{"id":31,"date":"2018-11-19T07:01:14","date_gmt":"2018-11-19T07:01:14","guid":{"rendered":"http:\/\/www.unordnung.net\/?p=31"},"modified":"2018-11-19T07:01:14","modified_gmt":"2018-11-19T07:01:14","slug":"linux-security-audit-mit-cisofy-lynis","status":"publish","type":"post","link":"https:\/\/unordnung.net\/misc\/2018\/11\/linux-security-audit-mit-cisofy-lynis\/","title":{"rendered":"Linux security audit mit CISOfy Lynis"},"content":{"rendered":"<p>MIt Lynis kann man sich wunderbar an ein sicheres System herantasten und sich einige Tips holen. Nachdem man lynis installiert hat, kann man mittels <em>lynis audit system <\/em>einen Report bekommen, der erz\u00e4hlt einem vieles \u00fcber das eigene System.<\/p>\n<blockquote><p><em>[+] File systems<\/em><br \/>\n<em>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/em><br \/>\n<em>&#8211; Checking mount points<\/em><br \/>\n<em>&#8211; Checking \/home mount point [ OK ]<\/em><br \/>\n<em>&#8211; Checking \/tmp mount point [ OK ]<\/em><br \/>\n<em>&#8211; Checking \/var mount point [ OK ]<\/em><br \/>\n<em>&#8211; Query swap partitions (fstab) [ OK ]<\/em><br \/>\n<em>&#8211; Testing swap partitions [ OK ]<\/em><br \/>\n<em>&#8211; Testing \/proc mount (hidepid) [ VORSCHLAG ]<\/em><br \/>\n<em>&#8211; Checking for old files in \/tmp [ OK ]<\/em><br \/>\n<em>&#8211; Checking \/tmp sticky bit [ OK ]<\/em><br \/>\n<em>&#8211; Checking \/var\/tmp sticky bit [ OK ]<\/em><br \/>\n<em>&#8211; ACL support root file system [ AKTIVIERT ]<\/em><br \/>\n<em>&#8211; Mount options of \/ [ NON DEFAULT ]<\/em><br \/>\n<em>&#8211; Mount options of \/home [ NON DEFAULT ]<\/em><br \/>\n<em>&#8211; Mount options of \/tmp [ NON DEFAULT ]<\/em><br \/>\n<em>&#8211; Mount options of \/var [ NON DEFAULT ]<\/em><br \/>\n<em>&#8211; Disable kernel support of some filesystems<\/em><br \/>\n<em>&#8211; Discovered kernel modules: freevxfs hfs hfsplus jffs2 squashfs udf<\/em><\/p><\/blockquote>\n<p>Z.B. sollte ich mich mal mit hidepid besch\u00e4ftigen. https:\/\/linux-audit.com\/linux-system-hardening-adding-hidepid-to-proc\/ Die netten Leute von Lynis stellen auch noch einen Blog bereit in dem man Tips zur L\u00f6sung gefundener Sicherheitsprobleme finde kann. Danke @<a href=\"https:\/\/cisofy.com\/\">CISOfy<\/a><br \/>\nIch werde bei Gelegenheit auf einzelne Punkte des Scans eingehen.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>MIt Lynis kann man sich wunderbar an ein sicheres System herantasten und sich einige Tips holen. Nachdem man lynis installiert hat, kann man mittels lynis audit system einen Report bekommen, der erz\u00e4hlt einem vieles \u00fcber das eigene System. [+] File systems &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212; &#8211; Checking mount points &#8211; Checking \/home mount point [ OK ] &#8211; &#8230; <a title=\"Linux security audit mit CISOfy Lynis\" class=\"read-more\" href=\"https:\/\/unordnung.net\/misc\/2018\/11\/linux-security-audit-mit-cisofy-lynis\/\">Read more<span class=\"screen-reader-text\">Linux security audit mit CISOfy Lynis<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[9,31,46,50,54,64],"class_list":["post-31","post","type-post","status-publish","format-standard","hentry","category-to_remember","tag-audit","tag-hardening","tag-linux","tag-lynis","tag-open-source","tag-security"],"_links":{"self":[{"href":"https:\/\/unordnung.net\/misc\/wp-json\/wp\/v2\/posts\/31","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unordnung.net\/misc\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unordnung.net\/misc\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unordnung.net\/misc\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/unordnung.net\/misc\/wp-json\/wp\/v2\/comments?post=31"}],"version-history":[{"count":0,"href":"https:\/\/unordnung.net\/misc\/wp-json\/wp\/v2\/posts\/31\/revisions"}],"wp:attachment":[{"href":"https:\/\/unordnung.net\/misc\/wp-json\/wp\/v2\/media?parent=31"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unordnung.net\/misc\/wp-json\/wp\/v2\/categories?post=31"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unordnung.net\/misc\/wp-json\/wp\/v2\/tags?post=31"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}