检查脚本

Linux安全检查脚本

#!/bin/bash

echo "#########check UID=0#########"

cat /etc/passwd|awk -F ':' '{if($3==0)print($1)}'


echo "#########check shadow null#########"

cat /etc/shadow|awk -F ':' '{if($2="")print($1)}'


echo "#########check Root ssh#########"|tee -a /tmp/wqout

cat /etc/ssh/sshd_config|grep PermitRootLogin|awk '{if($2=="yes")print $1,$2}'


echo "#########check Protocol version#########"

cat /etc/ssh/sshd_config|grep Protocol


echo "#########check X11 #########"

cat /etc/ssh/sshd_config|grep X11Forwarding|awk '{if($2=="yes")print($1,$2)}'


echo "#########check TMOUT #########"

cat /etc/profile|grep -i tmout


echo "#########check PASS_LEN #########"

cat /etc/login.defs|grep PASS_MIN_LEN|awk '{if($2<8) print ($1,$2)}'


echo "#########check PASSWORD #########"

cat /etc/pam.d/system-auth|grep password|grep requisite|grep pam_cracklib.so


echo "#########check PASS History #########"

cat /etc/pam.d/system-auth|grep password|grep sufficient|grep pam_unix.so


echo "#########check inittab #########"

cat /etc/inittab


echo "#########check umask #########"

cat /etc/profile|grep umask |grep -v By|awk '{print $2}'


echo "#########check secure log #########"

cat /etc/rsyslog.conf|grep -i authpriv|awk '{if($2=="/var/log/secure")print($1,$2)}'


chown root /etc/passwd

chgrp root /etc/passwd

chmod 644 /etc/passwd

chmod 400 /etc/shadow


chmod 664 /var/log/messages

chmod 664 /var/log/secure

chmod 664 /var/log/cron

chmod 664 /var/log/wtmp

chmod 664 /var/log/utmp

chmod 664 /var/log/lastlog


      本文转自flayber  51CTO博客,原文链接:http://blog.51cto.com/406647516/1967537,如需转载请自行联系原作者





评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值