-
Notifications
You must be signed in to change notification settings - Fork 46
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Cloudformation os hardening #46
Comments
2018-06-10 15:04:16 Hardening: assigned maximum number of hardening points for this item (3). Currently having 179 points (out of 248) |
2018-06-10 15:04:15 Result: sysctl key fs.suid_dumpable has a different value than expected in scan profile. Expected=0, Real=2 |
Current suggestions 2018-06-10 15:03:56 Suggestion: Version of Lynis outdated, consider upgrading to the latest version [test:LYNIS] [details:-] [solution:-] |
Follow lynis suggestions, Currently having 157 points (out of 243)
Hardening index : [64] [############ ]
Hardening strength: System has been hardened, but could use additional hardening
sysctl
2018-06-09 18:03:07 Action: Performing tests from category: Kernel Hardening
16:03:07
2018-06-09 18:03:07 ===---------------------------------------------------------------===
16:03:07
2018-06-09 18:03:07 Performing test ID KRNL-6000 (Check sysctl key pairs in scan profile)
16:03:07
2018-06-09 18:03:07 Result: sysctl key fs.protected_hardlinks contains equal expected and current value (1)
16:03:07
2018-06-09 18:03:07 Hardening: assigned maximum number of hardening points for this item (1). Currently having 129 points (out of 202)
16:03:07
2018-06-09 18:03:07 Result: sysctl key fs.protected_symlinks contains equal expected and current value (1)
16:03:07
2018-06-09 18:03:07 Hardening: assigned maximum number of hardening points for this item (1). Currently having 130 points (out of 203)
16:03:07
2018-06-09 18:03:07 Result: sysctl key fs.suid_dumpable has a different value than expected in scan profile. Expected=0, Real=2
16:03:07
2018-06-09 18:03:07 Hardening: assigned partial number of hardening points (0 of 1). Currently having 130 points (out of 204)
16:03:07
2018-06-09 18:03:07 Result: key hw.kbd.keymap_restrict_change does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key kern.sugid_coredump does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key kernel.core_setuid_ok does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: sysctl key kernel.core_uses_pid has a different value than expected in scan profile. Expected=1, Real=0
16:03:07
2018-06-09 18:03:07 Hardening: assigned partial number of hardening points (0 of 1). Currently having 130 points (out of 205)
16:03:07
2018-06-09 18:03:07 Result: sysctl key kernel.ctrl-alt-del contains equal expected and current value (0)
16:03:07
2018-06-09 18:03:07 Hardening: assigned maximum number of hardening points for this item (1). Currently having 131 points (out of 206)
16:03:07
2018-06-09 18:03:07 Result: sysctl key kernel.dmesg_restrict has a different value than expected in scan profile. Expected=1, Real=0
16:03:07
2018-06-09 18:03:07 Hardening: assigned partial number of hardening points (0 of 1). Currently having 131 points (out of 207)
16:03:07
2018-06-09 18:03:07 Result: key kernel.exec-shield-randomize does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key kernel.exec-shield does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: sysctl key kernel.kptr_restrict has a different value than expected in scan profile. Expected=2, Real=1
16:03:07
2018-06-09 18:03:07 Hardening: assigned partial number of hardening points (0 of 1). Currently having 131 points (out of 208)
16:03:07
2018-06-09 18:03:07 Result: key kernel.maps_protect does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: sysctl key kernel.randomize_va_space contains equal expected and current value (2)
16:03:07
2018-06-09 18:03:07 Hardening: assigned maximum number of hardening points for this item (1). Currently having 132 points (out of 209)
16:03:07
2018-06-09 18:03:07 Result: key kernel.suid_dumpable does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: sysctl key kernel.sysrq has a different value than expected in scan profile. Expected=0, Real=176
16:03:07
2018-06-09 18:03:07 Hardening: assigned partial number of hardening points (0 of 1). Currently having 132 points (out of 210)
16:03:07
2018-06-09 18:03:07 Result: key kernel.use-nx does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: sysctl key kernel.yama.ptrace_scope contains equal expected and current value (1 2 3)
16:03:07
2018-06-09 18:03:07 Hardening: assigned maximum number of hardening points for this item (1). Currently having 133 points (out of 211)
16:03:07
2018-06-09 18:03:07 Result: key net.inet.icmp.bmcastecho does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet.icmp.drop_redirect does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet.icmp.rediraccept does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet.icmp.timestamp does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet.ip.accept_sourceroute does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet.ip.check_interface does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet.ip.forwarding does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet.ip.linklocal.in.allowbadttl does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet.ip.process_options does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet.ip.random_id does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet.ip.redirect does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet.ip.sourceroute does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet.ip6.redirect does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet.tcp.always_keepalive does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet.tcp.blackhole does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet.tcp.drop_synfin does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet.tcp.icmp_may_rst does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet.tcp.nolocaltimewait does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet.tcp.path_mtu_discovery does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet.udp.blackhole does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet6.icmp6.rediraccept does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet6.ip6.forwarding does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet6.ip6.fw.enable does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key net.inet6.ip6.redirect does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: sysctl key net.ipv4.conf.all.accept_redirects contains equal expected and current value (0)
16:03:07
2018-06-09 18:03:07 Hardening: assigned maximum number of hardening points for this item (1). Currently having 134 points (out of 212)
16:03:07
2018-06-09 18:03:07 Result: sysctl key net.ipv4.conf.all.accept_source_route contains equal expected and current value (0)
16:03:07
2018-06-09 18:03:07 Hardening: assigned maximum number of hardening points for this item (1). Currently having 135 points (out of 213)
16:03:07
2018-06-09 18:03:07 Result: sysctl key net.ipv4.conf.all.bootp_relay contains equal expected and current value (0)
16:03:07
2018-06-09 18:03:07 Hardening: assigned maximum number of hardening points for this item (1). Currently having 136 points (out of 214)
16:03:07
2018-06-09 18:03:07 Result: sysctl key net.ipv4.conf.all.forwarding contains equal expected and current value (0)
16:03:07
2018-06-09 18:03:07 Hardening: assigned maximum number of hardening points for this item (1). Currently having 137 points (out of 215)
16:03:07
2018-06-09 18:03:07 Result: sysctl key net.ipv4.conf.all.log_martians has a different value than expected in scan profile. Expected=1, Real=0
16:03:07
2018-06-09 18:03:07 Hardening: assigned partial number of hardening points (0 of 1). Currently having 137 points (out of 216)
16:03:07
2018-06-09 18:03:07 Result: sysctl key net.ipv4.conf.all.mc_forwarding contains equal expected and current value (0)
16:03:07
2018-06-09 18:03:07 Hardening: assigned maximum number of hardening points for this item (1). Currently having 138 points (out of 217)
16:03:07
2018-06-09 18:03:07 Result: sysctl key net.ipv4.conf.all.proxy_arp contains equal expected and current value (0)
16:03:07
2018-06-09 18:03:07 Hardening: assigned maximum number of hardening points for this item (1). Currently having 139 points (out of 218)
16:03:07
2018-06-09 18:03:07 Result: sysctl key net.ipv4.conf.all.rp_filter contains equal expected and current value (1)
16:03:07
2018-06-09 18:03:07 Hardening: assigned maximum number of hardening points for this item (1). Currently having 140 points (out of 219)
16:03:07
2018-06-09 18:03:07 Result: sysctl key net.ipv4.conf.all.send_redirects has a different value than expected in scan profile. Expected=0, Real=1
16:03:07
2018-06-09 18:03:07 Hardening: assigned partial number of hardening points (0 of 1). Currently having 140 points (out of 220)
16:03:07
2018-06-09 18:03:07 Result: sysctl key net.ipv4.conf.default.accept_redirects contains equal expected and current value (0)
16:03:07
2018-06-09 18:03:07 Hardening: assigned maximum number of hardening points for this item (1). Currently having 141 points (out of 221)
16:03:07
2018-06-09 18:03:07 Result: sysctl key net.ipv4.conf.default.accept_source_route has a different value than expected in scan profile. Expected=0, Real=1
16:03:07
2018-06-09 18:03:07 Hardening: assigned partial number of hardening points (0 of 1). Currently having 141 points (out of 222)
16:03:07
2018-06-09 18:03:07 Result: sysctl key net.ipv4.conf.default.log_martians has a different value than expected in scan profile. Expected=1, Real=0
16:03:07
2018-06-09 18:03:07 Hardening: assigned partial number of hardening points (0 of 1). Currently having 141 points (out of 223)
16:03:07
2018-06-09 18:03:07 Result: sysctl key net.ipv4.icmp_echo_ignore_broadcasts contains equal expected and current value (1)
16:03:07
2018-06-09 18:03:07 Hardening: assigned maximum number of hardening points for this item (1). Currently having 142 points (out of 224)
16:03:07
2018-06-09 18:03:07 Result: sysctl key net.ipv4.icmp_ignore_bogus_error_responses contains equal expected and current value (1)
16:03:07
2018-06-09 18:03:07 Hardening: assigned maximum number of hardening points for this item (1). Currently having 143 points (out of 225)
16:03:07
2018-06-09 18:03:07 Result: sysctl key net.ipv4.tcp_syncookies contains equal expected and current value (1)
16:03:07
2018-06-09 18:03:07 Hardening: assigned maximum number of hardening points for this item (1). Currently having 144 points (out of 226)
16:03:07
2018-06-09 18:03:07 Result: sysctl key net.ipv4.tcp_timestamps contains equal expected and current value (0 1)
16:03:07
2018-06-09 18:03:07 Hardening: assigned maximum number of hardening points for this item (1). Currently having 145 points (out of 227)
16:03:07
2018-06-09 18:03:07 Result: sysctl key net.ipv6.conf.all.accept_redirects contains equal expected and current value (0)
16:03:07
2018-06-09 18:03:07 Hardening: assigned maximum number of hardening points for this item (1). Currently having 146 points (out of 228)
16:03:07
2018-06-09 18:03:07 Result: sysctl key net.ipv6.conf.all.accept_source_route contains equal expected and current value (0)
16:03:07
2018-06-09 18:03:07 Hardening: assigned maximum number of hardening points for this item (1). Currently having 147 points (out of 229)
16:03:07
2018-06-09 18:03:07 Result: key net.ipv6.conf.all.send_redirects does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: sysctl key net.ipv6.conf.default.accept_redirects contains equal expected and current value (0)
16:03:07
2018-06-09 18:03:07 Hardening: assigned maximum number of hardening points for this item (1). Currently having 148 points (out of 230)
16:03:07
2018-06-09 18:03:07 Result: sysctl key net.ipv6.conf.default.accept_source_route contains equal expected and current value (0)
16:03:07
2018-06-09 18:03:07 Hardening: assigned maximum number of hardening points for this item (1). Currently having 149 points (out of 231)
16:03:07
2018-06-09 18:03:07 Result: key security.bsd.hardlink_check_gid does not exist on this machine
16:03:07
2018-06-09 18:03:07 Result: key security.bsd.hardlink_check_uid does not exist on this machine
16:03:08
2018-06-09 18:03:08 Result: key security.bsd.see_other_gids does not exist on this machine
16:03:08
2018-06-09 18:03:08 Result: key security.bsd.see_other_uids does not exist on this machine
16:03:08
2018-06-09 18:03:08 Result: key security.bsd.stack_guard_page does not exist on this machine
16:03:08
2018-06-09 18:03:08 Result: key security.bsd.unprivileged_proc_debug does not exist on this machine
16:03:08
2018-06-09 18:03:08 Result: key security.bsd.unprivileged_read_msgbuf does not exist on this machine
16:03:08
2018-06-09 18:03:08 Result: found 9 keys that can use tuning, according scan profile
16:03:08
2018-06-09 18:03:08 Suggestion: One or more sysctl values differ from the scan profile and could be tweaked [test:KRNL-6000] [details:] [solution:Change sysctl value or disable test (skip-test=KRNL-6000:)]
The text was updated successfully, but these errors were encountered: