晋太元中,武陵人捕鱼为业。缘溪行,忘路之远近。忽逢桃花林,夹岸数百步,中无杂树,芳草鲜美,落英缤纷。渔人甚异之,复前行,欲穷其林。   林尽水源,便得一山,山有小口,仿佛若有光。便舍船,从口入。初极狭,才通人。复行数十步,豁然开朗。土地平旷,屋舍俨然,有良田、美池、桑竹之属。阡陌交通,鸡犬相闻。其中往来种作,男女衣着,悉如外人。黄发垂髫,并怡然自乐。   见渔人,乃大惊,问所从来。具答之。便要还家,设酒杀鸡作食。村中闻有此人,咸来问讯。自云先世避秦时乱,率妻子邑人来此绝境,不复出焉,遂与外人间隔。问今是何世,乃不知有汉,无论魏晋。此人一一为具言所闻,皆叹惋。余人各复延至其家,皆出酒食。停数日,辞去。此中人语云:“不足为外人道也。”(间隔 一作:隔绝)   既出,得其船,便扶向路,处处志之。及郡下,诣太守,说如此。太守即遣人随其往,寻向所志,遂迷,不复得路。   南阳刘子骥,高尚士也,闻之,欣然规往。未果,寻病终。后遂无问津者。 sh-3ll

HOME


sh-3ll 1.0
DIR:/proc/thread-self/root/opt/cpguard/3rdparty/lynis/include/
Upload File :
Current File : //proc/thread-self/root/opt/cpguard/3rdparty/lynis/include/tests_homedirs
#!/bin/sh

#################################################################################
#
#   Lynis
# ------------------
#
# Copyright (c) Michael Boelen, CISOfy, and many contributors.
#
# Website  : https://cisofy.com
# Blog     : https://linux-audit.com/
# GitHub   : https://github.com/CISOfy/lynis
#
# Lynis comes with ABSOLUTELY NO WARRANTY. This is free software, and you are
# welcome to redistribute it under the terms of the GNU General Public License.
# See LICENSE file for usage of this software.
#
#################################################################################
#
# Home directories
#
#################################################################################
#
    InsertSection "${SECTION_HOME_DIRECTORIES}"
#
#################################################################################
#
    # Ignore some top level directories (not the sub directories below)
    IGNORE_HOME_DIRS="/bin /boot /cdrom /dev /etc /home /lib /lib64 /media /mnt
                      /opt /proc /sbin /selinux /srv /sys /tmp /usr /var"
#
#################################################################################
#
    # Test        : HOME-9302
    # Description : Create list with home directories
    Register --test-no HOME-9302 --weight L --network NO --category security --description "Create list with home directories"
    if [ ${SKIPTEST} -eq 0 ]; then
        # Read sixth field of /etc/passwd
        LogText "Test: query ${ROOTDIR}etc/passwd to obtain home directories"
        FIND=$(${AWKBINARY} -F: '{ if ($1 !~ "#") print $6 }' ${ROOTDIR}etc/passwd | ${SORTBINARY} -u)
        for I in ${FIND}; do
            if [ -d ${I} ]; then
                LogText "Result: found home directory: ${I} (directory exists)"
                Report "home_directory[]=${I}"
            else
                LogText "Result: found home directory: ${I} (directory does not exist)"
            fi
        done
    fi
#
#################################################################################
#
    # Test        : HOME-9304
    # Description : Check if users' home directories permissions are 750 or more restrictive
    Register --test-no HOME-9304 --weight L --network NO --category security --description "Check if users' home directories permissions are 750 or more restrictive"
    if [ ${SKIPTEST} -eq 0 ]; then
        # Check if users' home directories permissions are 750 or more restrictive
        FOUND=0
        USERDATA=$(${GREPBINARY} -E -v '^(daemon|git|halt|root|shutdown|sync)' ${ROOTDIR}etc/passwd | ${AWKBINARY} -F: '($7 !~ "/(false|nologin)$") { print }')
        while read -r LINE; do
            USER=$(echo ${LINE} | ${CUTBINARY} -d: -f1)
            DIR=$(echo ${LINE} | ${CUTBINARY} -d: -f6)
            LogText "Test: checking directory '${DIR}' for user '${USER}'"
            if [ -d "${DIR}" ]; then
                WRITE_GROUP_PERM=$(${LSBINARY} -ld ${DIR} | ${CUTBINARY} -f1 -d" " | ${CUTBINARY} -c6)
                OTHER_PERMS=$(${LSBINARY} -ld ${DIR} | ${CUTBINARY} -f1 -d" " | ${CUTBINARY} -c8-10)
                if [ ! ${WRITE_GROUP_PERM} = "-" -o ! ${OTHER_PERMS} = "---" ]; then
                    LogText "Result: permissions of home directory ${DIR} of user ${USER} are not strict enough. Should be 750 or more restrictive. Change with: chmod 750 ${DIR}"
                    FOUND=1
                else
                    LogText "Result: permissions of home directory ${DIR} of user ${USER} are fine"
                fi
            fi
        done << EOF
${USERDATA}
EOF

        if [ ${FOUND} -eq 1 ]; then
            Display --indent 2 --text "- Permissions of home directories" --result "${STATUS_WARNING}" --color RED
            ReportSuggestion "${TEST_NO}" "Double check the permissions of home directories as some might be not strict enough."
        else
            Display --indent 2 --text "- Permissions of home directories" --result "${STATUS_OK}" --color GREEN
            LogText "Result: OK, all permissions of the home directories are 750 or more restrictive"
        fi
    fi
#
#################################################################################
#
    # Test        : HOME-9306
    # Description : Check if users own their home directories
    Register --test-no HOME-9306 --weight L --network NO --category security --description "Check if users own their home directories"
    if [ ${SKIPTEST} -eq 0 ]; then
        # Check if users own their home directories
        FOUND=0
        USERDATA=$(${GREPBINARY} -E -v '^(daemon|git|halt|root|shutdown|sync)' ${ROOTDIR}etc/passwd | ${AWKBINARY} -F: '($7 !~ "/(false|nologin)$") { print }')
        while read -r LINE; do
            USER=$(echo ${LINE} | ${CUTBINARY} -d: -f1)
            DIR=$(echo ${LINE} | ${CUTBINARY} -d: -f6)
            LogText "Test: checking directory '${DIR}' for user '${USER}'"
            if [ -d "${DIR}" ]; then
                OWNER=$(ls -ld ${DIR} | awk -F" " '{ print $3 }')
                if [ ! "${OWNER}" = "${USER}" ]; then
                    LogText "Result: the home directory ${DIR} of user ${USER} is owned by ${OWNER}. Correct: chown ${USER} ${DIR}" 
                    FOUND=1
                else
                    LogText "Result: ownership of home directory ${DIR} for user ${USER} looks to be correct"
                fi
            fi
        done << EOF
${USERDATA}
EOF

        if [ ${FOUND} -eq 1 ]; then
            Display --indent 2 --text "- Ownership of home directories" --result "${STATUS_WARNING}" --color RED
            ReportSuggestion "${TEST_NO}" "Double check the ownership of home directories as some might be incorrect."
        else
            Display --indent 2 --text "- Ownership of home directories" --result "${STATUS_OK}" --color GREEN
            LogText "Result: OK, all users own their home directories"
        fi
    fi
#
#################################################################################
#
    # Test        : HOME-9310
    # Description : Check for suspicious shell history files
    Register --test-no HOME-9310 --weight L --network NO --category security --description "Checking for suspicious shell history files"
    if [ ${SKIPTEST} -eq 0 ]; then
        if [ -n "${HOMEDIRS}" ]; then
            if [ "${OS}" = "Solaris" ]; then
                # Solaris doesn't support -maxdepth
                FIND=$(${FINDBINARY} ${HOMEDIRS} -name ".*history" ! -type f -print)
            else
                FIND=$(${FINDBINARY} ${HOMEDIRS} -maxdepth 1 -name ".*history" ! -type f -print)
            fi
            if [ -z "${FIND}" ]; then
                Display --indent 2 --text "- Checking shell history files" --result "${STATUS_OK}" --color GREEN
                LogText "Result: Ok, history files are type 'file'."
            else
                Display --indent 2 --text "- Checking shell history files" --result "${STATUS_WARNING}" --color RED
                LogText "Result: the following files seem to be of the wrong file type:"
                LogText "Output: ${FIND}"
                LogText "Info: above files could be redirected files to avoid logging and should be investigated"
                ReportWarning "${TEST_NO}" "Incorrect file type found for shell history file"
            fi
            LogText "Remark: History files are normally of the type 'file'. Symbolic links and other types are suspicious."
        else
            Display --indent 2 --text "- Checking shell history files" --result "${STATUS_SKIPPED}" --color WHITE
            LogText "Result: Homedirs is empty, therefore test will be skipped"
        fi
    fi
#
#################################################################################
#
    # Test        : HOME-9314
    # Description : Check if non local paths are found in PATH, which can be a risk, but also bad for performance
    #               (like searching on a filer, instead of local disk)
    #Register --test-no HOME-9314 --weight L --network NO --category security --description "Create list with home directories"
#
#################################################################################
#
    # Test        : HOME-9350
    # Description : Scan home directories for specific files, used in different tests later
    # Notes       : For performance reasons we combine the scanning of different files, so inode caching is used
    #               as much as possible for every find command
    # Profile opt : ignore-home-dir (multiple lines allowed), ignores home directory
    if [ -n "${REPORTFILE}" ]; then PREQS_MET="YES"; else PREQS_MET="NO"; fi
    Register --test-no HOME-9350 --preqs-met ${PREQS_MET} --weight L --network NO --category security --description "Collecting information from home directories"
    if [ ${SKIPTEST} -eq 0 ]; then
        IGNORE_HOME_DIRS=$(${GREPBINARY} "^ignore-home-dir=" ${REPORTFILE} | ${AWKBINARY} -F= '{ print $2 }')
        if [ -z "${IGNORE_HOME_DIRS}" ]; then
            LogText "Result: IGNORE_HOME_DIRS empty, no paths excluded"
        else
            LogText "Output: ${IGNORE_HOME_DIRS}"
        fi
    fi
#
#################################################################################
#

WaitForKeyPress

#
#================================================================================
# Lynis - Security Auditing and System Hardening for Linux and UNIX - https://cisofy.com