- checkrestart [ Not Installed ]

10/17/2019

report.html

[ Lynis 2.7.5 ]

################################################################################

Lynis comes with ABSOLUTELY NO WARRANTY. This is free software, and you are

welcome to redistribute it under the terms of the GNU General Public License.

See the LICENSE file for details about using this software.

2007-2019, CISOfy -

Enterprise support available (compliance, plugins, interface and tools)

################################################################################

[+] Initializing program

------------------------------------ Detecting OS...

- Checking profiles...

--------------------------------------------------Program version:

2.7.5

Operating system:

Linux

Operating system name:

Ubuntu Linux

Operating system version: 18.04

Kernel version:

4.15.0

Hardware platform:

x86_64

Hostname:

pc07

--------------------------------------------------Profiles:

/etc/lynis/default.prf

Log file:

/var/log/lynis.log

Report file:

/var/log/lynis-report.dat

Report version:

1.0

Plugin directory:

/etc/lynis/plugins

--------------------------------------------------Auditor:

[Not Specified]

Language:

en

Test category:

all

Test group:

all

--------------------------------------------------- Program update status...

[ DONE ]

[ DONE ]

[ NO UPDATE ]

[+] System Tools

------------------------------------ Scanning available tools...

- Checking system binaries...

[+] Plugins (phase 1)

-----------------------------------Note: plugins have more extensive tests and may take several minutes to complete

- Plugin: debian

[

[+] Debian Tests

------------------------------------ Checking for system binaries that are required by Debian Tests...

- Checking /bin...

[ FOUND ]

- Checking /sbin...

[ FOUND ]

- Checking /usr/bin...

[ FOUND ]

- Checking /usr/sbin...

[ FOUND ]

- Checking /usr/local/bin...

[ FOUND ]

- Checking /usr/local/sbin...

[ FOUND ]

- Authentication:

- PAM (Pluggable Authentication Modules):

- libpam-tmpdir

[ Not Installed

- libpam-usb

[ Not Installed

- File System Checks:

- DM-Crypt, Cryptsetup & Cryptmount:

- Software:

- apt-listbugs

[ Not Installed

- apt-listchanges

[ Not Installed

- checkrestart

[ Not Installed

?le:///home/moose/report.html

]

]

]

]

]

1/10

10/17/2019

report.html

- needrestart

- debsecan

cron ]

- debsums

cron ]

- fail2ban

]

[+] Boot and services

------------------------------------ Service Manager

- Checking UEFI boot

- Checking presence GRUB2

- Checking for password protection

- Check running services (systemctl)

Result: found 44 running services

- Check enabled services at boot (systemctl)

Result: found 71 enabled services

- Check startup files (permissions)

[+] Kernel

------------------------------------ Checking default run level

- Checking CPU support (NX/PAE)

CPU support: PAE and/or NoeXecute supported

- Checking kernel version and release

- Checking kernel type

- Checking loaded kernel modules

Found 126 active modules

- Checking Linux kernel configuration file

- Checking default I/O kernel scheduler

- Checking for available kernel update

- Checking core dumps configuration

- Checking setuid core dumps configuration

- Check if reboot is needed

[+] Memory and Processes

------------------------------------ Checking /proc/meminfo

- Searching for dead/zombie processes

- Searching for IO waiting processes

[+] Users, Groups and Authentication

------------------------------------ Administrator accounts

- Unique UIDs

- Consistency of group files (grpck)

- Unique group IDs

- Unique group names

- Password file consistency

- Query system users (non daemons)

- NIS+ authentication support

- NIS authentication support

- sudoers file

- Permissions for directory: /etc/sudoers.d

- Permissions for: /etc/sudoers

- Permissions for: /etc/sudoers.d/README

- PAM password strength tools

- PAM configuration files (pam.conf)

- PAM configuration files (pam.d)

- PAM modules

- LDAP module in PAM

- Accounts without expire date

- Accounts without password

- Checking user password aging (minimum)

- User password aging (maximum)

- Checking expired passwords

- Checking Linux single user mode authentication

- Determining default umask

- umask (/etc/profile)

?le:///home/moose/report.html

[ Not Installed ]

[ Installed and enabled for

[ Installed and enabled for

[ Not Installed ]

[

[

[

[

[

systemd ]

DISABLED ]

FOUND ]

NONE ]

DONE ]

[ DONE ]

[ OK ]

[ RUNLEVEL 5 ]

[

[

[

[

FOUND ]

DONE ]

DONE ]

DONE ]

[

[

[

[

[

[

FOUND ]

FOUND ]

OK ]

DISABLED ]

PROTECTED ]

NO ]

[ FOUND ]

[ OK ]

[ OK ]

[

[

[

[

[

[

[

[

[

[

[

[

[

[

[

[

[

[

[

[

[

[

[

[

OK ]

OK ]

OK ]

OK ]

OK ]

OK ]

DONE ]

NOT ENABLED ]

NOT ENABLED ]

FOUND ]

WARNING ]

OK ]

OK ]

SUGGESTION ]

FOUND ]

FOUND ]

FOUND ]

NOT FOUND ]

OK ]

OK ]

DISABLED ]

DISABLED ]

OK ]

OK ]

[ NOT FOUND ]

2/10

10/17/2019

report.html

- umask (/etc/login.defs)

- LDAP authentication support

- Logging failed login attempts

[+] Shells

------------------------------------ Checking shells from /etc/shells

Result: found 7 shells (valid shells: 7).

- Session timeout settings/tools

- Checking default umask values

- Checking default umask in /etc/bash.bashrc

- Checking default umask in /etc/profile

[ SUGGESTION ]

[ NOT ENABLED ]

[ ENABLED ]

[ NONE ]

[ NONE ]

[ NONE ]

[+] File systems

------------------------------------ Checking mount points

- Checking /home mount point

[ SUGGESTION ]

- Checking /tmp mount point

[ SUGGESTION ]

- Checking /var mount point

[ SUGGESTION ]

- Query swap partitions (fstab)

[ OK ]

- Testing swap partitions

[ OK ]

- Testing /proc mount (hidepid)

[ SUGGESTION ]

- Checking for old files in /tmp

[ OK ]

- Checking /tmp sticky bit

[ OK ]

- Checking /var/tmp sticky bit

[ OK ]

- ACL support root file system

[ ENABLED ]

- Mount options of /

[ NON DEFAULT ]

- Checking Locate database

[ FOUND ]

- Disable kernel support of some filesystems

- Discovered kernel modules: cramfs freevxfs hfs hfsplus jffs2 udf

[+] USB Devices

------------------------------------ Checking usb-storage driver (modprobe config)

- Checking USB devices authorization

- Checking USBGuard

[ NOT DISABLED ]

[ ENABLED ]

[ NOT FOUND ]

[+] Storage

------------------------------------ Checking firewire ohci driver (modprobe config)

[ DISABLED ]

[+] NFS

------------------------------------ Check running NFS daemon

[ NOT FOUND ]

[+] Name services

------------------------------------ Checking search domains

- Checking /etc/resolv.conf options

- Searching DNS domain name

- Checking /etc/hosts

- Checking /etc/hosts (duplicates)

- Checking /etc/hosts (hostname)

- Checking /etc/hosts (localhost)

- Checking /etc/hosts (localhost to IP)

[+] Ports and packages

------------------------------------ Searching package managers

- Searching dpkg package manager

- Querying package manager

- Query unpurged packages

- debsums utility

- Cron job for debsums

- Checking security repository in sources.list file

- Checking APT package database

- Checking vulnerable packages

- Checking upgradeable packages

- Checking package audit tool

Found: apt-get

?le:///home/moose/report.html

[ FOUND ]

[ FOUND ]

[ UNKNOWN ]

[

[

[

[

OK

OK

OK

OK

]

]

]

]

[ FOUND ]

[

[

[

[

[

[

[

[

FOUND ]

FOUND ]

FOUND ]

OK ]

OK ]

WARNING ]

SKIPPED ]

INSTALLED ]

3/10

10/17/2019

report.html

- Toolkit for automatic upgrades (unattended-upgrade)

[+] Networking

------------------------------------ Checking IPv6 configuration

Configuration method

IPv6 only

- Checking configured nameservers

- Testing nameservers

Nameserver: 127.0.0.53

- Checking default gateway

- Getting listening ports (TCP/UDP)

- Checking promiscuous interfaces

- Checking waiting connections

- Checking status DHCP client

- Checking for ARP monitoring software

[+] Printers and Spools

------------------------------------ Checking cups daemon

- Checking CUPS configuration file

- File permissions

- Checking CUPS addresses/sockets

- Checking lp daemon

[ FOUND ]

[ ENABLED ]

[ AUTO ]

[ NO ]

[

[

[

[

[

[

[

OK ]

DONE ]

DONE ]

OK ]

OK ]

RUNNING ]

NOT FOUND ]

[

[

[

[

[

RUNNING ]

OK ]

WARNING ]

FOUND ]

NOT RUNNING ]

[

[

[

[

[

FOUND ]

FOUND ]

OK ]

FOUND ]

ACTIVE ]

[+] Software: e-mail and messaging

-----------------------------------[+] Software: firewalls

------------------------------------ Checking iptables kernel module

- Checking iptables policies of chains

- Checking for empty ruleset

- Checking for unused rules

- Checking host based firewall

[+] Software: webserver

------------------------------------ Checking Apache (binary /usr/sbin/apache2)

[ FOUND ]

Info: Configuration file found (/etc/apache2/apache2.conf)

Info: No virtual hosts found

* Loadable modules

[ FOUND (114) ]

- Found 114 loadable modules

mod_evasive: anti-DoS/brute force

[ NOT FOUND ]

mod_reqtimeout/mod_qos

[ FOUND ]

ModSecurity: web application firewall

[ NOT FOUND ]

- Checking nginx

[ NOT FOUND ]

[+] SSH Support

------------------------------------ Checking running SSH daemon

[ NOT FOUND ]

[+] SNMP Support

------------------------------------ Checking running SNMP daemon

[ NOT FOUND ]

[+] Databases

------------------------------------ MySQL process status

- Redis (server) status

- Redis (requirepass configured)

- Redis (rename of CONFIG command)

- Redis (bind on localhost)

[

[

[

[

[

[+] LDAP Services

------------------------------------ Checking OpenLDAP instance

[ NOT FOUND ]

FOUND ]

FOUND ]

NOT FOUND ]

NOT FOUND ]

FOUND ]

[+] PHP

-----------------------------------?le:///home/moose/report.html

4/10

10/17/2019

- Checking PHP

- Checking PHP disabled functions

- Checking expose_php option

- Checking enable_dl option

- Checking allow_url_fopen option

- Checking allow_url_include option

report.html

[

[

[

[

[

[

FOUND ]

FOUND ]

ON ]

OFF ]

ON ]

OFF ]

[+] Squid Support

------------------------------------ Checking running Squid daemon

[ NOT FOUND ]

[+] Logging and files

------------------------------------ Checking for a running log daemon

- Checking Syslog-NG status

- Checking systemd journal status

- Checking Metalog status

- Checking RSyslog status

- Checking RFC 3195 daemon status

- Checking minilogd instances

- Checking logrotate presence

- Checking log directories (static list)

- Checking open log files

- Checking deleted files in use

[

[

[

[

[

[

[

[

[

[

[

OK ]

NOT FOUND ]

FOUND ]

NOT FOUND ]

FOUND ]

NOT FOUND ]

NOT FOUND ]

OK ]

DONE ]

DONE ]

FILES FOUND ]

[+] Insecure services

------------------------------------ Installed inetd package

- Installed xinetd package

- xinetd status

- Installed rsh client package

- Installed rsh server package

- Installed telnet client package

- Installed telnet server package

[

[

[

[

[

[

[

NOT FOUND ]

OK ]

NOT ACTIVE ]

OK ]

OK ]

OK ]

NOT FOUND ]

[+] Banners and identification

------------------------------------ /etc/issue

- /etc/issue contents

- /etc/

- /etc/ contents

[

[

[

[

FOUND ]

WEAK ]

FOUND ]

WEAK ]

[+] Scheduled tasks

------------------------------------ Checking crontab and cronjob files

[ DONE ]

[+] Accounting

------------------------------------ Checking accounting information

- Checking sysstat accounting data

- Checking auditd

[ NOT FOUND ]

[ DISABLED ]

[ NOT FOUND ]

[+] Time and Synchronization

------------------------------------ NTP daemon found: chronyd

- NTP daemon found: systemd (timesyncd)

- Checking for a running NTP daemon or client

[ FOUND ]

[ FOUND ]

[ OK ]

[+] Cryptography

------------------------------------ Checking for expired SSL certificates [3/9]

[ FOUND ]

[+] Virtualization

-----------------------------------[+] Containers

------------------------------------ Docker

- Docker daemon

- Docker info output (warnings)

?le:///home/moose/report.html

[ RUNNING ]

[ 1 ]

5/10

................
................

In order to avoid copyright disputes, this page is only a partial summary.

Google Online Preview   Download