: \( *0/ +root\).*Gid: \( .*/( +root|ssh_keys)\)" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#find /etc/ssh -xdev -type f -name 'ssh_host_*_key' -exec stat {} \; | grep -E \"Access:.*\(06[0-4]0.*Uid: \( *0/ +root\).*Gid: \( .*/( +root|ssh_keys)\)\" -ne 0 ";find /etc/ssh -xdev -type f -name 'ssh_host_*_key' -exec stat {} \; | grep -E "Access:.*\(06[0-4]0.*Uid: \( *0/ +root\).*Gid: \( .*/( +root|ssh_keys)\)"; fi
if [ $(find /etc/ssh -xdev -type f -name 'ssh_host_*_key' -exec stat {} \; | grep -Ev "Access:.*\(06[0-4]0.*Uid: \( *0/ +root\).*Gid: \( .*/( +root|ssh_keys)\)" | grep "Access:.*Uid.*Gid" | wc -l) -ne 0 ]; then echo "-------------------"; echo "#find /etc/ssh -xdev -type f -name 'ssh_host_*_key' -exec stat {} \; | grep -Ev \"Access:.*\(06[0-4]0.*Uid: \( *0/ +root\).*Gid: \( .*/( +root|ssh_keys)\)\" | grep \"Access:.*Uid.*Gid\" -eq 0 ";find /etc/ssh -xdev -type f -name 'ssh_host_*_key' -exec stat {} \; | grep -Ev "Access:.*\(06[0-4]0.*Uid: \( *0/ +root\).*Gid: \( .*/( +root|ssh_keys)\)" | grep "Access:.*Uid.*Gid"; fi
echo "######################################"
else
echo "{\"5.2.2. Cấu hình phân quyền cho các file SSH private host key\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện các câu lệnh sau để đặt quyền và chủ sở hữu cho các file SSH host public key:
# find /etc/ssh -xdev -type f -name 'ssh_host_*_key.pub' -exec chmod u-x,go-wx {} \;
# find /etc/ssh -xdev -type f -name 'ssh_host_*_key.pub' -exec chown root:root {} \;
if [ $(find /etc/ssh -xdev -type f -name 'ssh_host_*_key.pub' -exec stat {} \; | grep -E "Access:.*\(06[0-4][0-4].*Uid: \( *0/ +root\).*Gid: \( .*/( +root|ssh_keys)\)" | wc -l) -eq 0 ] || [ $(find /etc/ssh -xdev -type f -name 'ssh_host_*_key.pub' -exec stat {} \; | grep -Ev "Access:.*\(06[0-4][0-4].*Uid: \( *0/ +root\).*Gid: \( .*/( +root|ssh_keys)\)" | grep "Access:.*Uid.*Gid" | wc -l) -ne 0 ]; then
echo "{\"5.2.3. Cấu hình phân quyền cho các file SSH public host key\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để đặt quyền và chủ sở hữu cho các file SSH host public key:
# find /etc/ssh -xdev -type f -name 'ssh_host_*_key.pub' -exec chmod u-x,go-wx {} \;
# find /etc/ssh -xdev -type f -name 'ssh_host_*_key.pub' -exec chown root:root {} \;"
if [ $(find /etc/ssh -xdev -type f -name 'ssh_host_*_key.pub' -exec stat {} \; | grep -E "Access:.*\(06[0-4][0-4].*Uid: \( *0/ +root\).*Gid: \( .*/( +root|ssh_keys)\)" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#find /etc/ssh -xdev -type f -name 'ssh_host_*_key.pub' -exec stat {} \; | grep -E \"Access:.*\(06[0-4][0-4].*Uid: \( *0/ +root\).*Gid: \( .*/( +root|ssh_keys)\)\" -ne 0 ";find /etc/ssh -xdev -type f -name 'ssh_host_*_key.pub' -exec stat {} \; | grep -E "Access:.*\(06[0-4][0-4].*Uid: \( *0/ +root\).*Gid: \( .*/( +root|ssh_keys)\)"; fi
if [ $(find /etc/ssh -xdev -type f -name 'ssh_host_*_key.pub' -exec stat {} \; | grep -Ev "Access:.*\(06[0-4][0-4].*Uid: \( *0/ +root\).*Gid: \( .*/( +root|ssh_keys)\)" | grep "Access:.*Uid.*Gid" | wc -l) -ne 0 ]; then echo "-------------------"; echo "#find /etc/ssh -xdev -type f -name 'ssh_host_*_key.pub' -exec stat {} \; | grep -Ev \"Access:.*\(06[0-4][0-4].*Uid: \( *0/ +root\).*Gid: \( .*/( +root|ssh_keys)\)\" | grep \"Access:.*Uid.*Gid\" -eq 0 ";find /etc/ssh -xdev -type f -name 'ssh_host_*_key.pub' -exec stat {} \; | grep -Ev "Access:.*\(06[0-4][0-4].*Uid: \( *0/ +root\).*Gid: \( .*/( +root|ssh_keys)\)" | grep "Access:.*Uid.*Gid"; fi
echo "######################################"
else
echo "{\"5.2.3. Cấu hình phân quyền cho các file SSH public host key\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# AllowUsers <list of users>
# # Hoặc
# AllowGroups <list of groups>
# # Hoặc
# DenyUsers <list of users>
# # Hoặc
# DenyGroups <list of groups>
if [ $(sshd -T | grep -E '^\h*(allow|deny)(users|groups)\s+\S+' | wc -l) -eq 0 ]; then
echo "{\"5.2.4. Cấu hình giới hạn truy cập cho máy chủ SSH\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# AllowUsers <list of users>
# # Hoặc
# AllowGroups <list of groups>
# # Hoặc
# DenyUsers <list of users>
# # Hoặc
# DenyGroups <list of groups>"
if [ $(sshd -T | grep -E '^\h*(allow|deny)(users|groups)\s+\S+' | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sshd -T | grep -E '^\h*(allow|deny)(users|groups)\s+\S+' -ne 0 ";sshd -T | grep -E '^\h*(allow|deny)(users|groups)\s+\S+'; fi
echo "######################################"
else
echo "{\"5.2.4. Cấu hình giới hạn truy cập cho máy chủ SSH\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/ssh/sshd_config và thêm một trong các tham số sau:
# LogLevel INFO
# # Hoặc
# LogLevel VERBOSE
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -P "^\h*loglevel.*(INFO|VERBOSE)" | wc -l) -eq 0 ] || [ $(grep -i 'loglevel' /etc/ssh/sshd_config | grep -Evi '(VERBOSE|INFO)' | wc -l) -ne 0 ]; then
echo "{\"5.2.5. Cấu hình LogLevel cho máy chủ SSH\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/ssh/sshd_config và thêm một trong các tham số sau:
# LogLevel INFO
# # Hoặc
# LogLevel VERBOSE"
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -P "^\h*loglevel.*(INFO|VERBOSE)" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sshd -T -C user=root -C host=\"\$(hostname)\" -C addr=\"\$(grep \$(hostname) /etc/hosts | awk '{print \$1}')\" | grep -P \"^\\h*loglevel.*(INFO|VERBOSE)\" -ne 0 ";sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -P "^\h*loglevel.*(INFO|VERBOSE)"; fi
if [ $(grep -i 'loglevel' /etc/ssh/sshd_config | grep -Evi '(VERBOSE|INFO)' | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -i 'loglevel' /etc/ssh/sshd_config | grep -Evi '(VERBOSE|INFO)' -eq 0 ";grep -i 'loglevel' /etc/ssh/sshd_config | grep -Evi '(VERBOSE|INFO)'; fi
echo "######################################"
else
echo "{\"5.2.5. Cấu hình LogLevel cho máy chủ SSH\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# UsePAM yes
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -i "usepam.*yes" | wc -l) -eq 0 ] || [ $(grep -Ei '^\h*UsePAM\s+no' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then
echo "{\"5.2.6. Cấu hình sử dụng SSH PAM\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# UsePAM yes"
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -i "usepam.*yes" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sshd -T -C user=root -C host=\"\$(hostname)\" -C addr=\"\$(grep \$(hostname) /etc/hosts | awk '{print \$1}')\" | grep -i \"usepam.*yes\" -ne 0 ";sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -i "usepam.*yes"; fi
if [ $(grep -Ei '^\h*UsePAM\s+no' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ei '^\h*UsePAM\s+no' /etc/ssh/sshd_config -eq 0 ";grep -Ei '^\h*UsePAM\s+no' /etc/ssh/sshd_config; fi
echo "######################################"
else
echo "{\"5.2.6. Cấu hình sử dụng SSH PAM\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# PermitRootLogin no
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep "permitrootlogin.*no" | wc -l) -eq 0 ] || [ $(grep -Ei '^\h*PermitRootLogin\s+yes' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then
echo "{\"5.2.7. Cấu hình vô hiệu hoá đăng nhập bằng root cho máy chủ SSH\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# PermitRootLogin no"
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep "permitrootlogin.*no" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sshd -T -C user=root -C host=\"\$(hostname)\" -C addr=\"\$(grep \$(hostname) /etc/hosts | awk '{print \$1}')\" | grep "permitrootlogin.*no" -ne 0 ";sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep "permitrootlogin.*no"; fi
if [ $(grep -Ei '^\h*PermitRootLogin\s+yes' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ei '^\h*PermitRootLogin\s+yes' /etc/ssh/sshd_config -eq 0 ";grep -Ei '^\h*PermitRootLogin\s+yes' /etc/ssh/sshd_config; fi
echo "######################################"
else
echo "{\"5.2.7. Cấu hình vô hiệu hoá đăng nhập bằng root cho máy chủ SSH\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# HostbasedAuthentication no
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep "hostbasedauthentication.*no" | wc -l) -eq 0 ] || [ $(grep -Ei '^\h*HostbasedAuthentication\s+yes' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then
echo "{\"5.2.8. Cấu hình vô hiệu hoá HostbasedAuthentication cho máy chủ SSH\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# HostbasedAuthentication no"
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep "hostbasedauthentication.*no" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sshd -T -C user=root -C host=\"\$(hostname)\" -C addr=\"\$(grep \$(hostname) /etc/hosts | awk '{print \$1}')\" | grep \"hostbasedauthentication.*no\" -ne 0 ";sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep "hostbasedauthentication.*no"; fi
if [ $(grep -Ei '^\h*HostbasedAuthentication\s+yes' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ei '^\h*HostbasedAuthentication\s+yes' /etc/ssh/sshd_config -eq 0 ";grep -Ei '^\h*HostbasedAuthentication\s+yes' /etc/ssh/sshd_config; fi
echo "######################################"
else
echo "{\"5.2.8. Cấu hình vô hiệu hoá HostbasedAuthentication cho máy chủ SSH\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# PermitEmptyPasswords no
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep "permitemptypasswords.*no" | wc -l) -eq 0 ] || [ $(grep -Ei '^\h*PermitEmptyPasswords\s+yes' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then
echo "{\"5.2.9. Cấu hình vô hiệu hoá PermitEmptyPasswords cho máy chủ SSH\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# PermitEmptyPasswords no"
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep "permitemptypasswords.*no" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sshd -T -C user=root -C host=\"\$(hostname)\" -C addr=\"\$(grep \$(hostname) /etc/hosts | awk '{print \$1}')\" | grep \"permitemptypasswords.*no\" -ne 0 ";sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep "permitemptypasswords.*no"; fi
if [ $(grep -Ei '^\h*PermitEmptyPasswords\s+yes' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ei '^\h*PermitEmptyPasswords\s+yes' /etc/ssh/sshd_config -eq 0 ";grep -Ei '^\h*PermitEmptyPasswords\s+yes' /etc/ssh/sshd_config; fi
echo "######################################"
else
echo "{\"5.2.9. Cấu hình vô hiệu hoá PermitEmptyPasswords cho máy chủ SSH\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# PermitUserEnvironment no
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep "permituserenvironment.*no" | wc -l) -eq 0 ] || [ $(grep -Ei '^\h*PermitUserEnvironment\s+yes' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then
echo "{\"5.2.10. Cấu hình vô hiệu hoá PermitUserEnviroment cho máy chủ SSH\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# PermitUserEnvironment no"
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep "permituserenvironment.*no" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sshd -T -C user=root -C host=\"\$(hostname)\" -C addr=\"\$(grep \$(hostname) /etc/hosts | awk '{print \$1}')\" | grep \"permituserenvironment.*no\" -ne 0 ";sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep "permituserenvironment.*no"; fi
if [ $(grep -Ei '^\h*PermitUserEnvironment\s+yes' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ei '^\h*PermitUserEnvironment\s+yes' /etc/ssh/sshd_config -eq 0 ";grep -Ei '^\h*PermitUserEnvironment\s+yes' /etc/ssh/sshd_config; fi
echo "######################################"
else
echo "{\"5.2.10. Cấu hình vô hiệu hoá PermitUserEnviroment cho máy chủ SSH\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# IgnoreRhosts yes
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep "ignorerhosts.*yes" | wc -l) -eq 0 ] || [ $(grep -Ei '^\h*ignorerhosts\s+no\b' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then
echo "{\"5.2.11. Cấu hình vô hiệu hoá IgnoreRhosts cho máy chủ SSH\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# IgnoreRhosts yes"
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep "ignorerhosts.*yes" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sshd -T -C user=root -C host=\"\$(hostname)\" -C addr=\"\$(grep \$(hostname) /etc/hosts | awk '{print \$1}')\" | grep \"ignorerhosts.*yes\" -ne 0 ";sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep "ignorerhosts.*yes"; fi
if [ $(grep -Ei '^\h*ignorerhosts\s+no\b' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ei '^\h*ignorerhosts\s+no\b' /etc/ssh/sshd_config -eq 0 ";grep -Ei '^\h*ignorerhosts\s+no\b' /etc/ssh/sshd_config; fi
echo "######################################"
else
echo "{\"5.2.11. Cấu hình vô hiệu hoá IgnoreRhosts cho máy chủ SSH\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# X11Forwarding no
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -i "x11forwarding.*no" | wc -l) -eq 0 ] || [ $(grep -Ei '^\h*x11forwarding\s+yes' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then
echo "{\"5.2.12. Cấu hình vô hiệu hoá X11 Forwarding cho máy chủ SSH\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# X11Forwarding no"
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -i "x11forwarding.*no" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sshd -T -C user=root -C host=\"\$(hostname)\" -C addr=\"\$(grep \$(hostname) /etc/hosts | awk '{print \$1}')\" | grep -i \"x11forwarding.*no\" -ne 0 ";sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -i "x11forwarding.*no"; fi
if [ $(grep -Ei '^\h*x11forwarding\s+yes' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ei '^\h*x11forwarding\s+yes' /etc/ssh/sshd_config -eq 0 ";grep -Ei '^\h*x11forwarding\s+yes' /etc/ssh/sshd_config; fi
echo "######################################"
else
echo "{\"5.2.12. Cấu hình vô hiệu hoá X11 Forwarding cho máy chủ SSH\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# AllowTcpForwarding no
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -i "allowtcpforwarding.*no" | wc -l) -eq 0 ] || [ $(grep -Ei '^\h*AllowTcpForwarding\s+yes' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then
echo "{\"5.2.13. Cấu hình vô hiệu hoá SSH AllowTcpForwarding\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# AllowTcpForwarding no"
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -i "allowtcpforwarding.*no" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sshd -T -C user=root -C host=\"\$(hostname)\" -C addr=\"\$(grep \$(hostname) /etc/hosts | awk '{print \$1}')\" | grep -i \"allowtcpforwarding.*no\" -ne 0 ";sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -i "allowtcpforwarding.*no"; fi
if [ $(grep -Ei '^\h*AllowTcpForwarding\s+yes' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ei '^\h*AllowTcpForwarding\s+yes' /etc/ssh/sshd_config -eq 0 ";grep -Ei '^\h*AllowTcpForwarding\s+yes' /etc/ssh/sshd_config; fi
echo "######################################"
else
echo "{\"5.2.13. Cấu hình vô hiệu hoá SSH AllowTcpForwarding\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# Banner /etc/issue.net
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep "^banner.*/etc/issue.net" | wc -l) -eq 0 ] || [ $(grep -Ei '^\h*Banner\s+/etc/issue\.net' /etc/ssh/sshd_config | wc -l) -eq 0 ]; then
echo "{\"5.2.14. Cấu hình cảnh báo SSH\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# Banner /etc/issue.net"
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep "^banner.*/etc/issue.net" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sshd -T -C user=root -C host=\"\$(hostname)\" -C addr=\"\$(grep \$(hostname) /etc/hosts | awk '{print \$1}')\" | grep \"^banner.*/etc/issue.net\" -ne 0 ";sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep "^banner.*/etc/issue.net"; fi
if [ $(grep -Ei '^\h*Banner\s+/etc/issue\.net' /etc/ssh/sshd_config | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ei '^\h*Banner\s+/etc/issue\.net' /etc/ssh/sshd_config -ne 0 ";grep -Ei '^\h*Banner\s+/etc/issue\.net' /etc/ssh/sshd_config; fi
echo "######################################"
else
echo "{\"5.2.14. Cấu hình cảnh báo SSH\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau hoặc nhỏ hơn:
# MaxAuthTries 4
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep "maxauthtries\s[0-4]" | wc -l) -eq 0 ] || [ $(grep -Ei '^\h*maxauthtries\s+([5-9]|[1-9][0-9]+)' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then
echo "{\"5.2.15. Cấu hình SSH MaxAuthTries\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau hoặc nhỏ hơn:
# MaxAuthTries 4"
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep "maxauthtries\s[0-4]" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sshd -T -C user=root -C host=\"\$(hostname)\" -C addr=\"\$(grep \$(hostname) /etc/hosts | awk '{print \$1}')\" | grep \"maxauthtries\s[0-4]\" -ne 0 ";sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep "maxauthtries\s[0-4]"; fi
if [ $(grep -Ei '^\h*maxauthtries\s+([5-9]|[1-9][0-9]+)' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ei '^\h*maxauthtries\s+([5-9]|[1-9][0-9]+)' /etc/ssh/sshd_config -eq 0 ";grep -Ei '^\h*maxauthtries\s+([5-9]|[1-9][0-9]+)' /etc/ssh/sshd_config; fi
echo "######################################"
else
echo "{\"5.2.15. Cấu hình SSH MaxAuthTries\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# MaxStartups 10:30:60
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -Ei "maxstartups\s10:30:60" | wc -l) -eq 0 ] || [ $(grep -Ei '^\h*maxstartups\s+(((1[1-9]|[1-9][0-9][0-9]+):([0-9]+):([0-9]+))|(([0-9]+):(3[1-9]|[4-9][0-9]|[1-9][0-9][0-9]+):([0-9]+))|(([0-9]+):([0-9]+):(6[1-9]|[7-9][0-9]|[1-9][0-9][0-9]+)))' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then
echo "{\"5.2.16. Cấu hình SSH MaxStartups\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# MaxStartups 10:30:60"
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -Ei "maxstartups\s10:30:60" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sshd -T -C user=root -C host=\"\$(hostname)\" -C addr=\"\$(grep \$(hostname) /etc/hosts | awk '{print \$1}')\" | grep -Ei \"maxstartups\s10:30:60\" -ne 0 ";sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -Ei "maxstartups\s10:30:60"; fi
if [ $(grep -Ei '^\h*maxstartups\s+(((1[1-9]|[1-9][0-9][0-9]+):([0-9]+):([0-9]+))|(([0-9]+):(3[1-9]|[4-9][0-9]|[1-9][0-9][0-9]+):([0-9]+))|(([0-9]+):([0-9]+):(6[1-9]|[7-9][0-9]|[1-9][0-9][0-9]+)))' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ei '^\h*maxstartups\s+(((1[1-9]|[1-9][0-9][0-9]+):([0-9]+):([0-9]+))|(([0-9]+):(3[1-9]|[4-9][0-9]|[1-9][0-9][0-9]+):([0-9]+))|(([0-9]+):([0-9]+):(6[1-9]|[7-9][0-9]|[1-9][0-9][0-9]+)))' /etc/ssh/sshd_config -eq 0 ";grep -Ei '^\h*maxstartups\s+(((1[1-9]|[1-9][0-9][0-9]+):([0-9]+):([0-9]+))|(([0-9]+):(3[1-9]|[4-9][0-9]|[1-9][0-9][0-9]+):([0-9]+))|(([0-9]+):([0-9]+):(6[1-9]|[7-9][0-9]|[1-9][0-9][0-9]+)))' /etc/ssh/sshd_config; fi
echo "######################################"
else
echo "{\"5.2.16. Cấu hình SSH MaxStartups\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau hoặc nhỏ hơn:
# MaxSessions 10
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -Ei "maxsessions\s([1-9]|10)" | wc -l) -eq 0 ] || [ $(grep -Ei '^\h*MaxSessions\s+(0|1[1-9]|[2-9][0-9]|[1-9][0-9][0-9]+)' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then
echo "{\"5.2.17. Cấu hình SSH MaxSessions\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau hoặc nhỏ hơn:
# MaxSessions 10"
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -Ei "maxsessions\s([1-9]|10)" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sshd -T -C user=root -C host=\"\$(hostname)\" -C addr=\"\$(grep \$(hostname) /etc/hosts | awk '{print \$1}')\" | grep -Ei \"maxsessions\s([1-9]|10)\" -ne 0 ";sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -Ei "maxsessions\s([1-9]|10)"; fi
if [ $(grep -Ei '^\h*MaxSessions\s+(0|1[1-9]|[2-9][0-9]|[1-9][0-9][0-9]+)' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ei '^\h*MaxSessions\s+(0|1[1-9]|[2-9][0-9]|[1-9][0-9][0-9]+)' /etc/ssh/sshd_config -eq 0 ";grep -Ei '^\h*MaxSessions\s+(0|1[1-9]|[2-9][0-9]|[1-9][0-9][0-9]+)' /etc/ssh/sshd_config; fi
echo "######################################"
else
echo "{\"5.2.17. Cấu hình SSH MaxSessions\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau hoặc bé hơn:
# LoginGraceTime 60
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -E "logingracetime\s([1-9]|[1-5][0-9]|60)" | wc -l) -eq 0 ] || [ $(grep -Ei '^\h*LoginGraceTime\s+(0|6[1-9]|[7-9][0-9]|[1-9][0-9][0-9]+|[^1]m)' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then
echo "{\"5.2.18. Cấu hình SSH LoginGraceTime\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau hoặc bé hơn:
# LoginGraceTime 60"
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -E "logingracetime\s([1-9]|[1-5][0-9]|60)" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sshd -T -C user=root -C host=\"\$(hostname)\" -C addr=\"\$(grep \$(hostname) /etc/hosts | awk '{print \$1}')\" | grep -E \"logingracetime\s([1-9]|[1-5][0-9]|60)\" -ne 0 ";sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -E "logingracetime\s([1-9]|[1-5][0-9]|60)"; fi
if [ $(grep -Ei '^\h*LoginGraceTime\s+(0|6[1-9]|[7-9][0-9]|[1-9][0-9][0-9]+|[^1]m)' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ei '^\h*LoginGraceTime\s+(0|6[1-9]|[7-9][0-9]|[1-9][0-9][0-9]+|[^1]m)' /etc/ssh/sshd_config -eq 0 ";grep -Ei '^\h*LoginGraceTime\s+(0|6[1-9]|[7-9][0-9]|[1-9][0-9][0-9]+|[^1]m)' /etc/ssh/sshd_config; fi
echo "######################################"
else
echo "{\"5.2.18. Cấu hình SSH LoginGraceTime\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# ClientAliveInterval 900
# ClientAliveCountMax 0
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -E "clientaliveinterval\s([1-8][0-9][0-9]|900)" | wc -l) -eq 0 ] || [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -E "clientalivecountmax\s0" | wc -l) -eq 0 ] || [ $(grep -Ei '^\h*ClientAliveInterval\s+(0|9[0-9][1-9]|[1-9][0-9][0-9][0-9]+|1[6-9]m|[2-9][0-9]m|[1-9][0-9][0-9]+m)\b' /etc/ssh/sshd_config | wc -l) -ne 0 ] || [ $(grep -Ei '^\h*ClientAliveCountMax\s+([1-9]|[1-9][0-9]+)\b' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then
echo "{\"5.2.19. Cấu hình khoảng thời gian chờ không hoạt động cho máy chủ SSH\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/ssh/sshd_config và đặt tham số như sau:
# ClientAliveInterval 900
# ClientAliveCountMax 0"
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -E "clientaliveinterval\s([1-8][0-9][0-9]|900)" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sshd -T -C user=root -C host=\"\$(hostname)\" -C addr=\"\$(grep \$(hostname) /etc/hosts | awk '{print \$1}')\" | grep -E \"clientaliveinterval\s([1-8][0-9][0-9]|900)\" -ne 0 ";sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -E "clientaliveinterval\s([1-8][0-9][0-9]|900)"; fi
if [ $(sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -E "clientalivecountmax\s0" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#sshd -T -C user=root -C host=\"\$(hostname)\" -C addr=\"\$(grep \$(hostname) /etc/hosts | awk '{print \$1}')\" | grep -E \"clientalivecountmax\s0\" -ne 0 ";sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep -E "clientalivecountmax\s0"; fi
if [ $(grep -Ei '^\h*ClientAliveInterval\s+(0|9[0-9][1-9]|[1-9][0-9][0-9][0-9]+|1[6-9]m|[2-9][0-9]m|[1-9][0-9][0-9]+m)\b' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ei '^\h*ClientAliveInterval\s+(0|9[0-9][1-9]|[1-9][0-9][0-9][0-9]+|1[6-9]m|[2-9][0-9]m|[1-9][0-9][0-9]+m)\b' /etc/ssh/sshd_config -eq 0 ";grep -Ei '^\h*ClientAliveInterval\s+(0|9[0-9][1-9]|[1-9][0-9][0-9][0-9]+|1[6-9]m|[2-9][0-9]m|[1-9][0-9][0-9]+m)\b' /etc/ssh/sshd_config; fi
if [ $(grep -Ei '^\h*ClientAliveCountMax\s+([1-9]|[1-9][0-9]+)\b' /etc/ssh/sshd_config | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ei '^\h*ClientAliveCountMax\s+([1-9]|[1-9][0-9]+)\b' /etc/ssh/sshd_config -eq 0 ";grep -Ei '^\h*ClientAliveCountMax\s+([1-9]|[1-9][0-9]+)\b' /etc/ssh/sshd_config; fi
echo "######################################"
else
echo "{\"5.2.19. Cấu hình khoảng thời gian chờ không hoạt động cho máy chủ SSH\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/ssh/sshd_config và thêm/thay đổi dòng MACs để chứa danh sách MAC được chấp thuận, ví dụ:
# MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256
if [ $(grep "^MACs.*hmac" /etc/ssh/sshd_config | wc -l) -eq 0 ]; then
echo "{\"5.2.20. Cấu hình các thuật toán MAC được cho phép\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/ssh/sshd_config và thêm/thay đổi dòng MACs để chứa danh sách MAC được chấp thuận, ví dụ:
# MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256"
if [ $(grep "^MACs.*hmac" /etc/ssh/sshd_config | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep \"^MACs.*hmac\" /etc/ssh/sshd_config -ne 0 ";grep "^MACs.*hmac" /etc/ssh/sshd_config; fi
echo "######################################"
else
echo "{\"5.2.20. Cấu hình các thuật toán MAC được cho phép\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/pam.d/password-auth và /etc/pam.d/system-auth để bao gồm các tùy chọn phù hợp cho pam_pwquality.so và tuân thủ chính sách của tổ chức:
# password requisite pam_pwquality.so try_first_pass local_users_only enforce_for_root retry=3
# Chỉnh sửa file /etc/security/pwquality.conf để thêm hoặc cập nhật một trong những thiết lập sau:
# minlen = 8
# minclass = 4
# # Hoặc
# minlen = 8
# dcredit = -1
# ucredit = -1
# ocredit = -1
# lcredit = -1
# *Lưu ý: Các thiết lập trong file /etc/security/pwquality.conf phải sử dụng dấu cách xung quanh dấu “=”.
if [ $(grep "^password.*requisite.*pam_pwquality\.so.*try_first_pass.*local_users_only.*enforce_for_root.*retry=3" /etc/pam.d/system-auth | wc -l) -eq 0 ] || [ $(grep "^password.*requisite.*pam_pwquality\.so.*try_first_pass.*local_users_only.*enforce_for_root.*retry=3" /etc/pam.d/password-auth | wc -l) -eq 0 ] || [ $(grep -P "^\h*minlen = ([8-9]|[1-9][0-9])" /etc/security/pwquality.conf | wc -l) -eq 0 ] || [[ ($(grep "^minclass = 4" /etc/security/pwquality.conf | wc -l) -eq 0 && ($(grep "^dcredit = -1" /etc/security/pwquality.conf | wc -l) -eq 0 || $(grep "^ucredit = -1" /etc/security/pwquality.conf | wc -l) -eq 0 || $(grep "^ocredit = -1" /etc/security/pwquality.conf | wc -l) -eq 0 || $(grep "^lcredit = -1" /etc/security/pwquality.conf | wc -l) -eq 0)) ]]; then
echo "{\"5.3.1. Cấu hình điều kiện tạo mật khẩu\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/pam.d/password-auth và /etc/pam.d/system-auth để bao gồm các tùy chọn phù hợp cho pam_pwquality.so và tuân thủ chính sách của tổ chức:
# password requisite pam_pwquality.so try_first_pass local_users_only enforce_for_root retry=3
# Chỉnh sửa file /etc/security/pwquality.conf để thêm hoặc cập nhật một trong những thiết lập sau:
# minlen = 8
# minclass = 4
# # Hoặc
# minlen = 8
# dcredit = -1
# ucredit = -1
# ocredit = -1
# lcredit = -1
# *Lưu ý: Các thiết lập trong file /etc/security/pwquality.conf phải sử dụng dấu cách xung quanh dấu “=”."
if [ $(grep "^password.*requisite.*pam_pwquality\.so.*try_first_pass.*local_users_only.*enforce_for_root.*retry=3" /etc/pam.d/system-auth | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep \"^password.*requisite.*pam_pwquality\.so.*try_first_pass.*local_users_only.*enforce_for_root.*retry=3\" /etc/pam.d/system-auth -ne 0 ";grep "^password.*requisite.*pam_pwquality\.so.*try_first_pass.*local_users_only.*enforce_for_root.*retry=3" /etc/pam.d/system-auth; fi
if [ $(grep "^password.*requisite.*pam_pwquality\.so.*try_first_pass.*local_users_only.*enforce_for_root.*retry=3" /etc/pam.d/password-auth | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep \"^password.*requisite.*pam_pwquality\.so.*try_first_pass.*local_users_only.*enforce_for_root.*retry=3\" /etc/pam.d/password-auth -ne 0 ";grep "^password.*requisite.*pam_pwquality\.so.*try_first_pass.*local_users_only.*enforce_for_root.*retry=3" /etc/pam.d/password-auth; fi
if [ $(grep -P "^\h*minlen = ([8-9]|[1-9][0-9])" /etc/security/pwquality.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*minlen = ([8-9]|[1-9][0-9])\" /etc/security/pwquality.conf -ne 0 ";grep -P "^\h*minlen = ([8-9]|[1-9][0-9])" /etc/security/pwquality.conf; fi
if [ $(grep "^minclass = 4" /etc/security/pwquality.conf | wc -l) -eq 0 ] && [[ ($(grep "^dcredit = -1" /etc/security/pwquality.conf | wc -l) -eq 0 || $(grep "^ucredit = -1" /etc/security/pwquality.conf | wc -l) -eq 0 || $(grep "^ocredit = -1" /etc/security/pwquality.conf | wc -l) -eq 0 || $(grep "^lcredit = -1" /etc/security/pwquality.conf | wc -l) -eq 0) ]]; then echo "-------------------"; echo "#grep \"^minclass = 4\" /etc/security/pwquality.conf -ne 0 ";grep "^minclass = 4" /etc/security/pwquality.conf; fi
if [ $(grep "^minclass = 4" /etc/security/pwquality.conf | wc -l) -eq 0 ] && [ $(grep "^dcredit = -1" /etc/security/pwquality.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep \"^dcredit = -1\" /etc/security/pwquality.conf -ne 0 ";grep "^dcredit = -1" /etc/security/pwquality.conf; fi
if [ $(grep "^minclass = 4" /etc/security/pwquality.conf | wc -l) -eq 0 ] && [ $(grep "^ucredit = -1" /etc/security/pwquality.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep \"^ucredit = -1\" /etc/security/pwquality.conf -ne 0 ";grep "^ucredit = -1" /etc/security/pwquality.conf; fi
if [ $(grep "^minclass = 4" /etc/security/pwquality.conf | wc -l) -eq 0 ] && [ $(grep "^ocredit = -1" /etc/security/pwquality.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep \"^ocredit = -1\" /etc/security/pwquality.conf -ne 0 ";grep "^ocredit = -1" /etc/security/pwquality.conf; fi
if [ $(grep "^minclass = 4" /etc/security/pwquality.conf | wc -l) -eq 0 ] && [ $(grep "^lcredit = -1" /etc/security/pwquality.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep \"^lcredit = -1\" /etc/security/pwquality.conf -ne 0 ";grep "^lcredit = -1" /etc/security/pwquality.conf; fi
echo "######################################"
else
echo "{\"5.3.1. Cấu hình điều kiện tạo mật khẩu\" : \"PASSED\"}"
fi
############################################################################
# Đối với phiên bản 8.2 trở lên: Chỉnh sửa file /etc/security/faillock.conf để thêm hoặc cập nhật những thiết lập sau:
# deny = 5
# unlock_time = 900
# Đối với phiên bản 8.1 trở về trước: Chỉnh sửa file /etc/pam.d/password-auth và file /etc/pam.d/system-auth để thêm hoặc cập nhật những thiết lập sau:
# auth required pam_faillock.so preauth silent deny=5 unlock_time=900
# auth [default=die] pam_faillock.so authfail deny=5 unlock_time=900
# *Lưu ý: Nếu người dùng bị khoá do đã thử quá số lần cho phép, được định danh ở tham số deny= trong mô-đun pam_faillock.so, người dùng đó có thể được mở khoá bằng cách sử dụng lệnh faillock -u reset. Câu lệnh này sẽ reset lại số lần thử không thành công xuống 0.
if [[ ($(grep -P "^\h*deny.*=.*5" /etc/security/faillock.conf | wc -l) -eq 0 || $(grep -P "^\h*unlock_time.*=.*900" /etc/security/faillock.conf | wc -l) -eq 0) && ($(grep -P "^\h*auth.*required.*pam_faillock.so.*preauth.*silent.*deny=5.*unlock_time=900" /etc/pam.d/password-auth | wc -l) -eq 0 || $(grep -P "^\h*auth\h*\[default=die\]\h*pam_faillock.so.*authfail.*deny=5.*unlock_time=900" /etc/pam.d/password-auth | wc -l) -eq 0 || $(grep -P "^\h*auth.*required.*pam_faillock.so.*preauth.*silent.*deny=5.*unlock_time=900" /etc/pam.d/system-auth | wc -l) -eq 0 || $(grep -P "^\h*auth\h*\[default=die\]\h*pam_faillock.so.*authfail.*deny=5.*unlock_time=900" /etc/pam.d/system-auth | wc -l) -eq 0) ]]; then
echo "{\"5.3.2. Cấu hình khoá truy cập do nhiều lần nhập mật khẩu thất bại\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Đối với phiên bản 8.2 trở lên: Chỉnh sửa file /etc/security/faillock.conf để thêm hoặc cập nhật những thiết lập sau:
# deny = 5
# unlock_time = 900
# Đối với phiên bản 8.1 trở về trước: Chỉnh sửa file /etc/pam.d/password-auth và file /etc/pam.d/system-auth để thêm hoặc cập nhật những thiết lập sau:
# auth required pam_faillock.so preauth silent deny=5 unlock_time=900
# auth required pam_faillock.so authfail deny=5 unlock_time=900
# *Lưu ý: Nếu người dùng bị khoá do đã thử quá số lần cho phép, được định danh ở tham số deny= trong mô-đun pam_faillock.so, người dùng đó có thể được mở khoá bằng cách sử dụng lệnh faillock -u -reset. Câu lệnh này sẽ reset lại số lần thử không thành công xuống 0."
if [ $(grep -P "^\h*deny.*=.*5" /etc/security/faillock.conf | wc -l) -eq 0 ] && [[ ($(grep -P "^\h*auth.*required.*pam_faillock.so.*preauth.*silent.*deny=5.*unlock_time=900" /etc/pam.d/password-auth | wc -l) -eq 0 || $(grep -P "^\h*auth\h*\[default=die\]\h*pam_faillock.so.*authfail.*deny=5.*unlock_time=900" /etc/pam.d/password-auth | wc -l) -eq 0 || $(grep -P "^\h*auth.*required.*pam_faillock.so.*preauth.*silent.*deny=5.*unlock_time=900" /etc/pam.d/system-auth | wc -l) -eq 0 || $(grep -P "^\h*auth\h*\[default=die\]\h*pam_faillock.so.*authfail.*deny=5.*unlock_time=900" /etc/pam.d/system-auth | wc -l) -eq 0) ]]; then echo "-------------------"; echo "#grep -P \"^\\h*deny.*=.*5\" /etc/security/faillock.conf -ne 0 ";grep -P "^\h*deny.*=.*5" /etc/security/faillock.conf; fi
if [ $(grep -P "^\h*unlock_time.*=.*900" /etc/security/faillock.conf | wc -l) -eq 0 ] && [[ ($(grep -P "^\h*auth.*required.*pam_faillock.so.*preauth.*silent.*deny=5.*unlock_time=900" /etc/pam.d/password-auth | wc -l) -eq 0 || $(grep -P "^\h*auth\h*\[default=die\]\h*pam_faillock.so.*authfail.*deny=5.*unlock_time=900" /etc/pam.d/password-auth | wc -l) -eq 0 || $(grep -P "^\h*auth.*required.*pam_faillock.so.*preauth.*silent.*deny=5.*unlock_time=900" /etc/pam.d/system-auth | wc -l) -eq 0 || $(grep -P "^\h*auth\h*\[default=die\]\h*pam_faillock.so.*authfail.*deny=5.*unlock_time=900" /etc/pam.d/system-auth | wc -l) -eq 0) ]]; then echo "-------------------"; echo "#grep -P \"^\\h*unlock_time.*=.*900\" /etc/security/faillock.conf -ne 0 ";grep -P "^\h*unlock_time.*=.*900" /etc/security/faillock.conf; fi
if [[ ($(grep -P "^\h*deny.*=.*5" /etc/security/faillock.conf | wc -l) -eq 0 || $(grep -P "^\h*unlock_time.*=.*900" /etc/security/faillock.conf | wc -l) -eq 0) ]] && [ $(grep -P "^\h*auth.*required.*pam_faillock.so.*preauth.*silent.*deny=5.*unlock_time=900" /etc/pam.d/password-auth | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*auth.*required.*pam_faillock.so.*preauth.*silent.*deny=5.*unlock_time=900\" /etc/pam.d/password-auth -ne 0 ";grep -P "^\h*auth.*required.*pam_faillock.so.*preauth.*silent.*deny=5.*unlock_time=900" /etc/pam.d/password-auth; fi
if [[ ($(grep -P "^\h*deny.*=.*5" /etc/security/faillock.conf | wc -l) -eq 0 || $(grep -P "^\h*unlock_time.*=.*900" /etc/security/faillock.conf | wc -l) -eq 0) ]] && [ $(grep -P "^\h*auth\h*\[default=die\]\h*pam_faillock.so.*authfail.*deny=5.*unlock_time=900" /etc/pam.d/password-auth | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*auth\\h*\\[default=die\\]\\h*pam_faillock.so.*authfail.*deny=5.*unlock_time=900\" /etc/pam.d/password-auth -ne 0 ";grep -P "^\h*auth\h*\[default=die\]\h*pam_faillock.so.*authfail.*deny=5.*unlock_time=900" /etc/pam.d/password-auth; fi
if [[ ($(grep -P "^\h*deny.*=.*5" /etc/security/faillock.conf | wc -l) -eq 0 || $(grep -P "^\h*unlock_time.*=.*900" /etc/security/faillock.conf | wc -l) -eq 0) ]] && [ $(grep -P "^\h*auth.*required.*pam_faillock.so.*preauth.*silent.*deny=5.*unlock_time=900" /etc/pam.d/system-auth | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*auth.*required.*pam_faillock.so.*preauth.*silent.*deny=5.*unlock_time=900\" /etc/pam.d/system-auth -ne 0 ";grep -P "^\h*auth.*required.*pam_faillock.so.*preauth.*silent.*deny=5.*unlock_time=900" /etc/pam.d/system-auth; fi
if [[ ($(grep -P "^\h*deny.*=.*5" /etc/security/faillock.conf | wc -l) -eq 0 || $(grep -P "^\h*unlock_time.*=.*900" /etc/security/faillock.conf | wc -l) -eq 0) ]] && [ $(grep -P "^\h*auth\h*\[default=die\]\h*pam_faillock.so.*authfail.*deny=5.*unlock_time=900" /etc/pam.d/system-auth | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*auth\\h*\\[default=die\\]\\h*pam_faillock.so.*authfail.*deny=5.*unlock_time=900\" /etc/pam.d/system-auth -ne 0 ";grep -P "^\h*auth\h*\[default=die\]\h*pam_faillock.so.*authfail.*deny=5.*unlock_time=900" /etc/pam.d/system-auth; fi
echo "######################################"
else
echo "{\"5.3.2. Cấu hình khoá truy cập do nhiều lần nhập mật khẩu thất bại\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/pam.d/system-auth thêm hoặc chỉnh sửa tham số remember trong các dòng có chứa pam_unix.so và pwhistory.so thành 5 như sau:
# password sufficient pam_unix.so remember=5
# password required pam_pwhistory.so remember=5
if [ $(grep -P "^\h*password.*sufficient.*pam_unix\.so.*remember.*5" /etc/pam.d/system-auth | wc -l) -eq 0 ] || [ $(grep -P "^\h*password.*required.*pam_pwhistory\.so.*remember.*5" /etc/pam.d/system-auth | wc -l) -eq 0 ] || [ $(grep -Ev "^\s+*password.*sufficient.*pam_unix\.so.*remember.*5|^\s+*password.*required.*pam_pwhistory\.so.*remember.*5" /etc/pam.d/system-auth | grep -E "password.*(pam_unix\.so|pwhistory\.so)" | wc -l) -ne 0 ]; then
echo "{\"5.3.3. Giới hạn việc sử dụng lại mật khẩu\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/pam.d/system-auth thêm hoặc chỉnh sửa tham số remember trong các dòng có chứa pam_unix.so và pwhistory.so thành 5 như sau:
# password sufficient pam_unix.so remember=5
# password required pam_pwhistory.so remember=5"
if [ $(grep -P "^\h*password.*sufficient.*pam_unix\.so.*remember.*5" /etc/pam.d/system-auth | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*password.*sufficient.*pam_unix\.so.*remember.*5\" /etc/pam.d/system-auth -ne 0 ";grep -P "^\h*password.*sufficient.*pam_unix\.so.*remember.*5" /etc/pam.d/system-auth; fi
if [ $(grep -P "^\h*password.*required.*pam_pwhistory\.so.*remember.*5" /etc/pam.d/system-auth | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*password.*required.*pam_pwhistory\.so.*remember.*5\" /etc/pam.d/system-auth -ne 0 ";grep -P "^\h*password.*required.*pam_pwhistory\.so.*remember.*5" /etc/pam.d/system-auth; fi
if [ $(grep -Ev "^\s+*password.*sufficient.*pam_unix\.so.*remember.*5|^\s+*password.*required.*pam_pwhistory\.so.*remember.*5" /etc/pam.d/system-auth | grep -E "password.*(pam_unix\.so|pwhistory\.so)" | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ev \"^\s+*password.*sufficient.*pam_unix\.so.*remember.*5|^\s+*password.*required.*pam_pwhistory\.so.*remember.*5\" /etc/pam.d/system-auth | grep -E \"password.*(pam_unix\.so|pwhistory\.so)\" -eq 0 ";grep -Ev "^\s+*password.*sufficient.*pam_unix\.so.*remember.*5|^\s+*password.*required.*pam_pwhistory\.so.*remember.*5" /etc/pam.d/system-auth | grep -E "password.*(pam_unix\.so|pwhistory\.so)"; fi
echo "######################################"
else
echo "{\"5.3.3. Giới hạn việc sử dụng lại mật khẩu\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/pam.d/password-auth và /etc/pam.d/system-auth để có tùy chọn sha512 cho pam_unix.so như dưới đây:
# password sufficient pam_unix.so sha512
# Đối với Centos 8:
# Chỉnh sửa /etc/libuser.conf thêm hoặc chỉnh sửa các tham số sau:
# crypt_style = sha512
# Chỉnh sửa /etc/login.defs thêm hoặc chỉnh sửa các tham số sau:
# ENCRYPT_METHOD SHA512
if [[ ($(grep -P "^\h*password.*sufficient.*pam_unix.so.*sha512" /etc/pam.d/password-auth | wc -l) -eq 0 || $(grep -P "^\h*password.*sufficient.*pam_unix.so.*sha512" /etc/pam.d/system-auth | wc -l) -eq 0) ]] && [[ ($(cat /etc/system-release | grep -E "\s[8-9].[0-9]" | wc -l) -eq 0 || $(grep -P "^\h*crypt_style.*=.*sha512" /etc/libuser.conf | wc -l) -eq 0 || $(grep -P "^\h*ENCRYPT_METHOD.*SHA512" /etc/login.defs | wc -l) -eq 0) ]]; then
echo "{\"5.3.4. Cấu hình thuật toán hash mật khẩu sang SHA-512\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/pam.d/password-auth và /etc/pam.d/system-auth để có tùy chọn sha512 cho pam_unix.so như dưới đây:
# password sufficient pam_unix.so sha512
# Đối với Centos 8:
# Chỉnh sửa /etc/libuser.conf thêm hoặc chỉnh sửa các tham số sau:
# crypt_style = sha512
# Chỉnh sửa /etc/login.defs thêm hoặc chỉnh sửa các tham số sau:
# ENCRYPT_METHOD SHA512"
if [ $(grep -P "^\h*password.*sufficient.*pam_unix.so.*sha512" /etc/pam.d/password-auth | wc -l) -eq 0 ] && [[ ($(cat /etc/system-release | grep -E "\s[8-9].[0-9]" | wc -l) -eq 0 || $(grep -P "^\h*crypt_style.*=.*sha512" /etc/libuser.conf | wc -l) -eq 0 || $(grep -P "^\h*ENCRYPT_METHOD.*SHA512" /etc/login.defs | wc -l) -eq 0) ]]; then echo "-------------------"; echo "#grep -P \"^\\h*password.*sufficient.*pam_unix.so.*sha512\" /etc/pam.d/password-auth -ne 0 ";grep -P "^\h*password.*sufficient.*pam_unix.so.*sha512" /etc/pam.d/password-auth; fi
if [ $(grep -P "^\h*password.*sufficient.*pam_unix.so.*sha512" /etc/pam.d/system-auth | wc -l) -eq 0 ] && [[ ($(cat /etc/system-release | grep -E "\s[8-9].[0-9]" | wc -l) -eq 0 || $(grep -P "^\h*crypt_style.*=.*sha512" /etc/libuser.conf | wc -l) -eq 0 || $(grep -P "^\h*ENCRYPT_METHOD.*SHA512" /etc/login.defs | wc -l) -eq 0) ]]; then echo "-------------------"; echo "#grep -P \"^\\h*password.*sufficient.*pam_unix.so.*sha512\" /etc/pam.d/system-auth -ne 0 ";grep -P "^\h*password.*sufficient.*pam_unix.so.*sha512" /etc/pam.d/system-auth; fi
if [[ ($(grep -P "^\h*password.*sufficient.*pam_unix.so.*sha512" /etc/pam.d/password-auth | wc -l) -eq 0 || $(grep -P "^\h*password.*sufficient.*pam_unix.so.*sha512" /etc/pam.d/system-auth | wc -l) -eq 0) ]] && [ $(grep -P "^\h*crypt_style.*=.*sha512" /etc/libuser.conf | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*crypt_style.*=.*sha512\" /etc/libuser.conf -ne 0 ";grep -P "^\h*crypt_style.*=.*sha512" /etc/libuser.conf; fi
if [[ ($(grep -P "^\h*password.*sufficient.*pam_unix.so.*sha512" /etc/pam.d/password-auth | wc -l) -eq 0 || $(grep -P "^\h*password.*sufficient.*pam_unix.so.*sha512" /etc/pam.d/system-auth | wc -l) -eq 0) ]] && [ $(grep -P "^\h*ENCRYPT_METHOD.*SHA512" /etc/login.defs | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*ENCRYPT_METHOD.*SHA512\" /etc/login.defs -ne 0 ";grep -P "^\h*ENCRYPT_METHOD.*SHA512" /etc/login.defs; fi
echo "######################################"
else
echo "{\"5.3.4. Cấu hình thuật toán hash mật khẩu sang SHA-512\" : \"PASSED\"}"
fi
############################################################################
# Đặt tham số PASS_MAX_DAYS trong file /etc/login.defs tuân theo chính sách của tổ chức:
# PASS_MAX_DAYS 365
# Chỉnh sửa tham số cho người dùng sử dụng mật khẩu bằng câu lệnh sau:
# chage --maxdays 365 <user>
if [ $(grep -P "^\h*PASS_MAX_DAYS.*(9[0-9]|[1-2][0-9][0-9]|3[0-6][0-9]|36[0-5])" /etc/login.defs | wc -l) -eq 0 ] || [ $(grep -E '^[^:]+:[^!*]' /etc/shadow | cut -d: -f1,5 | awk -F ':' '{if($2<90||$2>365) print}' | grep -v "root" | wc -l) -ne 0 ]; then
echo "{\"5.4.1.1. Cấu hình thời gian hết hạn sử dụng mật khẩu\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Đặt tham số PASS_MAX_DAYS trong file /etc/login.defs tuân theo chính sách của tổ chức:
# PASS_MAX_DAYS 180
# Chỉnh sửa tham số cho người dùng sử dụng mật khẩu bằng câu lệnh sau:
# chage --maxdays 180 <user>"
if [ $(grep -P "^\h*PASS_MAX_DAYS.*(9[0-9]|[1-2][0-9][0-9]|3[0-6][0-9]|36[0-5])" /etc/login.defs | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*PASS_MAX_DAYS.*(9[0-9]|[1-2][0-9][0-9]|3[0-6][0-9]|36[0-5])\" /etc/login.defs -ne 0 ";grep -P "^\h*PASS_MAX_DAYS.*(9[0-9]|[1-2][0-9][0-9]|3[0-6][0-9]|36[0-5])" /etc/login.defs; fi
if [ $(grep -E '^[^:]+:[^!*]' /etc/shadow | cut -d: -f1,5 | awk -F ':' '{if($2<90||$2>365) print}' | grep -v "root" | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -E '^[^:]+:[^!*]' /etc/shadow | cut -d: -f1,5 | awk -F ':' '{if(\$2<90||\$2>365) print}' | grep -v "root" -eq 0 ";grep -E '^[^:]+:[^!*]' /etc/shadow | cut -d: -f1,5 | awk -F ':' '{if($2<90||$2>365) print}' | grep -v "root"; fi
echo "######################################"
else
echo "{\"5.4.1.1. Cấu hình thời gian hết hạn sử dụng mật khẩu\" : \"PASSED\"}"
fi
############################################################################
# Đặt tham số PASS_MIIN_DAYS trong file /etc/login.defs là 7:
# PASS_MIN_DAYS 7
# Chỉnh sửa tham số cho người dùng sử dụng mật khẩu bằng câu lệnh sau:
# chage --mindays 7 <user>
if [ $(grep -P "^\h*PASS_MIN_DAYS.*7" /etc/login.defs | wc -l) -eq 0 ] || [ $(grep -P "^\h*[^:]+:[^\!*]" /etc/shadow | cut -d: -f1,4 | awk -F: '($2<7) {print}' | grep -v "root" | wc -l) -ne 0 ]; then
echo "{\"5.4.1.2. Cấu hình thời gian tối thiểu giữa những lần thay đổi mật khẩu\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Đặt tham số PASS_MIIN_DAYS trong file /etc/login.defs là 7:
# PASS_MIN_DAYS 7
# Chỉnh sửa tham số cho người dùng sử dụng mật khẩu bằng câu lệnh sau:
# chage --mindays 7 <user>"
if [ $(grep -P "^\h*PASS_MIN_DAYS.*7" /etc/login.defs | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*PASS_MIN_DAYS.*7\" /etc/login.defs -ne 0 ";grep -P "^\h*PASS_MIN_DAYS.*7" /etc/login.defs; fi
if [ $(grep -P "^\h*[^:]+:[^\!*]" /etc/shadow | cut -d: -f1,4 | awk -F: '($2<7) {print}' | grep -v "root" | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*[^:]+:[^\!*]\" /etc/shadow | cut -d: -f1,4 | awk -F: '(\$2<7) {print}' | grep -v \"root\" -eq 0 ";grep -P "^\h*[^:]+:[^\!*]" /etc/shadow | cut -d: -f1,4 | awk -F: '($2<7) {print}' | grep -v "root"; fi
echo "######################################"
else
echo "{\"5.4.1.2. Cấu hình thời gian tối thiểu giữa những lần thay đổi mật khẩu\" : \"PASSED\"}"
fi
############################################################################
# Đặt tham số PASS_WARN_AGE trong file /etc/login.defs là 7:
# PASS_WARN_AGE 7
# Chỉnh sửa tham số của người dùng sử dụng mật khẩu bằng câu lệnh sau:
# chage --warndays 7 <user>
if [ $(grep -P "^\h*PASS_WARN_AGE.*7" /etc/login.defs | wc -l) -eq 0 ] || [ $(grep -P "^\h*[^:]+:[^\!*]" /etc/shadow | cut -d: -f1,6 | awk -F: '($2<7) {print}' | wc -l) -ne 0 ]; then
echo "{\"5.4.1.3. Cấu hình thời gian cảnh báo mật khẩu hết hạn\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Đặt tham số PASS_WARN_AGE trong file /etc/login.defs là 7:
# PASS_WARN_AGE 7
# Chỉnh sửa tham số của người dùng sử dụng mật khẩu bằng câu lệnh sau:
# chage --warndays 7 <user>"
if [ $(grep -P "^\h*PASS_WARN_AGE.*7" /etc/login.defs | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*PASS_WARN_AGE.*7\" /etc/login.defs -ne 0 ";grep -P "^\h*PASS_WARN_AGE.*7" /etc/login.defs; fi
if [ $(grep -P "^\h*[^:]+:[^\!*]" /etc/shadow | cut -d: -f1,6 | awk -F: '($2<7) {print}' | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*[^:]+:[^\!*]\" /etc/shadow | cut -d: -f1,6 | awk -F: '(\$2<7) {print}' -eq 0 ";grep -P "^\h*[^:]+:[^\!*]" /etc/shadow | cut -d: -f1,6 | awk -F: '($2<7) {print}'; fi
echo "######################################"
else
echo "{\"5.4.1.3. Cấu hình thời gian cảnh báo mật khẩu hết hạn\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện câu lệnh sau dể đặt khoảng thời gian tài khoản không hoạt động là 30 ngày:
# useradd -D -f 30
# Chỉnh sửa thông số của người dùng sử dụng mật khẩu bằng câu lệnh sau:
# chage --inactive 30 <user>
if [ $(useradd -D | grep "INACTIVE.*30" | wc -l) -eq 0 ] || [ $(grep -Ev "^\+" /etc/shadow | awk -F: '( $2!="*" && $2!="!!" && $7>30 && $7!="") {print}' | wc -l) -ne 0 ]; then
echo "{\"5.4.1.4. Cấu hình thời gian khoá tài khoản không thay mật khẩu sau khi hết hạn\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau dể đặt khoảng thời gian tài khoản không hoạt động là 30 ngày:
# useradd -D -f 30
# Chỉnh sửa thông số của người dùng sử dụng mật khẩu bằng câu lệnh sau:
# chage --inactive 30 <user>"
if [ $(useradd -D | grep "INACTIVE.*30" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#useradd -D | grep \"INACTIVE.*30\" -ne 0 ";useradd -D | grep "INACTIVE.*30"; fi
if [ $(grep -Ev "^\+" /etc/shadow | awk -F: '( $2!="*" && $2!="!!" && $7>30 && $7!="") {print}' | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -Ev \"^\+\" /etc/shadow | awk -F: '( \$2!=\"*\" && \$2!=\"!!\" && \$7>30 && \$7!=\"\") {print}' -eq 0 ";grep -Ev "^\+" /etc/shadow | awk -F: '( $2!="*" && $2!="!!" && $7>30 && $7!="") {print}'; fi
echo "######################################"
else
echo "{\"5.4.1.4. Cấu hình thời gian khoá tài khoản không thay mật khẩu sau khi hết hạn\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện câu lệnh sau để liệt kê các tài khoản có thời giant hay đổi mật khẩu lần cuối không hợp lệ:
# awk -F: '/^[^:]+:[^!*]/{print $1}' /etc/shadow | while read -r usr; do change=$(date -d "$(chage --list $usr | grep '^Last password change' | cut -d: -f2 | grep -v 'never$')" +%s); if [[ "$change" -gt "$(date +%s)" ]]; then echo "User: \"$usr\" last password change was \"$(chage --list $usr | grep '^Last password change' | cut -d: -f2)\""; fi; done
# Tiến hành khoá tài khoản, hết hạn mật khẩu hoặc đặt lại mật khẩu các tài khoản được tìm thấy.
if [ $(awk -F: '/^[^:]+:[^!*]/{print $1}' /etc/shadow | while read -r usr; do change=$(date -d "$(chage --list $usr | grep '^Last password change' | cut -d: -f2 | grep -v 'never$')" +%s); if [[ "$change" -gt "$(date +%s)" ]]; then echo "User: \"$usr\" last password change was \"$(chage --list $usr | grep '^Last password change' | cut -d: -f2)\""; fi; done | wc -l) -ne 0 ]; then
echo "{\"5.4.1.5. Đảm bảo thời gian thay đổi mật khẩu lần cuối hợp lệ\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để liệt kê các tài khoản có thời giant hay đổi mật khẩu lần cuối không hợp lệ:
# awk -F: '/^[^:]+:[^!*]/{print \$1}' /etc/shadow | while read -r usr; do change=\$(date -d \"\$(chage --list \$usr | grep '^Last password change' | cut -d: -f2 | grep -v 'never\$')\" +%s); if [[ \"\$change\" -gt \"\$(date +%s)\" ]]; then echo \"User: \\\"\$usr\\\" last password change was \\\"\$(chage --list \$usr | grep '^Last password change' | cut -d: -f2)\\\"\"; fi; done
# Tiến hành khoá tài khoản, hết hạn mật khẩu hoặc đặt lại mật khẩu các tài khoản được tìm thấy."
if [ $(awk -F: '/^[^:]+:[^!*]/{print $1}' /etc/shadow | while read -r usr; do change=$(date -d "$(chage --list $usr | grep '^Last password change' | cut -d: -f2 | grep -v 'never$')" +%s); if [[ "$change" -gt "$(date +%s)" ]]; then echo "User: \"$usr\" last password change was \"$(chage --list $usr | grep '^Last password change' | cut -d: -f2)\""; fi; done | wc -l) -ne 0 ]; then echo "-------------------"; echo "#awk -F: '/^[^:]+:[^!*]/{print \$1}' /etc/shadow | while read -r usr; do change=\$(date -d \"\$(chage --list \$usr | grep '^Last password change' | cut -d: -f2 | grep -v 'never\$')\" +%s); if [[ \"\$change\" -gt \"\$(date +%s)\" ]]; then echo \"User: \\\"\$usr\\\" last password change was \\\"\$(chage --list \$usr | grep '^Last password change' | cut -d: -f2)\\\"\"; fi; done -eq 0 ";awk -F: '/^[^:]+:[^!*]/{print $1}' /etc/shadow | while read -r usr; do change=$(date -d "$(chage --list $usr | grep '^Last password change' | cut -d: -f2 | grep -v 'never$')" +%s);if [[ "$change" -gt "$(date +%s)" ]]; then echo "User: \"$usr\" last password change was \"$(chage --list $usr | grep '^Last password change' | cut -d: -f2)\""; fi; done; fi
echo "######################################"
else
echo "{\"5.4.1.5. Đảm bảo thời gian thay đổi mật khẩu lần cuối hợp lệ\" : \"PASSED\"}"
fi
############################################################################
# Đặt shell cho tất cả tài khoản hệ thống sang /sbin/nologin:
# usermod -s /sbin/nologin <user>
# Thực hiện câu lệnh sau sẽ đặt mọi tài khoản hệ thống sang non-login shell:
# awk -F: '($1!~/^(root|halt|sync|shutdown|nfsnobody)$/ && $3<'"$(awk '/^\h*UID_MIN/{print $2}' /etc/login.defs)"' && $7!~/^(\/usr)?\/sbin\/nologin(\/)?$/ && $7!~/(\/usr)?\/bin\/false(\/)?$/) { print $1 }' /etc/passwd | while read user; do usermod -s $(which nologin) $user; done
# Khoá tất cả tài khoản hệ thống không phải root:
# usermod -L <user>
# Thực hiện câu lệnh sau sẽ tự động khoá mọi tài khoản hệ thống ngoài root:
# awk -F: '($1!="root" && $1!~/^\+/ && $3<'"$(awk '/^\h*UID_MIN/{print $2}' /etc/login.defs)"') {print $1}' /etc/passwd | xargs -I '{}' passwd -S '{}' | awk '($2!="L" && $2!="LK") {print $1}' | while read user; do usermod -L $user; done
if [ $(awk -F: '($1!~/^(root|halt|sync|shutdown|nfsnobody)$/ && $3<'"$(awk '/^\h*UID_MIN/{print $2}' /etc/login.defs)"' && $7!~/^(\/usr)?\/sbin\/nologin(\/)?$/ && $7!~/(\/usr)?\/bin\/false(\/)?$/) { print $1 }' /etc/passwd | wc -l) -ne 0 ] || [ $(awk -F: '($1!="root" && $1!~/^\+/ && $3<'"$(awk '/^\h*UID_MIN/{print $2}' /etc/login.defs)"') {print $1}' /etc/passwd | xargs -I '{}' passwd -S '{}' | awk '($2!="L" && $2!="LK") {print $1}' | wc -l) -ne 0 ]; then
echo "{\"5.4.2. Cấu hình vô hiệu hoá đăng nhập bằng tài khoản hệ thống\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Đặt shell cho tất cả tài khoản hệ thống sang /sbin/nologin:
# usermod -s /sbin/nologin <user>
# Thực hiện câu lệnh sau sẽ đặt mọi tài khoản hệ thống sang non-login shell:
# awk -F: '(\$1\!~/^(root|halt|sync|shutdown|nfsnobody)\$/ && \$3<'\"\$(awk '/^\\s*UID_MIN/{print \$2}' /etc/login.defs)\"' && \$7\!~/^(\\/usr)?\\/sbin\\/nologin(\\/)?\$/ && \$7\!~/(\\/usr)?\\/bin\\/false(\\/)?\$/) { print \$1 }' /etc/passwd | while read user; do usermod -s \$(which nologin) \$user; done
# Khoá tất cả tài khoản hệ thống không phải root:
# usermod -L <user>
# Thực hiện câu lệnh sau sẽ tự động khoá mọi tài khoản hệ thống ngoài root:
# awk -F: '(\$1!=\"root\" && \$1\!~/^\\+/ && \$3<'\"\$(awk '/^\\s*UID_MIN/{print \$2}' /etc/login.defs)\"') {print \$1}' /etc/passwd | xargs -I '{}' passwd -S '{}' | awk '(\$2!=\"L\" && \$2!=\"LK\") {print \$1}' | while read user; do usermod -L \$user; done"
if [ $(awk -F: '($1!~/^(root|halt|sync|shutdown|nfsnobody)$/ && $3<'"$(awk '/^\h*UID_MIN/{print $2}' /etc/login.defs)"' && $7!~/^(\/usr)?\/sbin\/nologin(\/)?$/ && $7!~/(\/usr)?\/bin\/false(\/)?$/) { print $1 }' /etc/passwd | wc -l) -ne 0 ]; then echo "-------------------"; echo "#awk -F: '(\$1\!~/^(root|halt|sync|shutdown|nfsnobody)\$/ && \$3<'\"\$(awk '/^\\s*UID_MIN/{print \$2}' /etc/login.defs)\"' && \$7\!~/^(\\/usr)?\\/sbin\\/nologin(\\/)?\$/ && \$7\!~/(\\/usr)?\\/bin\\/false(\\/)?\$/) { print \$1 }' /etc/passwd -eq 0 ";awk -F: '($1!~/^(root|halt|sync|shutdown|nfsnobody)$/ && $3<'"$(awk '/^\h*UID_MIN/{print $2}' /etc/login.defs)"' && $7!~/^(\/usr)?\/sbin\/nologin(\/)?$/ && $7!~/(\/usr)?\/bin\/false(\/)?$/) { print $1 }' /etc/passwd; fi
if [ $(awk -F: '($1!="root" && $1!~/^\+/ && $3<'"$(awk '/^\h*UID_MIN/{print $2}' /etc/login.defs)"') {print $1}' /etc/passwd | xargs -I '{}' passwd -S '{}' | awk '($2!="L" && $2!="LK") {print $1}' | wc -l) -ne 0 ]; then echo "-------------------"; echo "#awk -F: '(\$1!=\"root\" && \$1\!~/^\\+/ && \$3<'\"\$(awk '/^\\s*UID_MIN/{print \$2}' /etc/login.defs)\"') {print \$1}' /etc/passwd | xargs -I '{}' passwd -S '{}' | awk '(\$2!=\"L\" && \$2!=\"LK\") {print \$1}' -eq 0 ";awk -F: '($1!="root" && $1!~/^\+/ && $3<'"$(awk '/^\h*UID_MIN/{print $2}' /etc/login.defs)"') {print $1}' /etc/passwd | xargs -I '{}' passwd -S '{}' | awk '($2!="L" && $2!="LK") {print $1}'; fi
echo "######################################"
else
echo "{\"5.4.2. Cấu hình vô hiệu hoá đăng nhập bằng tài khoản hệ thống\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa một trong các file /etc/bashrc, /etc/profile và /etc/profile.d/*.sh thêm hoặc thay đổi các tham số TMOUT phù hợp với chính sách:
# readonly TMOUT=900 ; export TMOUT
if [ $(grep "TMOUT=900" /etc/bashrc /etc/profile /etc/profile.d/*.sh | wc -l) -eq 0 ] || [ $(grep -E "readonly\s+TMOUT" /etc/bashrc /etc/profile /etc/profile.d/*.sh | wc -l) -eq 0 ] || [ $(grep -E "export\s+TMOUT" /etc/bashrc /etc/profile /etc/profile.d/*.sh | wc -l) -eq 0 ] || [ $(echo $TMOUT | grep "^900$" | wc -l) -eq 0 ]; then
echo "{\"5.4.3. Cấu hình shell timeout mặc định\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa một trong các file /etc/bashrc, /etc/profile và /etc/profile.d/*.sh thêm hoặc thay đổi các tham số TMOUT phù hợp với chính sách:
# readonly TMOUT=900 ; export TMOUT"
if [ $(grep "TMOUT=900" /etc/bashrc /etc/profile /etc/profile.d/*.sh | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep \"TMOUT=900\" /etc/bashrc /etc/profile /etc/profile.d/*.sh -ne 0 ";grep "TMOUT=900" /etc/bashrc /etc/profile /etc/profile.d/*.sh; fi
if [ $(grep -E "readonly\s+TMOUT" /etc/bashrc /etc/profile /etc/profile.d/*.sh | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -E \"readonly\s+TMOUT\" /etc/bashrc /etc/profile /etc/profile.d/*.sh -ne 0 ";grep -E "readonly\s+TMOUT" /etc/bashrc /etc/profile /etc/profile.d/*.sh; fi
if [ $(grep -E "export\s+TMOUT" /etc/bashrc /etc/profile /etc/profile.d/*.sh | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -E \"export\s+TMOUT\" /etc/bashrc /etc/profile /etc/profile.d/*.sh -ne 0 ";grep -E "export\s+TMOUT" /etc/bashrc /etc/profile /etc/profile.d/*.sh; fi
if [ $(echo $TMOUT | grep "^900$" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#echo \$TMOUT | grep \"^900\$\" -ne 0 ";echo $TMOUT | grep "^900$"; fi
echo "######################################"
else
echo "{\"5.4.3. Cấu hình shell timeout mặc định\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện câu lệnh sau để đặt group mặc định cho người dùng root là GID 0:
# usermod -g 0 root
if [ $(grep -P "^\h*root:" /etc/passwd | cut -d: -f1,4 | grep "0" | wc -l) -eq 0 ]; then
echo "{\"5.4.4. Cấu hình group mặc định của tài khoản root\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để đặt group mặc định cho người dùng root là GID 0:
# usermod -g 0 root"
if [ $(grep -P "^\h*root:" /etc/passwd | cut -d: -f1,4 | grep "0" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*root:\" /etc/passwd | cut -d: -f1,4 | grep \"0\" -ne 0 ";grep -P "^\h*root:" /etc/passwd | cut -d: -f1,4 | grep "0"; fi
echo "######################################"
else
echo "{\"5.4.4. Cấu hình group mặc định của tài khoản root\" : \"PASSED\"}"
fi
############################################################################
# Chỉnh sửa file /etc/bashrc, /etc/profile và /etc/profile.d/*.sh, thêm vào hoặc chỉnh sửa tất cả các tham số umask như sau:
# umask 027
if [[ (($(grep -Ei '^\h*UMASK\s+(0[0-7][2-7]7|[0-7][2-7]7)\b' /etc/login.defs | wc -l) -eq 0 || $(grep -Ei '^\h*USERGROUPS_ENAB\s*"?no"?\b' /etc/login.defs | wc -l) -eq 0) && $(grep -E '^\h*session\s+(optional|requisite|required)\s+pam_umask.so\b' /etc/pam.d/password-auth /etc/pam.d/system-auth | wc -l) -eq 0 && $(grep -REi '^\h*UMASK\s+\s*(0[0-7][2-7]7|[0-7][2-7]7|u=(r?|w?|x?)(r?|w?|x?)(r?|w?|x?),g=(r?x?|x?r?),o=)\b' /etc/profile* /etc/bashrc* | wc -l) -eq 0) ]] || [ $(grep -RPi '(^|^[^#]*)\s*umask\s+([0-7][0-7][01][0-7]\b|[0-7][0-7][0-7][0-6]\b|[0-7][01][0-7]\b|[0-7][0-7][0-6]\b|(u=[rwx]{0,3},)?(g=[rwx]{0,3},)?o=[rwx]+\b|(u=[rwx]{1,3},)?g=[^rx]{1,3}( ,o=[rwx]{0,3})?\b)' /etc/login.defs /etc/profile* /etc/bashrc* | wc -l) -ne 0 ]; then
echo "{\"5.4.5. Cấu hình user umask mặc định\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Chỉnh sửa file /etc/bashrc, /etc/profile và /etc/profile.d/*.sh, thêm vào hoặc chỉnh sửa tất cả các tham số umask như sau:
# umask 027"
if [ $(grep -Ei '^\h*UMASK\s+(0[0-7][2-7]7|[0-7][2-7]7)\b' /etc/login.defs | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ei '^\h*UMASK\s+(0[0-7][2-7]7|[0-7][2-7]7)\b' /etc/login.defs -ne 0 ";grep -Ei '^\h*UMASK\s+(0[0-7][2-7]7|[0-7][2-7]7)\b' /etc/login.defs; fi
if [ $(grep -Ei '^\h*USERGROUPS_ENAB\s*"?no"?\b' /etc/login.defs | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Ei '^\h*USERGROUPS_ENAB\s*\"?no\"?\b' /etc/login.defs -ne 0 ";grep -Ei '^\h*USERGROUPS_ENAB\s*"?no"?\b' /etc/login.defs; fi
if [ $(grep -E '^\h*session\s+(optional|requisite|required)\s+pam_umask.so\b' /etc/pam.d/password-auth /etc/pam.d/system-auth | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -E '^\h*session\s+(optional|requisite|required)\s+pam_umask.so\b' /etc/pam.d/password-auth /etc/pam.d/system-auth -ne 0 ";grep -E '^\h*session\s+(optional|requisite|required)\s+pam_umask.so\b' /etc/pam.d/password-auth /etc/pam.d/system-auth; fi
if [ $(grep -REi '^\h*UMASK\s+\s*(0[0-7][2-7]7|[0-7][2-7]7|u=(r?|w?|x?)(r?|w?|x?)(r?|w?|x?),g=(r?x?|x?r?),o=)\b' /etc/profile* /etc/bashrc* | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -REi '^\h*UMASK\s+\s*(0[0-7][2-7]7|[0-7][2-7]7|u=(r?|w?|x?)(r?|w?|x?)(r?|w?|x?),g=(r?x?|x?r?),o=)\b' /etc/profile* /etc/bashrc* -ne 0 ";grep -REi '^\h*UMASK\s+\s*(0[0-7][2-7]7|[0-7][2-7]7|u=(r?|w?|x?)(r?|w?|x?)(r?|w?|x?),g=(r?x?|x?r?),o=)\b' /etc/profile* /etc/bashrc*; fi
if [ $(grep -RPi '(^|^[^#]*)\s*umask\s+([0-7][0-7][01][0-7]\b|[0-7][0-7][0-7][0-6]\b|[0-7][01][0-7]\b|[0-7][0-7][0-6]\b|(u=[rwx]{0,3},)?(g=[rwx]{0,3},)?o=[rwx]+\b|(u=[rwx]{1,3},)?g=[^rx]{1,3}( ,o=[rwx]{0,3})?\b)' /etc/login.defs /etc/profile* /etc/bashrc* | wc -l) -ne 0 ]; then echo "-------------------"; echo "#grep -RPi '(^|^[^#]*)\s*umask\s+([0-7][0-7][01][0-7]\b|[0-7][0-7][0-7][0-6]\b|[0-7][01][0-7]\b|[0-7][0-7][0-6]\b|(u=[rwx]{0,3},)?(g=[rwx]{0,3},)?o=[rwx]+\b|(u=[rwx]{1,3},)?g=[^rx]{1,3}( ,o=[rwx]{0,3})?\b)' /etc/login.defs /etc/profile* /etc/bashrc* -eq 0 ";grep -RPi '(^|^[^#]*)\s*umask\s+([0-7][0-7][01][0-7]\b|[0-7][0-7][0-7][0-6]\b|[0-7][01][0-7]\b|[0-7][0-7][0-6]\b|(u=[rwx]{0,3},)?(g=[rwx]{0,3},)?o=[rwx]+\b|(u=[rwx]{1,3},)?g=[^rx]{1,3}( ,o=[rwx]{0,3})?\b)' /etc/login.defs /etc/profile* /etc/bashrc*; fi
echo "######################################"
else
echo "{\"5.4.5. Cấu hình user umask mặc định\" : \"PASSED\"}"
fi
############################################################################
# Tạo ra một nhóm rỗng sẽ được chỉ định để sử dụng trong lệnh su, tên nhóm nên được đặt tên theo chính sách:
# groupadd sugroup
# Thêm dòng sau vào file /etc/pam.d/su, chỉ định nhóm rỗng vừa tạo vào:
# auth required pam_wheel.so use_uid group=sugroup
if [ $(grep -Pi '^\h*auth\h+(?:required|requisite)\h+pam_wheel\.so\h+(?:[^#\n\r]+\h+)?((?!\2)(use_uid\b|group=\H+\b))\h+(?:[^#\n\r]+\h+)?((?!\1)(use_uid\b|group=\H+\b))(\ h+.*)?$' /etc/pam.d/su | wc -l) -eq 0 ] || [ $(grep -P "^\h*sugroup:x:.*:$" /etc/group | wc -l) -eq 0 ]; then
echo "{\"5.4.6. Cấu hình hạn chế truy cập cho câu lệnh su\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Tạo ra một nhóm rỗng sẽ được chỉ định để sử dụng trong lệnh su, tên nhóm nên được đặt tên theo chính sách:
# groupadd sugroup
# Thêm dòng sau vào file /etc/pam.d/su, chỉ định nhóm rỗng vừa tạo vào:
# auth required pam_wheel.so use_uid group=sugroup
# Tạo một danh sách người dùng được ngăn cách bởi dấu phẩy ở dòng wheel trong file /etc/group:
# wheel:x:10:root,<user list>"
if [ $(grep -Pi '^\h*auth\h+(?:required|requisite)\h+pam_wheel\.so\h+(?:[^#\n\r]+\h+)?((?!\2)(use_uid\b|group=\H+\b))\h+(?:[^#\n\r]+\h+)?((?!\1)(use_uid\b|group=\H+\b))(\ h+.*)?$' /etc/pam.d/su | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -Pi '^\h*auth\h+(?:required|requisite)\h+pam_wheel\.so\h+(?:[^#\n\r]+\h+)?((?!\2)(use_uid\b|group=\H+\b))\h+(?:[^#\n\r]+\h+)?((?!\1)(use_uid\b|group=\H+\b))(\ h+.*)?\$' /etc/pam.d/su -ne 0 ";grep -Pi '^\h*auth\h+(?:required|requisite)\h+pam_wheel\.so\h+(?:[^#\n\r]+\h+)?((?!\2)(use_uid\b|group=\H+\b))\h+(?:[^#\n\r]+\h+)?((?!\1)(use_uid\b|group=\H+\b))(\ h+.*)?$' /etc/pam.d/su; fi
if [ $(grep -P "^\h*sugroup:x:.*:$" /etc/group | wc -l) -eq 0 ]; then echo "-------------------"; echo "#grep -P \"^\\h*sugroup:x:.*:\$\" /etc/group -ne 0 ";grep -P "^\h*sugroup:x:.*:$" /etc/group; fi
echo "######################################"
else
echo "{\"5.4.6. Cấu hình hạn chế truy cập cho câu lệnh su\" : \"PASSED\"}"
fi
##################################################################################################################
# Thực hiện câu lệnh sau để đặt sticky bit cho toàn bộ thư mục dùng chung:
# df --local -P | awk '{if (NR!=1) print $6}' | xargs -I '{}' find '{}' -xdev -type d \( -perm -0002 -a ! -perm -1000 \) 2>/dev/null | xargs -I '{}' chmod a+t '{}'
if [ $(df --local -P | awk '{if (NR!=1) print $6}' | xargs -I '{}' find '{}' -xdev -type d \( -perm -0002 -a ! -perm -1000 \) 2>/dev/null | wc -l) -ne 0 ]; then
echo "{\"6.1.1. Cấu hình sticky bit cho tất cả các thư mục dùng chung\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để đặt sticky bit cho toàn bộ thư mục dùng chung:
# df --local -P | awk '{if (NR!=1) print \$6}' | xargs -I '{}' find '{}' -xdev -type d \( -perm -0002 -a ! -perm -1000 \) 2>/dev/null | xargs -I '{}' chmod a+t '{}'"
if [ $(df --local -P | awk '{if (NR!=1) print $6}' | xargs -I '{}' find '{}' -xdev -type d \( -perm -0002 -a ! -perm -1000 \) 2>/dev/null | wc -l) -ne 0 ]; then echo "-------------------"; echo "#df --local -P | awk '{if (NR!=1) print \$6}' | xargs -I '{}' find '{}' -xdev -type d \( -perm -0002 -a ! -perm -1000 \) 2>/dev/null -eq 0 ";df --local -P | awk '{if (NR!=1) print $6}' | xargs -I '{}' find '{}' -xdev -type d \( -perm -0002 -a ! -perm -1000 \) 2>/dev/null; fi
echo "######################################"
else
echo "{\"6.1.1. Cấu hình sticky bit cho tất cả các thư mục dùng chung\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện các câu lệnh sau để đặt quyền ở file /etc/passwd /etc/shadow, /etc/group, /etc/gshadow, /etc/passwd-, /etc/shadow-, /etc/group-, /etc/gshadow-:
# # /etc/passwd
# chown root:root /etc/passwd
# chmod 644 /etc/passwd
# # /etc/shadow
# chown root:root /etc/shadow
# chmod 0000 /etc/shadow
# # /etc/group
# chown root:root /etc/group
# chmod u-x,g-wx,o-wx /etc/group
# # /etc/gshadow
# chown root:root /etc/gshadow
# chmod 0000 /etc/gshadow
# # /etc/passwd-
# chown root:root /etc/passwd-
# chmod u-x,go-wx /etc/passwd-
# # /etc/shadow-
# chown root:root /etc/shadow-
# chmod 0000 /etc/shadow-
# # /etc/group-
# chown root:root /etc/group-
# chmod u-x,go-wx /etc/group-
# # /etc/gshadow-
# chown root:root /etc/gshadow-
# chmod 0000 /etc/gshadow-
if [ $(stat /etc/passwd | grep "0644.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then
echo "{\"6.1.2. Cấu hình phân quyền cho file /etc/passwd\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để đặt quyền ở file /etc/passwd:
# # /etc/passwd
# chown root:root /etc/passwd
# chmod 644 /etc/passwd"
if [ $(stat /etc/passwd | grep "0644.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat /etc/passwd | grep \"0644.*Uid:.*0/.*root.*Gid:.*0/.*root\" -ne 0 ";stat /etc/passwd | grep "0644.*Uid:.*0/.*root.*Gid:.*0/.*root"; fi
echo "######################################"
else
echo "{\"6.1.2. Cấu hình phân quyền cho file /etc/passwd\" : \"PASSED\"}"
fi
if [ $(stat /etc/shadow | grep "0000.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then
echo "{\"6.1.3. Cấu hình phân quyền cho file /etc/shadow\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để đặt quyền ở file /etc/shadow:
# # /etc/shadow
# chown root:root /etc/shadow
# chmod 0000 /etc/shadow"
if [ $(stat /etc/shadow | grep "0000.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat /etc/shadow | grep \"0000.*Uid:.*0/.*root.*Gid:.*0/.*root\" -ne 0 ";stat /etc/shadow | grep "0000.*Uid:.*0/.*root.*Gid:.*0/.*root"; fi
echo "######################################"
else
echo "{\"6.1.3. Cấu hình phân quyền cho file /etc/shadow\" : \"PASSED\"}"
fi
if [ $(stat /etc/group | grep "0644.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then
echo "{\"6.1.4. Cấu hình phân quyền cho file /etc/group\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để đặt quyền ở file /etc/group:
# # /etc/group
# chown root:root /etc/group
# chmod u-x,g-wx,o-wx /etc/group"
if [ $(stat /etc/group | grep "0644.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat /etc/group | grep \"0644.*Uid:.*0/.*root.*Gid:.*0/.*root\" -ne 0 ";stat /etc/group | grep "0644.*Uid:.*0/.*root.*Gid:.*0/.*root"; fi
echo "######################################"
else
echo "{\"6.1.4. Cấu hình phân quyền cho file /etc/group\" : \"PASSED\"}"
fi
if [ $(stat /etc/gshadow | grep "0000.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then
echo "{\"6.1.5. Cấu hình phân quyền cho file /etc/gshadow\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để đặt quyền ở file /etc/gshadow:
# # /etc/gshadow
# chown root:root /etc/gshadow
# chmod 0000 /etc/gshadow"
if [ $(stat /etc/gshadow | grep "0000.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat /etc/gshadow | grep \"0000.*Uid:.*0/.*root.*Gid:.*0/.*root\" -ne 0 ";stat /etc/gshadow | grep "0000.*Uid:.*0/.*root.*Gid:.*0/.*root"; fi
echo "######################################"
else
echo "{\"6.1.5. Cấu hình phân quyền cho file /etc/gshadow\" : \"PASSED\"}"
fi
if [ $(stat /etc/passwd- | grep "0[0246][04][04].*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then
echo "{\"6.1.6. Cấu hình phân quyền cho file /etc/passwd-\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để đặt quyền ở file /etc/passwd-:
# # /etc/passwd-
# chown root:root /etc/passwd-
# chmod u-x,go-wx /etc/passwd-"
if [ $(stat /etc/passwd- | grep "0[0246][04][04].*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat /etc/passwd- | grep \"0[0246][04][04].*Uid:.*0/.*root.*Gid:.*0/.*root\" -ne 0 ";stat /etc/passwd- | grep "0[0246][04][04].*Uid:.*0/.*root.*Gid:.*0/.*root"; fi
echo "######################################"
else
echo "{\"6.1.6. Cấu hình phân quyền cho file /etc/passwd-\" : \"PASSED\"}"
fi
if [ $(stat /etc/shadow- | grep "0000.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then
echo "{\"6.1.7. Cấu hình phân quyền cho file /etc/shadow-\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để đặt quyền ở file /etc/shadow-:
# # /etc/shadow-
# chown root:root /etc/shadow-
# chmod 0000 /etc/shadow-"
if [ $(stat /etc/shadow- | grep "0000.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat /etc/shadow- | grep \"0000.*Uid:.*0/.*root.*Gid:.*0/.*root\" -ne 0 ";stat /etc/shadow- | grep "0000.*Uid:.*0/.*root.*Gid:.*0/.*root"; fi
echo "######################################"
else
echo "{\"6.1.7. Cấu hình phân quyền cho file /etc/shadow-\" : \"PASSED\"}"
fi
if [ $(stat /etc/group- | grep "0[0246][04][04].*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then
echo "{\"6.1.8. Cấu hình phân quyền cho file /etc/group-\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để đặt quyền ở file /etc/group-:
# # /etc/group-
# chown root:root /etc/group-
# chmod u-x,go-wx /etc/group-"
if [ $(stat /etc/group- | grep "0[0246][04][04].*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat /etc/group- | grep \"0[0246][04][04].*Uid:.*0/.*root.*Gid:.*0/.*root\" -ne 0 ";stat /etc/group- | grep "0[0246][04][04].*Uid:.*0/.*root.*Gid:.*0/.*root"; fi
echo "######################################"
else
echo "{\"6.1.8. Cấu hình phân quyền cho file /etc/group-\" : \"PASSED\"}"
fi
if [ $(stat /etc/gshadow- | grep -E "0000.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then
echo "{\"6.1.9. Cấu hình phân quyền cho file /etc/gshadow-\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để đặt quyền ở file /etc/gshadow-:
# # /etc/gshadow-
# chown root:root /etc/gshadow-
# chmod 0000 /etc/gshadow-"
if [ $(stat /etc/gshadow- | grep -E "0000.*Uid:.*0/.*root.*Gid:.*0/.*root" | wc -l) -eq 0 ]; then echo "-------------------"; echo "#stat /etc/gshadow- | grep -E \"0000.*Uid:.*0/.*root.*Gid:.*0/.*root\" -ne 0 ";stat /etc/gshadow- | grep -E "0000.*Uid:.*0/.*root.*Gid:.*0/.*root"; fi
echo "######################################"
else
echo "{\"6.1.9. Cấu hình phân quyền cho file /etc/gshadow-\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện các câu lệnh sau để xác định các file world-writable trong hệ thống:
# df --local -P | awk '{if (NR!=1) print $6}' | xargs -I '{}' find '{}' -xdev -type f -perm -0002
# find / -xdev -type f -perm -0002
# Thực hiện câu lệnh sau để xóa quyền ghi đối với danh mục "other" cho các file vừa tìm được, tham khảo tài liệu của nhà cung cấp có liên quan để tránh vi phạm bất kỳ phụ thuộc ứng dụng nào trên một tệp nhất định.
# chmod o-w <filename>
if [ $(df --local -P | awk '{if (NR!=1) print $6}' | xargs -I '{}' find '{}' -xdev -path /proc -prune -o -type f -perm -0002 -print 2>/dev/null | wc -l) -ne 0 ] || [ $(find / -xdev -path /proc -prune -o -type f -perm -0002 -print 2>/dev/null | wc -l) -ne 0 ]; then
echo "{\"6.1.10. Đảm bảo không có file world-writable tồn tại\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để xác định các file world-writable trong hệ thống:
# df --local -P | awk '{if (NR!=1) print \$6}' | xargs -I '{}' find '{}' -xdev -type f -perm -0002
# find / -xdev -type f -perm -0002
# Thực hiện câu lệnh sau để xóa quyền ghi đối với danh mục \"other\" cho các file vừa tìm được, tham khảo tài liệu của nhà cung cấp có liên quan để tránh vi phạm bất kỳ phụ thuộc ứng dụng nào trên một tệp nhất định.
# chmod o-w <filename>"
if [ $(df --local -P | awk '{if (NR!=1) print $6}' | xargs -I '{}' find '{}' -xdev -path /proc -prune -o -type f -perm -0002 -print 2>/dev/null | wc -l) -ne 0 ]; then echo "-------------------"; echo "#df --local -P | awk '{if (NR!=1) print \$6}' | xargs -I '{}' find '{}' -xdev -path /proc -prune -o -type f -perm -0002 -print 2>/dev/null -eq 0 ";df --local -P | awk '{if (NR!=1) print $6}' | xargs -I '{}' find '{}' -xdev -path /proc -prune -o -type f -perm -0002 -print 2>/dev/null; fi
if [ $(find / -xdev -path /proc -prune -o -type f -perm -0002 -print 2>/dev/null | wc -l) -ne 0 ]; then echo "-------------------"; echo "#find / -xdev -path /proc -prune -o -type f -perm -0002 -print 2>/dev/null -eq 0 ";find / -xdev -path /proc -prune -o -type f -perm -0002 -print 2>/dev/null; fi
echo "######################################"
else
echo "{\"6.1.10. Đảm bảo không có file world-writable tồn tại\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện các câu lệnh sau để xác định các file và thư mục được sở hữu bởi người dùng hoặc group không được liệt kê trong file cấu hình hệ thống:
# df --local -P | awk '{if (NR!=1) print $6}' | xargs -I '{}' find '{}' -xdev -nouser
# find /* -xdev -nouser
# Thực hiện câu lệnh sau để đặt lại quyền sở hữu các file vừa tìm được cho một số người dùng hoặc group đang hoạt động trên hệ thống:
# chown <owner>:<group> <filename>
if [ $(df --local -P | awk '{if (NR!=1) print $6}' | xargs -I '{}' find '{}' -xdev -nouser 2>/dev/null | wc -l) -ne 0 ] || [ $(find /* -xdev -nouser 2>/dev/null | wc -l) -ne 0 ]; then
echo "{\"6.1.11. Đảm bảo các file hoặc thư mục không có chủ sở hữu không tồn tại\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để xác định các file và thư mục được sở hữu bởi người dùng hoặc group không được liệt kê trong file cấu hình hệ thống:
# df --local -P | awk '{if (NR!=1) print \$6}' | xargs -I '{}' find '{}' -xdev -nouser
# find /* -xdev -nouser
# Thực hiện câu lệnh sau để đặt lại quyền sở hữu các file vừa tìm được cho một số người dùng hoặc group đang hoạt động trên hệ thống:
# chown <owner>:<group> <filename>"
if [ $(df --local -P | awk '{if (NR!=1) print $6}' | xargs -I '{}' find '{}' -xdev -nouser 2>/dev/null | wc -l) -ne 0 ]; then echo "-------------------"; echo "#df --local -P | awk '{if (NR!=1) print \$6}' | xargs -I '{}' find '{}' -xdev -nouser 2>/dev/null -eq 0 ";df --local -P | awk '{if (NR!=1) print $6}' | xargs -I '{}' find '{}' -xdev -nouser 2>/dev/null; fi
if [ $(find /* -xdev -nouser 2>/dev/null | wc -l) -ne 0 ]; then echo "-------------------"; echo "#find /* -xdev -nouser 2>/dev/null -eq 0 ";find /* -xdev -nouser 2>/dev/null; fi
echo "######################################"
else
echo "{\"6.1.11. Đảm bảo các file hoặc thư mục không có chủ sở hữu không tồn tại\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện các câu lệnh sau để xác định các file và thư mục được sở hữu bởi người dùng hoặc group không được liệt kê trong file cấu hình hệ thống:
# df --local -P | awk '{if (NR!=1) print $6}' | xargs -I '{}' find '{}' -xdev -nogroup
# find /* -xdev -nogroup
# Thực hiện câu lệnh sau để đặt lại quyền sở hữu các file vừa tìm được cho một số người dùng hoặc group đang hoạt động trên hệ thống:
# chown <owner>:<group> <filename>
if [ $(df --local -P | awk '{if (NR!=1) print $6}' | xargs -I '{}' find '{}' -xdev -nogroup 2>/dev/null | wc -l) -ne 0 ] || [ $(find /* -xdev -nogroup 2>/dev/null | wc -l) -ne 0 ]; then
echo "{\"6.1.12. Đảm bảo các file hoặc thư mục không có nhóm không tồn tại\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện các câu lệnh sau để xác định các file và thư mục được sở hữu bởi người dùng hoặc group không được liệt kê trong file cấu hình hệ thống:
# df --local -P | awk '{if (NR!=1) print \$6}' | xargs -I '{}' find '{}' -xdev -nogroup
# find /* -xdev -nogroup
# Thực hiện câu lệnh sau để đặt lại quyền sở hữu các file vừa tìm được cho một số người dùng hoặc group đang hoạt động trên hệ thống:
# chown <owner>:<group> <filename>"
if [ $(df --local -P | awk '{if (NR!=1) print $6}' | xargs -I '{}' find '{}' -xdev -nogroup 2>/dev/null | wc -l) -ne 0 ]; then echo "-------------------"; echo "#df --local -P | awk '{if (NR!=1) print \$6}' | xargs -I '{}' find '{}' -xdev -nogroup 2>/dev/null -eq 0 ";df --local -P | awk '{if (NR!=1) print $6}' | xargs -I '{}' find '{}' -xdev -nogroup 2>/dev/null; fi
if [ $(find /* -xdev -nogroup 2>/dev/null | wc -l) -ne 0 ]; then echo "-------------------"; echo "#find /* -xdev -nogroup 2>/dev/null -eq 0 ";find /* -xdev -nogroup 2>/dev/null; fi
echo "######################################"
else
echo "{\"6.1.12. Đảm bảo các file hoặc thư mục không có nhóm không tồn tại\" : \"PASSED\"}"
fi
############################################################################
# Nếu có tài khoản nào trong file /etc/shadow không có mật khẩu, thực hiện câu lệnh sau để khoá tài khoản đến khi xác định được nguyên nhân tài khoản đó không có mật khẩu:
# passwd -l <username>
# Đồng thời, kiểm tra tài khoản đó được đăng nhập hay chưa và tìm hiểu xem tài khoản đó được sử dụng với mục đích gì để nếu nó cần phải bị xóa.
if [ $(awk -F: '$5==90 && $6==7 {print}' /etc/shadow | awk -F: ' $2=="!" || $2=="" || $2=="!!"{print $1 " " $2}' | wc -l) -ne 0 ]; then
echo "{\"6.2.1. Đảm bảo trường mật khẩu không để trống\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Nếu có tài khoản nào trong file /etc/shadow không có mật khẩu, thực hiện câu lệnh sau để khoá tài khoản đến khi xác định được nguyên nhân tài khoản đó không có mật khẩu:
# passwd -l <username>
# Đồng thời, kiểm tra tài khoản đó được đăng nhập hay chưa và tìm hiểu xem tài khoản đó được sử dụng với mục đích gì để nếu nó cần phải bị xóa."
if [ $(awk -F: '$5==90 && $6==7 {print}' /etc/shadow | awk -F: ' $2=="!" || $2=="" || $2=="!!"{print $1 " " $2}' | wc -l) -ne 0 ]; then echo "-------------------"; echo "#awk -F: '\$5==90 && \$6==7 {print}' /etc/shadow | awk -F: ' \$2==\"!\" || \$2==\"\" || \$2==\"!!\"{print \$1 \" \" \$2}' -eq 0 ";awk -F: '$5==90 && $6==7 {print}' /etc/shadow | awk -F: ' $2=="!" || $2=="" || $2=="!!"{print $1 " " $2}'; fi
echo "######################################"
else
echo "{\"6.2.1. Đảm bảo trường mật khẩu không để trống\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện câu lệnh sau để xác định các nhóm tồn tại trong file /etc/passwd không tồn tại trong file /etc/group:
# for i in $(cut -s -d: -f4 /etc/passwd | sort -u ); do grep -q -P "^.*?:[^:]*:$i:" /etc/group || echo "Group $i"; done
# Thực hiện hành động thích hợp để sửa bất kỳ group nào được tìm thấy.
if [ $(for i in $(cut -s -d: -f4 /etc/passwd | sort -u ); do grep -q -P "^.*?:[^:]*:$i:" /etc/group || echo "Group $i"; done | wc -l) -ne 0 ]; then
echo "{\"6.2.2. Đảm bảo mọi nhóm trong file /etc/passwd tồn tại trong file /etc/group\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để xác định các nhóm tồn tại trong file /etc/passwd không tồn tại trong file /etc/group:
# for i in \$(cut -s -d: -f4 /etc/passwd | sort -u ); do grep -q -P \"^.*?:[^:]*:\$i:\" /etc/group || echo \"Group \$i\"; done
# Thực hiện hành động thích hợp để sửa bất kỳ group nào được tìm thấy."
if [ $(for i in $(cut -s -d: -f4 /etc/passwd | sort -u ); do grep -q -P "^.*?:[^:]*:$i:" /etc/group || echo "Group $i"; done | wc -l) -ne 0 ]; then echo "-------------------"; echo "#for i in \$(cut -s -d: -f4 /etc/passwd | sort -u ); do grep -q -P \"^.*?:[^:]*:\$i:\" /etc/group || echo \"Group \$i\"; done -eq 0 ";for i in $(cut -s -d: -f4 /etc/passwd | sort -u ); do grep -q -P "^.*?:[^:]*:$i:" /etc/group || echo "Group $i"; done; fi
echo "######################################"
else
echo "{\"6.2.2. Đảm bảo mọi nhóm trong file /etc/passwd tồn tại trong file /etc/group\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện câu lệnh sau để xác định các UID tồn tại trong file /etc/passwd không tồn tại trong file /etc/group:
# cut -f3 -d":" /etc/passwd | sort -n | uniq -c | while read x ; do [ -z "$x" ] && break; set - $x; if [ $1 -gt 1 ]; then users=$(awk -F: '($3 == n) { print $1 }' n=$2 /etc/passwd | xargs); echo "Duplicate UID ($2): $users"; fi; done
# Dựa theo kết quả trên, tạo ra một UID độc nhất và kiểm tra toàn bộ file sở hữu bởi UID bị trùng để xác định các file đó thuộc về UID nào.
if [ $(cut -f3 -d":" /etc/passwd | sort -n | uniq -c | while read x ; do [ -z "$x" ] && break; set - $x; if [ $1 -gt 1 ]; then users=$(awk -F: '($3 == n) { print $1 }' n=$2 /etc/passwd | xargs); echo "Duplicate UID ($2): $users"; fi; done | wc -l) -ne 0 ]; then
echo "{\"6.2.3. Đảm bảo UID không bị lặp\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để xác định các UID tồn tại trong file /etc/passwd không tồn tại trong file /etc/group:
# cut -f3 -d\":\" /etc/passwd | sort -n | uniq -c | while read x ; do [ -z \"\$x\" ] && break; set - \$x; if [ \$1 -gt 1 ]; then users=\$(awk -F: '(\$3 == n) { print \$1 }' n=\$2 /etc/passwd | xargs); echo \"Duplicate UID (\$2): \$users\"; fi; done
# Dựa theo kết quả trên, tạo ra một UID độc nhất và kiểm tra toàn bộ file sở hữu bởi UID bị trùng để xác định các file đó thuộc về UID nào."
if [ $(cut -f3 -d":" /etc/passwd | sort -n | uniq -c | while read x ; do [ -z "$x" ] && break; set - $x; if [ $1 -gt 1 ]; then users=$(awk -F: '($3 == n) { print $1 }' n=$2 /etc/passwd | xargs); echo "Duplicate UID ($2): $users"; fi; done | wc -l) -ne 0 ]; then echo "-------------------"; echo "#cut -f3 -d\":\" /etc/passwd | sort -n | uniq -c | while read x ; do [ -z \"\$x\" ] && break; set - \$x; if [ \$1 -gt 1 ]; then users=\$(awk -F: '(\$3 == n) { print \$1 }' n=\$2 /etc/passwd | xargs); echo \"Duplicate UID (\$2): \$users\"; fi; done -eq 0 ";cut -f3 -d":" /etc/passwd | sort -n | uniq -c | while read x ; do [ -z "$x" ] && break; set - $x; if [ $1 -gt 1 ]; then users=$(awk -F: '($3 == n) { print $1 }' n=$2 /etc/passwd | xargs); echo "Duplicate UID ($2): $users"; fi; done; fi
echo "######################################"
else
echo "{\"6.2.3. Đảm bảo UID không bị lặp\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện câu lệnh sau để xác định các GID bị lặp trong file /etc/group:
# cut -d: -f3 /etc/group | sort | uniq -d | while read x ; do echo "Duplicate GID ($x) in /etc/group"; done
# Dựa theo kết quả trên, tạo ra một GID độc nhất và kiểm tra toàn bộ file sở hữu bởi GID bị trùng để xác định các file đó thuộc về GID nào.
# Có thể sử dụng lệnh grpck để kiểm tra các mâu thuẫn khác trong file/etc/group.
if [ $(cut -d: -f3 /etc/group | sort | uniq -d | while read x ; do echo "Duplicate GID ($x) in /etc/group"; done | wc -l) -ne 0 ]; then
echo "{\"6.2.4. Đảm bảo GID không bị lặp\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để xác định các GID bị lặp trong file /etc/group:
# cut -d: -f3 /etc/group | sort | uniq -d | while read x ; do echo \"Duplicate GID (\$x) in /etc/group\"; done
# Dựa theo kết quả trên, tạo ra một GID độc nhất và kiểm tra toàn bộ file sở hữu bởi GID bị trùng để xác định các file đó thuộc về GID nào.
# Có thể sử dụng lệnh grpck để kiểm tra các mâu thuẫn khác trong file/etc/group."
if [ $(cut -d: -f3 /etc/group | sort | uniq -d | while read x ; do echo "Duplicate GID ($x) in /etc/group"; done | wc -l) -ne 0 ]; then echo "-------------------"; echo "#cut -d: -f3 /etc/group | sort | uniq -d | while read x ; do echo \"Duplicate GID (\$x) in /etc/group\"; done -eq 0 ";cut -d: -f3 /etc/group | sort | uniq -d | while read x ; do echo "Duplicate GID ($x) in /etc/group"; done; fi
echo "######################################"
else
echo "{\"6.2.4. Đảm bảo GID không bị lặp\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện câu lệnh sau để xác định các username bị lặp trong file /etc/passwd:
# cut -d: -f1 /etc/passwd | sort | uniq -d | while read x; do echo "Duplicate username ${x} in /etc/passwd"; done
# Dựa theo kết quả trên, tạo ra một tên người dùng độc nhất cho người dùng. Quyền sở hữu của người dùng ở file sẽ tự động cập nhật thay đổi nếu người dùng có UID độc nhất.
if [ $(cut -d: -f1 /etc/passwd | sort | uniq -d | while read x; do echo "Duplicate username ${x} in /etc/passwd"; done | wc -l) -ne 0 ]; then
echo "{\"6.2.5. Đảm bảo tên người dùng không bị lặp\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để xác định các username bị lặp trong file /etc/passwd:
# cut -d: -f1 /etc/passwd | sort | uniq -d | while read x; do echo \"Duplicate username \${x} in /etc/passwd\"; done
# Dựa theo kết quả trên, tạo ra một tên người dùng độc nhất cho người dùng. Quyền sở hữu của người dùng ở file sẽ tự động cập nhật thay đổi nếu người dùng có UID độc nhất."
if [ $(cut -d: -f1 /etc/passwd | sort | uniq -d | while read x; do echo "Duplicate username ${x} in /etc/passwd"; done | wc -l) -ne 0 ]; then echo "-------------------"; echo "#cut -d: -f1 /etc/passwd | sort | uniq -d | while read x; do echo \"Duplicate username \${x} in /etc/passwd\"; done -eq 0 ";cut -d: -f1 /etc/passwd | sort | uniq -d | while read x; do echo "Duplicate username ${x} in /etc/passwd"; done; fi
echo "######################################"
else
echo "{\"6.2.5. Đảm bảo tên người dùng không bị lặp\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện câu lệnh sau để xác định các username bị lặp trong file /etc/group:
# cut -d: -f1 /etc/group | sort | uniq -d | while read -r x; do echo "Duplicate group name ${x} in /etc/group"; done
# Dựa theo kết quả trên, tạo ra một tên group độc nhất cho người dùng. Quyền sở hữu của group ở file sẽ tự động cập nhật thay đổi nếu group có GID độc nhất.
if [ $(cut -d: -f1 /etc/group | sort | uniq -d | while read -r x; do echo "Duplicate group name ${x} in /etc/group"; done | wc -l) -ne 0 ]; then
echo "{\"6.2.6. Đảm bảo tên group không bị lặp\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện câu lệnh sau để xác định các username bị lặp trong file /etc/group:
# cut -d: -f1 /etc/group | sort | uniq -d | while read -r x; do echo \"Duplicate group name \${x} in /etc/group\"; done
# Dựa theo kết quả trên, tạo ra một tên group độc nhất cho người dùng. Quyền sở hữu của group ở file sẽ tự động cập nhật thay đổi nếu group có GID độc nhất."
if [ $(cut -d: -f1 /etc/group | sort | uniq -d | while read -r x; do echo "Duplicate group name ${x} in /etc/group"; done | wc -l) -ne 0 ]; then echo "-------------------"; echo "#cut -d: -f1 /etc/group | sort | uniq -d | while read -r x; do echo \"Duplicate group name \${x} in /etc/group\"; done -eq 0 ";cut -d: -f1 /etc/group | sort | uniq -d | while read -r x; do echo "Duplicate group name ${x} in /etc/group"; done; fi
echo "######################################"
else
echo "{\"6.2.6. Đảm bảo tên group không bị lặp\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện đoạn script sau để kiểm tra tính toàn vẹn cho môi trường PATH của root:
# RPCV="$(sudo -Hiu root env 2>/dev/null | grep '^PATH=' | cut -d= -f2)"; echo "$RPCV" | grep -q "::" && echo "root's path contains a empty directory (::)"; echo "$RPCV" | grep -q ":$" && echo "root's path contains a trailing (:)" ; for x in $(echo "$RPCV" | tr ":" " "); do if [ -d "$x" ]; then ls -ldH "$x" | awk '$9 == "." {print "PATH contains current working directory (.)"} $3 != "root" {print $9, "is not owned by root"} substr($1,6,1) != "-" {print $9, "is group writable"} substr($1,9,1) != "-" {print $9, "is world writable"}'; else echo "$x is not a directory"; fi; done
# Sửa chữa hoặc lý giải kết quả tìm được.
if [ $(RPCV="$(sudo -Hiu root env 2>/dev/null | grep '^PATH=' | cut -d= -f2)"; echo "$RPCV" | grep -q "::" && echo "root's path contains a empty directory (::)"; echo "$RPCV" | grep -q ":$" && echo "root's path contains a trailing (:)" ; for x in $(echo "$RPCV" | tr ":" " "); do if [ -d "$x" ]; then ls -ldH "$x" | awk '$9 == "." {print "PATH contains current working directory (.)"} $3 != "root" {print $9, "is not owned by root"} substr($1,6,1) != "-" {print $9, "is group writable"} substr($1,9,1) != "-" {print $9, "is world writable"}'; else echo "$x is not a directory"; fi; done | grep -v "/root/bin" | wc -l) -ne 0 ]; then
echo "{\"6.2.7. Đảm bảo tính toàn vẹn cho biến môi trường PATH của root\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện đoạn script sau để kiểm tra tính toàn vẹn cho môi trường PATH của root:
# RPCV=\"\$(sudo -Hiu root env 2>/dev/null | grep '^PATH=' | cut -d= -f2)\"; echo \"\$RPCV\" | grep -q \"::\" && echo \"root's path contains a empty directory (::)\"; echo \"\$RPCV\" | grep -q \":\$\" && echo \"root's path contains a trailing (:)\" ; for x in \$(echo \"\$RPCV\" | tr \":\" \" \"); do if [ -d \"\$x\" ]; then ls -ldH \"\$x\" | awk '\$9 == \".\" {print \"PATH contains current working directory (.)\"} \$3 != \"root\" {print \$9, \"is not owned by root\"} substr(\$1,6,1) != \"-\" {print \$9, \"is group writable\"} substr(\$1,9,1) != \"-\" {print \$9, \"is world writable\"}'; else echo \"\$x is not a directory\"; fi; done
# Sửa chữa hoặc lý giải kết quả tìm được."
if [ $(RPCV="$(sudo -Hiu root env 2>/dev/null | grep '^PATH=' | cut -d= -f2)"; echo "$RPCV" | grep -q "::" && echo "root's path contains a empty directory (::)"; echo "$RPCV" | grep -q ":$" && echo "root's path contains a trailing (:)" ; for x in $(echo "$RPCV" | tr ":" " "); do if [ -d "$x" ]; then ls -ldH "$x" | awk '$9 == "." {print "PATH contains current working directory (.)"} $3 != "root" {print $9, "is not owned by root"} substr($1,6,1) != "-" {print $9, "is group writable"} substr($1,9,1) != "-" {print $9, "is world writable"}'; else echo "$x is not a directory"; fi; done | grep -v "/root/bin" | wc -l) -ne 0 ]; then echo "-------------------"; echo "#RPCV=\"\$(sudo -Hiu root env 2>/dev/null | grep '^PATH=' | cut -d= -f2)\"; echo \"\$RPCV\" | grep -q \"::\" && echo \"root's path contains a empty directory (::)\"; echo \"\$RPCV\" | grep -q \":\$\" && echo \"root's path contains a trailing (:)\" ; for x in \$(echo \"\$RPCV\" | tr \":\" \" \"); do if [ -d \"\$x\" ]; then ls -ldH \"\$x\" | awk '\$9 == \".\" {print \"PATH contains current working directory (.)\"} \$3 != \"root\" {print \$9, \"is not owned by root\"} substr(\$1,6,1) != \"-\" {print \$9, \"is group writable\"} substr(\$1,9,1) != \"-\" {print \$9, \"is world writable\"}'; else echo \"\$x is not a directory\"; fi; done | grep -v \"/root/bin\" -eq 0 ";RPCV="$(sudo -Hiu root env 2>/dev/null | grep '^PATH=' | cut -d= -f2)"; echo "$RPCV" | grep -q "::" && echo "root's path contains a empty directory (::)"; echo "$RPCV" | grep -q ":$" && echo "root's path contains a trailing (:)" ; for x in $(echo "$RPCV" | tr ":" " "); do if [ -d "$x" ]; then ls -ldH "$x" | awk '$9 == "." {print "PATH contains current working directory (.)"} $3 != "root" {print $9, "is not owned by root"} substr($1,6,1) != "-" {print $9, "is group writable"} substr($1,9,1) != "-" {print $9, "is world writable"}'; else echo "$x is not a directory"; fi; done | grep -v "/root/bin"; fi
echo "######################################"
else
echo "{\"6.2.7. Đảm bảo tính toàn vẹn cho biến môi trường PATH của root\" : \"PASSED\"}"
fi
############################################################################
# Loại bỏ bất kỳ user nào ngoài root có UID là 0 hoặc chỉ định chúng một UID mới, phù hợp với chính sách của tổ chức.
if [ $(cat /etc/passwd | awk -F: '$3==0 {print $1}' | grep -v "root" | wc -l) -ne 0 ]; then
echo "{\"6.2.8. Đảm bảo root là tài khoản duy nhất có UID là 0\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Loại bỏ bất kỳ user nào ngoài root có UID là 0 hoặc chỉ định chúng một UID mới, phù hợp với chính sách của tổ chức."
if [ $(cat /etc/passwd | awk -F: '$3==0 {print $1}' | grep -v "root" | wc -l) -ne 0 ]; then echo "-------------------"; echo "#cat /etc/passwd | awk -F: '\$3==0 {print \$1}' | grep -v \"root\" -eq 0 ";cat /etc/passwd | awk -F: '$3==0 {print $1}' | grep -v "root"; fi
echo "######################################"
else
echo "{\"6.2.8. Đảm bảo root là tài khoản duy nhất có UID là 0\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện đoạn script sau để tạo và đảm bảo người dùng tương ứng sở hữu thư mục đó. Những người dùng không có thư mục home nên bị xóa hoặc chỉ định họ một thư mục home phù hợp:
# awk -F: '($1!~/(halt|sync|shutdown|nfsnobody)/ && $7!~/^(\/usr)?\/sbin\/nologin(\/)?$/ && $7!~/(\/usr)?\/bin\/false(\/)?$/) { print $1 " " $6 }' /etc/passwd | while read -r user dir; do if [ ! -d "$dir" ]; then mkdir "$dir"; chmod g-w,o-wrx "$dir"; chown "$user" "$dir"; fi; done
if [ $(awk -F: '($1!~/(halt|sync|shutdown|nfsnobody)/ && $7!~/^(\/usr)?\/sbin\/nologin(\/)?$/ && $7!~/(\/usr)?\/bin\/false(\/)?$/) { print $1 " " $6 }' /etc/passwd | while read -r user dir; do if [ ! -d "$dir" ]; then mkdir "$dir"; chmod g-w,o-wrx "$dir"; chown "$user" "$dir"; fi; done | wc -l) -ne 0 ]; then
echo "{\"6.2.9. Đảm bảo mọi người dùng đều tồn tại thư mục home\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện đoạn script sau để tạo và đảm bảo người dùng tương ứng sở hữu thư mục đó. Những người dùng không có thư mục home nên bị xóa hoặc chỉ định họ một thư mục home phù hợp:
# awk -F: '(\$1\!~/(halt|sync|shutdown|nfsnobody)/ && \$7\!~/^(\\/usr)?\\/sbin\\/nologin(\\/)?\$/ && \$7\!~/(\\/usr)?\\/bin\\/false(\\/)?\$/) { print \$1 \" \" \$6 }' /etc/passwd | while read -r user dir; do if [ ! -d \"\$dir\" ]; then mkdir \"\$dir\"; chmod g-w,o-wrx \"\$dir\"; chown \"\$user\" \"\$dir\"; fi; done"
if [ $(awk -F: '($1!~/(halt|sync|shutdown|nfsnobody)/ && $7!~/^(\/usr)?\/sbin\/nologin(\/)?$/ && $7!~/(\/usr)?\/bin\/false(\/)?$/) { print $1 " " $6 }' /etc/passwd | while read -r user dir; do if [ ! -d "$dir" ]; then mkdir "$dir"; chmod g-w,o-wrx "$dir"; chown "$user" "$dir"; fi; done | wc -l) -ne 0 ]; then echo "-------------------"; echo "#awk -F: '(\$1\!~/(halt|sync|shutdown|nfsnobody)/ && \$7\!~/^(\\/usr)?\\/sbin\\/nologin(\\/)?\$/ && \$7\!~/(\\/usr)?\\/bin\\/false(\\/)?\$/) { print \$1 \" \" \$6 }' /etc/passwd | while read -r user dir; do if [ ! -d \"\$dir\" ]; then mkdir \"\$dir\"; chmod g-w,o-wrx \"\$dir\"; chown \"\$user\" \"\$dir\"; fi; done -eq 0 ";awk -F: '($1!~/(halt|sync|shutdown|nfsnobody)/ && $7!~/^(\/usr)?\/sbin\/nologin(\/)?$/ && $7!~/(\/usr)?\/bin\/false(\/)?$/) { print $1 " " $6 }' /etc/passwd | while read -r user dir; do if [ ! -d "$dir" ]; then mkdir "$dir"; chmod g-w,o-wrx "$dir"; chown "$user" "$dir"; fi; done; fi
echo "######################################"
else
echo "{\"6.2.9. Đảm bảo mọi người dùng đều tồn tại thư mục home\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện đoạn script sau để tạo hoặc thay đổi quyền sở hữu của bất kỳ thư mục home nào không được sở hữu bởi người dùng được định danh sang đúng người dùng:
# awk -F: '($1!~/(halt|sync|shutdown|nfsnobody)/ && $7!~/^(\/usr)?\/sbin\/nologin(\/)?$/ && $7!~/(\/usr)?\/bin\/false(\/)?$/) { print $1 " " $6 }' /etc/passwd | while read -r user dir; do if [ ! -d "$dir" ]; then echo "User: "$user" home directory: "$dir" does not exist "; mkdir "$dir"; chmod g-w,o-rwx "$dir"; chown "$user" "$dir"; else owner=$(stat -L -c "%U" "$dir"); if [ "$owner" != "$user" ]; then chmod g-w,o-rwx "$dir"; chown "$user" "$dir"; fi; fi; done
if [ $(awk -F: '($1!~/(halt|sync|shutdown|nfsnobody)/ && $7!~/^(\/usr)?\/sbin\/nologin(\/)?$/ && $7!~/(\/usr)?\/bin\/false(\/)?$/) { print $1 " " $6 }' /etc/passwd | while read -r user dir; do if [ ! -d "$dir" ]; then echo "User: $user home directory: $dir does not exist "; mkdir "$dir"; chmod g-w,o-rwx "$dir"; chown "$user" "$dir"; else owner=$(stat -L -c "%U" "$dir"); if [ "$owner" != "$user" ]; then chmod g-w,o-rwx "$dir"; chown "$user" "$dir"; fi; fi; done | wc -l) -ne 0 ]; then
echo "{\"6.2.10. Đảm bảo người dùng sở hữu thư mục home của chính họ\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện đoạn script sau để tạo hoặc thay đổi quyền sở hữu của bất kỳ thư mục home nào không được sở hữu bởi người dùng được định danh sang đúng người dùng:
# awk -F: '(\$1\!~/(halt|sync|shutdown|nfsnobody)/ && \$7\!~/^(\\/usr)?\\/sbin\\/nologin(\\/)?\$/ && \$7\!~/(\\/usr)?\\/bin\\/false(\\/)?\$/) { print \$1 \" \" \$6 }' /etc/passwd | while read -r user dir; do if [ ! -d \"\$dir\" ]; then echo \"User: \"\$user\" home directory: \"\$dir\" does not exist \"; mkdir \"\$dir\"; chmod g-w,o-rwx \"\$dir\"; chown \"\$user\" \"\$dir\"; else owner=\$(stat -L -c \"%U\" \"\$dir\"); if [ \"\$owner\" != \"\$user\" ]; then chmod g-w,o-rwx \"\$dir\"; chown \"\$user\" \"\$dir\"; fi; fi; done"
if [ $(awk -F: '($1!~/(halt|sync|shutdown|nfsnobody)/ && $7!~/^(\/usr)?\/sbin\/nologin(\/)?$/ && $7!~/(\/usr)?\/bin\/false(\/)?$/) { print $1 " " $6 }' /etc/passwd | while read -r user dir; do if [ ! -d "$dir" ]; then echo "User: $user home directory: $dir does not exist "; mkdir "$dir"; chmod g-w,o-rwx "$dir"; chown "$user" "$dir"; else owner=$(stat -L -c "%U" "$dir"); if [ "$owner" != "$user" ]; then chmod g-w,o-rwx "$dir"; chown "$user" "$dir"; fi; fi; done | wc -l) -ne 0 ]; then echo "-------------------"; echo "#awk -F: '(\$1\!~/(halt|sync|shutdown|nfsnobody)/ && \$7\!~/^(\\/usr)?\\/sbin\\/nologin(\\/)?\$/ && \$7\!~/(\\/usr)?\\/bin\\/false(\\/)?\$/) { print \$1 \" \" \$6 }' /etc/passwd | while read -r user dir; do if [ ! -d \"\$dir\" ]; then echo \"User: \$user home directory: \$dir does not exist \"; mkdir \"\$dir\"; chmod g-w,o-rwx \"\$dir\"; chown \"\$user\" \"\$dir\"; else owner=\$(stat -L -c \"%U\" \"\$dir\"); if [ \"\$owner\" != \"\$user\" ]; then chmod g-w,o-rwx \"\$dir\"; chown \"\$user\" \"\$dir\"; fi; fi; done -eq 0 ";awk -F: '($1!~/(halt|sync|shutdown|nfsnobody)/ && $7!~/^(\/usr)?\/sbin\/nologin(\/)?$/ && $7!~/(\/usr)?\/bin\/false(\/)?$/) { print $1 " " $6 }' /etc/passwd | while read -r user dir; do if [ ! -d "$dir" ]; then echo "User: $user home directory: $dir does not exist "; mkdir "$dir"; chmod g-w,o-rwx "$dir"; chown "$user" "$dir"; else owner=$(stat -L -c "%U" "$dir"); if [ "$owner" != "$user" ]; then chmod g-w,o-rwx "$dir"; chown "$user" "$dir"; fi; fi; done; fi
echo "######################################"
else
echo "{\"6.2.10. Đảm bảo người dùng sở hữu thư mục home của chính họ\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện đoạn script sau để đặt quyền cho thư mục home của tất cả người dùng là 750:
# awk -F: '($1!~/(halt|sync|shutdown|nfsnobody)/ && $7!~/^(\/usr)?\/sbin\/nologin(\/)?$/ && $7!~/(\/usr)?\/bin\/false(\/)?$/) {print $6}' /etc/passwd | while read -r dir; do if [ -d "$dir" ]; then dirperm=$(stat -L -c "%A" "$dir"); if [ "$(echo "$dirperm" | cut -c6)" != "-" ] || [ "$(echo "$dirperm" | cut -c8)" != "-" ] || [ "$(echo "$dirperm" | cut -c9)" != "-" ] || [ "$(echo "$dirperm" | cut -c10)" != "-" ]; then chmod g-w,o-rwx "$dir"; fi; fi; done
if [ $(awk -F: '($1!~/(halt|sync|shutdown|nfsnobody)/ && $7!~/^(\/usr)?\/sbin\/nologin(\/)?$/ && $7!~/(\/usr)?\/bin\/false(\/)?$/) {print $1 " " $6}' /etc/passwd | while read -r user dir; do if [ ! -d "$dir" ]; then echo "User: \"$user\" home directory: \"$dir\" doesn't exist"; else dirperm=$(stat -L -c "%A" "$dir"); if [ "$(echo "$dirperm" | cut -c6)" != "-" ] || [ "$(echo "$dirperm" | cut -c8)" != "-" ] || [ "$(echo "$dirperm" | cut -c9)" != "-" ] || [ "$(echo "$dirperm" | cut -c10)" != "-" ]; then echo "User: \"$user\" home directory: \"$dir\" has permissions: \"$(stat -L -c "%a" "$dir")\""; fi; fi; done | wc -l) -ne 0 ]; then
echo "{\"6.2.11. Đảm bảo quyền thư mục home của người dùng có mức bảo mật cao\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện đoạn script sau để đặt quyền cho thư mục home của tất cả người dùng là 750:
# awk -F: '(\$1\!~/(halt|sync|shutdown|nfsnobody)/ && \$7\!~/^(\\/usr)?\\/sbin\\/nologin(\\/)?\$/ && \$7\!~/(\\/usr)?\\/bin\\/false(\\/)?\$/) {print \$6}' /etc/passwd | while read -r dir; do if [ -d \"\$dir\" ]; then dirperm=\$(stat -L -c \"%A\" \"\$dir\"); if [ \"\$(echo \"\$dirperm\" | cut -c6)\" != \"-\" ] || [ \"\$(echo \"\$dirperm\" | cut -c8)\" != \"-\" ] || [ \"\$(echo \"\$dirperm\" | cut -c9)\" != \"-\" ] || [ \"\$(echo \"\$dirperm\" | cut -c10)\" != \"-\" ]; then chmod g-w,o-rwx \"\$dir\"; fi; fi; done"
if [ $(awk -F: '($1!~/(halt|sync|shutdown|nfsnobody)/ && $7!~/^(\/usr)?\/sbin\/nologin(\/)?$/ && $7!~/(\/usr)?\/bin\/false(\/)?$/) {print $1 " " $6}' /etc/passwd | while read -r user dir; do if [ ! -d "$dir" ]; then echo "User: \"$user\" home directory: \"$dir\" doesn't exist"; else dirperm=$(stat -L -c "%A" "$dir"); if [ "$(echo "$dirperm" | cut -c6)" != "-" ] || [ "$(echo "$dirperm" | cut -c8)" != "-" ] || [ "$(echo "$dirperm" | cut -c9)" != "-" ] || [ "$(echo "$dirperm" | cut -c10)" != "-" ]; then echo "User: \"$user\" home directory: \"$dir\" has permissions: \"$(stat -L -c "%a" "$dir")\""; fi; fi; done | wc -l) -ne 0 ]; then echo "-------------------"; echo "#awk -F: '(\$1\!~/(halt|sync|shutdown|nfsnobody)/ && \$7\!~/^(\\/usr)?\\/sbin\\/nologin(\\/)?\$/ && \$7\!~/(\\/usr)?\\/bin\\/false(\\/)?\$/) {print \$1 \" \" \$6}' /etc/passwd | while read -r user dir; do if [ ! -d \"\$dir\" ]; then echo \"User: \\\"\$user\\\" home directory: \\\"\$dir\\\" doesn't exist\"; else dirperm=\$(stat -L -c \"%A\" \"\$dir\"); if [ \"\$(echo \"\$dirperm\" | cut -c6)\" != \"-\" ] || [ \"\$(echo \"\$dirperm\" | cut -c8)\" != \"-\" ] || [ \"\$(echo \"\$dirperm\" | cut -c9)\" != \"-\" ] || [ \"\$(echo \"\$dirperm\" | cut -c10)\" != \"-\" ]; then echo \"User: \\\"\$user\\\" home directory: \\\"\$dir\\\" has permissions: \\\"\$(stat -L -c \"%a\" \"\$dir\")\\\"\"; fi; fi; done -eq 0 ";awk -F: '($1!~/(halt|sync|shutdown|nfsnobody)/ && $7!~/^(\/usr)?\/sbin\/nologin(\/)?$/ && $7!~/(\/usr)?\/bin\/false(\/)?$/) {print $1 " " $6}' /etc/passwd | while read -r user dir; do if [ ! -d "$dir" ]; then echo "User: \"$user\" home directory: \"$dir\" doesn't exist"; else dirperm=$(stat -L -c "%A" "$dir"); if [ "$(echo "$dirperm" | cut -c6)" != "-" ] || [ "$(echo "$dirperm" | cut -c8)" != "-" ] || [ "$(echo "$dirperm" | cut -c9)" != "-" ] || [ "$(echo "$dirperm" | cut -c10)" != "-" ]; then echo "User: \"$user\" home directory: \"$dir\" has permissions: \"$(stat -L -c "%a" "$dir")\""; fi; fi; done; fi
echo "######################################"
else
echo "{\"6.2.11. Đảm bảo quyền thư mục home của người dùng có mức bảo mật cao\" : \"PASSED\"}"
fi
############################################################################
# Thực hiện đoạn script sau để loại bỏ quyền ghi các file dot của group và other:
# awk -F: '($1!~/(halt|sync|shutdown)/ && $7!~/^(\/usr)?\/sbin\/nologin(\/)?$/ && $7!~/(\/usr)?\/bin\/false(\/)?$/) { print $1 " " $6 }' /etc/passwd | while read -r user dir; do if [ -d "$dir" ]; then for file in "$dir"/.*; do if [ ! -h "$file" ] && [ -f "$file" ]; then fileperm=$(stat -L -c "%A" "$file"); if [ "$(echo "$fileperm" | cut -c6)" != "-" ] || [ "$(echo "$fileperm" | cut -c9)" != "-" ]; then chmod go-w "$file"; fi; fi; done; fi; done
if [ $(find /home/ -name ".[A-Za-z0-9]*" -perm /g+w,o+w | wc -l) -ne 0 ]; then
echo "{\"6.2.12. Đảm bảo các file dot của người dùng không cấp quyền write cho group hoặc other\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Thực hiện đoạn script sau để loại bỏ quyền ghi các file dot của group và other:
# awk -F: '(\$1\!~/(halt|sync|shutdown)/ && \$7\!~/^(\\/usr)?\\/sbin\\/nologin(\\/)?\$/ && \$7\!~/(\\/usr)?\\/bin\\/false(\\/)?\$/) { print \$1 \" \" \$6 }' /etc/passwd | while read -r user dir; do if [ -d \"\$dir\" ]; then for file in \"\$dir\"/.*; do if [ ! -h \"\$file\" ] && [ -f \"\$file\" ]; then fileperm=\$(stat -L -c \"%A\" \"\$file\"); if [ \"\$(echo \"\$fileperm\" | cut -c6)\" != \"-\" ] || [ \"\$(echo \"\$fileperm\" | cut -c9)\" != \"-\" ]; then chmod go-w \"\$file\"; fi; fi; done; fi; done"
if [ $(find /home/ -name ".[A-Za-z0-9]*" -perm /g+w,o+w | wc -l) -ne 0 ]; then echo "-------------------"; echo "#find /home/ -name \".[A-Za-z0-9]*\" -perm /g+w,o+w -eq 0 ";find /home/ -name ".[A-Za-z0-9]*" -perm /g+w,o+w; fi
echo "######################################"
else
echo "{\"6.2.12. Đảm bảo các file dot của người dùng không cấp quyền write cho group hoặc other\" : \"PASSED\"}"
fi
############################################################################
# Việc chỉnh sửa toàn cục cho thư mục của người dùng mà không báo trước có thể khiến người dùng không hài lòng. Bởi vậy, khuyến nghị tạo nên một chính sách theo dõi để báo cáo file .forward của người dùng và xác định hành động nên làm theo chính sách.
if [ $(find /home/ -type f -name "*.forward" 2>/dev/null | wc -l) -ne 0 ]; then
echo "{\"6.2.13. Đảm bảo không người dùng nào có file .forward\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Việc chỉnh sửa toàn cục cho thư mục của người dùng mà không báo trước có thể khiến người dùng không hài lòng. Bởi vậy, khuyến nghị tạo nên một chính sách theo dõi để báo cáo file .forward của người dùng và xác định hành động nên làm theo chính sách."
if [ $(find /home/ -type f -name "*.forward" 2>/dev/null | wc -l) -ne 0 ]; then echo "-------------------"; echo "#find /home/ -type f -name \"*.forward\" 2>/dev/null -eq 0 ";find /home/ -type f -name "*.forward" 2>/dev/null; fi
echo "######################################"
else
echo "{\"6.2.13. Đảm bảo không người dùng nào có file .forward\" : \"PASSED\"}"
fi
############################################################################
# Việc chỉnh sửa toàn cục cho thư mục của người dùng mà không báo trước có thể khiến người dùng không hài lòng. Bởi vậy, khuyến nghị tạo nên một chính sách theo dõi để báo cáo file .netrc của người dùng và xác định hành động nên làm theo chính sách.
if [ $(find /home -name ".netrc" | wc -l) -ne 0 ]; then
echo "{\"6.2.14. Đảm bảo không người dùng nào có file .netrc\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Việc chỉnh sửa toàn cục cho thư mục của người dùng mà không báo trước có thể khiến người dùng không hài lòng. Bởi vậy, khuyến nghị tạo nên một chính sách theo dõi để báo cáo file .netrc của người dùng và xác định hành động nên làm theo chính sách."
if [ $(find /home -name ".netrc" | wc -l) -ne 0 ]; then echo "-------------------"; echo "#find /home -name \".netrc\" -eq 0 ";find /home -name ".netrc"; fi
echo "######################################"
else
echo "{\"6.2.14. Đảm bảo không người dùng nào có file .netrc\" : \"PASSED\"}"
fi
############################################################################
# Việc chỉnh sửa toàn cục cho thư mục của người dùng mà không báo trước có thể khiến người dùng không hài lòng. Bởi vậy, khuyến nghị tạo nên một chính sách theo dõi để báo cáo file .rhost của người dùng và xác định hành động nên làm theo chính sách.
if [ $(find /home -name ".rhosts" | wc -l) -ne 0 ]; then
echo "{\"6.2.15. Đảm bảo không người dùng nào có file .rhosts\" : \"FAILED\"}"
# Log
echo "######################################"
echo "# Việc chỉnh sửa toàn cục cho thư mục của người dùng mà không báo trước có thể khiến người dùng không hài lòng. Bởi vậy, khuyến nghị tạo nên một chính sách theo dõi để báo cáo file .rhost của người dùng và xác định hành động nên làm theo chính sách."
if [ $(find /home -name ".rhosts" | wc -l) -ne 0 ]; then echo "-------------------"; echo "#find /home -name \".rhosts\" -eq 0 ";find /home -name ".rhosts"; fi
echo "######################################"
else
echo "{\"6.2.15. Đảm bảo không người dùng nào có file .rhosts\" : \"PASSED\"}"
fi