...
Kube-Hunter results Nexus URL: https://nexus.akraino.org/content/sites/logs/fujitsu/job/sdt/r7/sdt-bluval/1/
Vuls
Nexus URL: https://nexus.akraino.org/content/sites/logs/fujitsu/job/sdt/r7/sdt-vuls/1/
...
Nexus URL (manual run, with fixes): https://nexus.akraino.org/content/sites/logs/fujitsu/job/sdt/r7/sdt-lynis/12/
The results compare with the Lynis Incubation: PASS/FAIL Criteria, v1.0 as follows.
...
2022-09-14 16:19:49 Test: Checking for program update...
2022-09-14 16:19:49 Result: Update check failed. No network connection?
2022-09-14 16:19:49 Info: to perform an automatic update check, outbound DNS connections should be allowed (TXT record).
2022-09-14 16:19:49 Suggestion: This release is more than 4 months old. Check the website or GitHub to see if there is an update available. [test:LYNIS] [details:-] [solution:-]
Note: Lynis was downloaded and run directly on the SUT. See the link The test environment is a proxied private network inside the Fujitsu corporate network which does not allow direct DNS lookups using tools such as dig. Therefore the update check cannot be performed automatically.
The latest version of Lynis, 3.0.8 at time of execution, was downloaded and run directly on the SUT. See the link below:
Steps To Implement Security Scan Requirements#InstallandExecute
The following list of tests MUST complete as passing
No. | Test | Result | Notes | ||
---|---|---|---|---|---|
1 | Test: Checking PASS_MAX_DAYS option in /etc/login.defs | 2022-0910-14 1611 11:2048:32 Result: password aging limits are not configured | 2 | 22 Test: Checking PASS_MAX_DAYS option in /etc/login.defs | Required configuration |
2 | Performing test ID AUTH-9328 (Default umask values) | 2022-0910-14 1611 11:20:32 Result: found umask 022, which could be improved | |||
3 | Performing test ID SSH-7440 (Check OpenSSH option: AllowUsers and AllowGroups) | 2022-09-14 16:20:44 Result: SSH has no specific user or group limitation. Most likely all valid users can SSH to this machine. | |||
4 | 48:22 Performing test ID AUTH-9328 (Default umask values) 2022-10-11 11:48:22 Test: Checking umask value in /etc/login.defs | Required configuration | |||
3 | Performing test ID SSH-7440 (Check OpenSSH option: AllowUsers and AllowGroups) | 2022-10-11 11:51:21 Performing test ID SSH-7440 (Check OpenSSH option: AllowUsers and AllowGroups) | Required configuration | ||
4 | Test: checking for file /etc/network/if-up.d/ntpdate | 2022-10-11 11:51:25 Test: checking for file /etc/network/if-up.d/ntpdate 2022-0910-14 1611 11:2051:46 25 Result: file /etc/network/if-up.d/ntpdate does not exist 2022-0910-14 1611 11:2051:46 25 Result: Found a time syncing daemon/client. 2022-0910-14 1611 11:2051:46 25 Hardening: assigned maximum number of hardening points for this item (3).item (3). Currently having 173 points (out of 249) | |||
5 | Performing test ID KRNL-6000 (Check sysctl key pairs in scan profile) : Following sub-tests required | N/A | |||
5a | sysctl key fs.suid_dumpable contains equal expected and current value (0) | 2022-0910-14 1611 11:2051:58 37 Result: sysctl key fs.suid_dumpable contains equal expected and current value (0) | Required configuration | ||
5b | sysctl key kernel.dmesg_restrict contains equal expected and current value (1) | 2022-0910-14 1611 11:2051:58 37 Result: sysctl key kernel.dmesg_restrict has a different value than expected in scan profile. Expected=1, Real=0 | 5c | contains equal expected and current value (1) | Required configuration |
5c | sysctl key net.ipv4.conf.default.accept_source_route contains equal expected and current value (0) | 2022-10-11 11:51:37 Result: sysctl key net.ipv4.conf.default.accept_source_route contains equal expected and current value (0value (0) | Required configuration | ||
6 | Test: Check if one or more compilers can be found on the system | 2022-03-07 15:55:29 Performing test ID HRDN-7220 (Check if one or more compilers are installed) | 6 | 55:29 Test: Check if one or more compilers can be found on the systemfound on the system | Required removal of build-essential package and apt autoremove, and /bin/as |
Kube-Hunter
Nexus URL: https://nexus.akraino.org/content/sites/logs/fujitsu/job/sdt/r7/sdt-bluval/1/
...