From dc65ae72e26c0714067b5e00e77c3557de38d3f1 Mon Sep 17 00:00:00 2001 From: Leif Johansson Date: Thu, 1 Nov 2018 10:19:13 +0100 Subject: [PATCH] daily security report --- global/overlay/etc/cron.daily/secreport | 4 ++++ global/overlay/usr/local/sbin/secreport.sh | 3 ++- 2 files changed, 6 insertions(+), 1 deletion(-) create mode 100755 global/overlay/etc/cron.daily/secreport diff --git a/global/overlay/etc/cron.daily/secreport b/global/overlay/etc/cron.daily/secreport new file mode 100755 index 00000000..f6956b0b --- /dev/null +++ b/global/overlay/etc/cron.daily/secreport @@ -0,0 +1,4 @@ +SHELL=/bin/sh +PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin + +/usr/local/sbin/secreport.sh > /var/log/secreport.log diff --git a/global/overlay/usr/local/sbin/secreport.sh b/global/overlay/usr/local/sbin/secreport.sh index 9fd2a105..31b1f7d1 100755 --- a/global/overlay/usr/local/sbin/secreport.sh +++ b/global/overlay/usr/local/sbin/secreport.sh @@ -1,12 +1,13 @@ #!/bin/bash echo "### $HOSTNAME" +grep 127.0.1.1 /etc/hosts echo "### SUID binaries" find / -perm -4000 -ls echo "### World writable files" -find / -type f -a -perm -o=w +find / -type f -a -perm -o=w -ls echo "### lines in authorized_keys" for h in `awk -F: '{print $6}' /etc/passwd`; do