LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian
User Name
Password
Debian This forum is for the discussion of Debian Linux.

Notices


Reply
  Search this Thread
Old 03-20-2012, 03:46 PM   #1
mikeey
LQ Newbie
 
Registered: Mar 2012
Posts: 3

Rep: Reputation: Disabled
Security audit on Debian - what to do with all the warnings


Hi guys

I just ran a security audit using Tiger on my Debian server. It gave me a ton of warnings, and I've fixed alot of them, however, there is a few that I can't figure out how to fix. Could you give me the exact commands to fix them aswell as a detailed explanation how/why things work like that, so that I actually learn something and not just fix and forget.

http://pastebin.com/UdM3d7gv

Thank you,
Michael

Last edited by mikeey; 03-20-2012 at 03:58 PM.
 
Old 03-20-2012, 05:32 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by mikeey View Post
Security scripts *** 3.2.3, 2008.09.10.09.30 ***
Sure this is the most recent version?


Quote:
Originally Posted by mikeey View Post
[pass013w] Username `X' is not using an acceptable password hash
See bug http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=432918 ?


Quote:
Originally Posted by mikeey View Post
[pass015w] Login ID sshd does not have a valid shell (/usr/sbin/nologin).
'sshd' isn't an account that any human user should use. No valid shell is good.


Quote:
Originally Posted by mikeey View Post
[acc006w] Login ID X's home directory (/X/X) has group `4096' write access.
Looks like an error separating fields ("4096" is a common value where 'stat' returns IO Blocks).


Quote:
Originally Posted by mikeey View Post
[acc022w] Login ID X home directory (/nonexistent) is not accessible.
Some processes need not or should not have a home.


Quote:
Originally Posted by mikeey View Post
[path002w] /path/to/item in root's PATH from default is not owned by root (owned by tty).
Lesser-privileged or unprivileged users shouldn't trick root into writing to files owned by them.


Quote:
Originally Posted by mikeey View Post
CRON file `' is owned by crontab.
Looks like an error. Fixing it requires debugging.


Quote:
Originally Posted by mikeey View Post
Found cron file for unknown user .
Hmm. Interesting. If listing crontab files doesn't show clues then this requires debug output to find out what happened though.


Quote:
Originally Posted by mikeey View Post
[cron004w] Root crontab does not exist
If root doesn't need its own crotan that's not a problem.


Quote:
Originally Posted by mikeey View Post
[cron005w] Use of cron is not restricted
See /etc/cron.{deny,allow}


Quote:
Originally Posted by mikeey View Post
[inet003w] The port for service pop-2 is also assigned to service pop2.
Conflicting assignments could be fixed checking /etc/services against the file the official assigning authority (IANA?) provides.


Quote:
Originally Posted by mikeey View Post
[init004e] `/usr/lib/tiger/systems/default/gen_mounts' is not executable (command GET_MOUNTS).
Seems like an error to me.


Quote:
Originally Posted by mikeey View Post
[rootkit009a] A rootkit seems to be installed in the system INFECTED (PORTS: 31337)
Weak alert by chkrootkit. See its FAQ and the patch in my web log.


Quote:
Originally Posted by mikeey View Post
[dev003w] The directory /dev/block resides in a device directory.
Probably too strict check, even for Debian. Doesn't seem like a problem to me.


Quote:
Originally Posted by mikeey View Post
--FAIL-- [logf005f] Log file /var/log/wtmp permission should be 644
--FAIL-- [logf005f] Log file /var/log/btmp permission should be 600
--FAIL-- [logf005f] Log file /var/run/utmp permission should be 644
Depends on your distribution. Often 0664 access perms allowing other processes to write to it.


Quote:
Originally Posted by mikeey View Post
[misc022f] The umask setting in /etc/profile is insecure
You didn't list it. What does it default to?


Quote:
Originally Posted by mikeey View Post
[lin003w] The process `exim4' is listening on socket TCP (0t0 on TCP interface) is run by Debian-exim.
Seems like a message of the informational level to me.


Quote:
Originally Posted by mikeey View Post
[ssh004w] The PasswordAuthentication directive in /etc/ssh/sshd_config is set to the unapproved defult value: yes.
See recommendations in http://www.linuxquestions.org/questi...tempts-340366/


Quote:
Originally Posted by mikeey View Post
--ERROR-- [init006e] `/etc/printcap' does not exist (file definition src).
--ERROR-- [init006e] `/etc/printcap' does not exist (file definition infile).
?


Quote:
Originally Posted by mikeey View Post
--ERROR-- [init001e] Don't have required command NETSTAT.
Instal the package containing netstat?


Quote:
Originally Posted by mikeey View Post
--ERROR-- [init004e] `/usr/lib/tiger/systems/default/getdisks' is not executable (command GETDISKS).
Seems like an error to me.

* BTW first thing you should know is GNU/Tiger has a switch (I always forget if it's "-e" or "-E") that intersperses warnings with explanations. I suggest you use it (or look up the codes in the explanation file) first.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Linux security audit tools er_gaurav22 Linux - Security 4 03-05-2008 01:47 AM
LXer: Audit your Cisco router's security with Nipper LXer Syndicated Linux News 0 12-25-2007 10:50 PM
abuse@email.com security warnings emetib Linux - Security 5 09-24-2004 06:39 PM
security audit? nabil_boussetta Linux - Security 1 07-07-2004 03:38 AM
How do you setup a cron job for a security audit? Lorianna Programming 3 04-18-2002 05:29 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian

All times are GMT -5. The time now is 06:52 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration