{"id":2479,"date":"2014-08-28T20:06:42","date_gmt":"2014-08-28T19:06:42","guid":{"rendered":"https:\/\/beufa.net\/?p=2479"},"modified":"2014-09-29T13:06:33","modified_gmt":"2014-09-29T12:06:33","slug":"auditer-la-configuration-securite-de-votre-unix-avec-lynis","status":"publish","type":"post","link":"https:\/\/beufa.net\/fr\/blog\/auditer-la-configuration-securite-de-votre-unix-avec-lynis\/","title":{"rendered":"Auditer la configuration s\u00e9curit\u00e9 de votre Unix avec Lynis"},"content":{"rendered":"<p>Lynis est un outil d&#8217;audit de votre syst\u00e8me Unix\/Linux (et d&#8217;autres syst\u00e8mes type AIX).<\/p>\n<p>L&#8217;objectif est d&#8217;am\u00e9liorer la s\u00e9curit\u00e9 de votre syst\u00e8me par une v\u00e9rification de certains \u00e9l\u00e9ments de s\u00e9curit\u00e9. Bien s\u00fbr, il ne faut pas s&#8217;attendre \u00e0 une v\u00e9rification compl\u00e8te de votre syst\u00e8me d&#8217;un point de vue applicatif, mais il s&#8217;agit d&#8217;un bon d\u00e9but pour auditer ce qui pourrait poser un probl\u00e8me de s\u00e9curisation de votre machine, en cas d&#8217;attaque sur un de vos applicatifs par exemple.<\/p>\n<p>Pour t\u00e9l\u00e9chargez Lynis, rendez vous ici :\u00a0<a href=\"http:\/\/cisofy.com\/lynis\/\" target=\"_blank\">http:\/\/cisofy.com\/lynis\/<\/a> <del>(<a title=\"Lynis on rootkit.nl\" href=\"http:\/\/rootkit.nl\/software\/lynis\/\" target=\"_blank\">http:\/\/rootkit.nl\/software\/lynis\/<\/a>)<\/del><\/p>\n<p><!--more--><\/p>\n<p>Les options sont les suivantes :<\/p>\n<pre class=\"brush:shell\">[20:53 user@server lynis] &gt; sudo sh lynis\r\n\r\n[ Lynis 1.6.0 ]\r\n\r\n################################################################################\r\n Lynis comes with ABSOLUTELY NO WARRANTY. This is free software, and you are\r\n welcome to redistribute it under the terms of the GNU General Public License.\r\n See the LICENSE file for details about using this software.\r\n\r\n Copyright 2007-2014 - Michael Boelen, http:\/\/cisofy.com\r\n Enterprise support and plugins available via CISOfy - http:\/\/cisofy.com\r\n################################################################################\r\n\r\n[+] Initializing program\r\n------------------------------------\r\n  Scan options:\r\n    --auditor \"&lt;name&gt;\"            : Auditor name\r\n    --check-all (-c)              : Check system\r\n    --no-log                      : Don't create a log file\r\n    --profile &lt;profile&gt;           : Scan the system with the given profile file\r\n    --quick (-Q)                  : Quick mode, don't wait for user input\r\n    --tests \"&lt;tests&gt;\"             : Run only tests defined by &lt;tests&gt;\r\n    --tests-category \"&lt;category&gt;\" : Run only tests defined by &lt;category&gt;\r\n\r\n  Layout options:\r\n    --no-colors                   : Don't use colors in output\r\n    --quiet (-q)                  : No output, except warnings\r\n    --reverse-colors              : Optimize color display for light backgrounds\r\n\r\n  Misc options:\r\n    --check-update                : Check for updates\r\n    --debug                       : Debug logging to screen\r\n    --view-manpage (--man)        : View man page\r\n    --version (-V)                : Display version number and quit\r\n\r\n  Enterprise options:\r\n    --plugin-dir \"&lt;path\"&gt;         : Define path of available plugins\r\n    --upload                      : Upload data to central node\r\n\r\n  Error: No parameters specified!\r\n  See man page and documentation for all available options.\r\n\r\nExiting..\r\n<\/pre>\n<p>&nbsp;<\/p>\n<p>Personnellement, j&#8217;utilise le mode suivant depuis la 1.6.0 :<\/p>\n<pre class=\"brush:shell\">[20:58 user@serveur lynis] &gt; sudo sh lynis --check-all --quick\r\n<\/pre>\n<p>&nbsp;<\/p>\n<p>L&#8217;outil vous fournit alors un rapport d\u00e9taill\u00e9 \u00e9crit dans un log, avec des &#8220;Warnings&#8221;, des &#8220;Suggestions&#8221; et un &#8220;Hardening index&#8221;. L&#8217;avantage, c&#8217;est que les conseils sont d\u00e9taill\u00e9s, et qu&#8217;il est facilement possible des les consid\u00e9rer et comprendre pour ensuite les corriger !<\/p>\n<pre class=\"brush:shell\">================================================================================\r\n\r\n  -[ Lynis 1.6.0 Results ]-\r\n\r\n  Warnings:\r\n  ----------------------------\r\n  - grpck binary found errors in one or more group files [AUTH-9216]\r\n      http:\/\/cisofy.com\/controls\/AUTH-9216\/\r\n\r\n  - PHP option expose_php is possibly turned on, which can reveal useful information for attackers. [PHP-2372]\r\n      http:\/\/cisofy.com\/controls\/PHP-2372\/\r\n\r\n Suggestions:\r\n  ----------------------------\r\n  - Check process listing for processes waiting for IO requests [PROC-3614]\r\n      http:\/\/cisofy.com\/controls\/PROC-3614\/\r\n  - Run grpck manually and check your group files [AUTH-9216]\r\n      http:\/\/cisofy.com\/controls\/AUTH-9216\/\r\n  - Install a PAM module for password strength testing like pam_cracklib or pam_passwdqc [AUTH-9262]\r\n      http:\/\/cisofy.com\/controls\/AUTH-9262\/\r\n  - Configure password aging limits to enforce password changing on a regular base [AUTH-9286]\r\n      http:\/\/cisofy.com\/controls\/AUTH-9286\/\r\n  - Default umask in \/etc\/login.defs could be more strict like 027 [AUTH-9328]\r\n      http:\/\/cisofy.com\/controls\/AUTH-9328\/\r\n  - Default umask in \/etc\/init.d\/rc could be more strict like 027 [AUTH-9328]\r\n      http:\/\/cisofy.com\/controls\/AUTH-9328\/\r\n\r\n[...]\r\n\r\n  Follow-up:\r\n  ----------------------------\r\n  - Check the logfile (less \/var\/log\/lynis.log)\r\n  - Read security controls texts (http:\/\/cisofy.com)\r\n  - Use --upload to upload data (Lynis Enterprise users)\r\n\r\n[...]\r\n\r\n================================================================================\r\n  Lynis Scanner (details):\r\n\r\n  Hardening index : 66 [#############       ]\r\n  Tests performed : 192\r\n  Plugins enabled : 0\r\n\r\n  Lynis Modules:\r\n<\/pre>\n<p>&nbsp;<\/p>\n<p>Bref, vous n&#8217;avez plus d&#8217;excuses, et vous pouvez m\u00eame charger des tests en fonction de vos crit\u00e8res de normes \u00e0 respecter !<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Lynis est un outil d&#8217;audit de votre syst\u00e8me Unix\/Linux (et d&#8217;autres syst\u00e8mes type AIX). L&#8217;objectif est d&#8217;am\u00e9liorer la s\u00e9curit\u00e9 de votre syst\u00e8me par une v\u00e9rification<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/beufa.net\/fr\/blog\/auditer-la-configuration-securite-de-votre-unix-avec-lynis\/\">Continue reading<span class=\"screen-reader-text\">Auditer la configuration s\u00e9curit\u00e9 de votre Unix avec Lynis<\/span><\/a><\/div>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,31,25],"tags":[92,115,79],"class_list":["post-2479","post","type-post","status-publish","format-standard","hentry","category-linux","category-scanner","category-securite-2","tag-audit","tag-linux","tag-securite","entry"],"_links":{"self":[{"href":"https:\/\/beufa.net\/fr\/wp-json\/wp\/v2\/posts\/2479","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/beufa.net\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/beufa.net\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/beufa.net\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/beufa.net\/fr\/wp-json\/wp\/v2\/comments?post=2479"}],"version-history":[{"count":2,"href":"https:\/\/beufa.net\/fr\/wp-json\/wp\/v2\/posts\/2479\/revisions"}],"predecessor-version":[{"id":2508,"href":"https:\/\/beufa.net\/fr\/wp-json\/wp\/v2\/posts\/2479\/revisions\/2508"}],"wp:attachment":[{"href":"https:\/\/beufa.net\/fr\/wp-json\/wp\/v2\/media?parent=2479"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/beufa.net\/fr\/wp-json\/wp\/v2\/categories?post=2479"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/beufa.net\/fr\/wp-json\/wp\/v2\/tags?post=2479"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}