mirror of
https://git.FreeBSD.org/src.git
synced 2024-11-30 08:19:09 +00:00
Add an (off by default) check for negative permissions (where the
group on a object has less permissions that everyone). These permissions will not work reliably over NFS if you have more than 14 supplemental groups and are usually not what you mean. MFC after: 1 week
This commit is contained in:
parent
7e54af0831
commit
7cdc1c0007
Notes:
svn2git
2020-12-20 02:59:44 +00:00
svn path=/head/; revision=215213
@ -160,6 +160,9 @@ daily_status_security_diff_flags="-b -u" # flags for diff output
|
||||
# 100.chksetuid
|
||||
daily_status_security_chksetuid_enable="YES"
|
||||
|
||||
# 110.neggrpperm
|
||||
daily_status_security_neggrpperm_enable="NO"
|
||||
|
||||
# 200.chkmounts
|
||||
daily_status_security_chkmounts_enable="YES"
|
||||
#daily_status_security_chkmounts_ignore="^amd:" # Don't check matching
|
||||
|
54
etc/periodic/security/110.neggrpperm
Executable file
54
etc/periodic/security/110.neggrpperm
Executable file
@ -0,0 +1,54 @@
|
||||
#!/bin/sh -
|
||||
#
|
||||
# Copyright (c) 2001 The FreeBSD Project
|
||||
# All rights reserved.
|
||||
#
|
||||
# Redistribution and use in source and binary forms, with or without
|
||||
# modification, are permitted provided that the following conditions
|
||||
# are met:
|
||||
# 1. Redistributions of source code must retain the above copyright
|
||||
# notice, this list of conditions and the following disclaimer.
|
||||
# 2. Redistributions in binary form must reproduce the above copyright
|
||||
# notice, this list of conditions and the following disclaimer in the
|
||||
# documentation and/or other materials provided with the distribution.
|
||||
#
|
||||
# THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
|
||||
# ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
||||
# IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
||||
# ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
|
||||
# FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
|
||||
# DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
|
||||
# OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
||||
# HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
|
||||
# LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
|
||||
# OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
|
||||
# SUCH DAMAGE.
|
||||
#
|
||||
# $FreeBSD$
|
||||
#
|
||||
|
||||
# If there is a global system configuration file, suck it in.
|
||||
#
|
||||
if [ -r /etc/defaults/periodic.conf ]
|
||||
then
|
||||
. /etc/defaults/periodic.conf
|
||||
source_periodic_confs
|
||||
fi
|
||||
|
||||
rc=0
|
||||
|
||||
case "$daily_status_security_neggrpperm_enable" in
|
||||
[Yy][Ee][Ss])
|
||||
echo ""
|
||||
echo 'Checking negative group permissions:'
|
||||
MP=`mount -t ufs,zfs | awk '$0 !~ /no(suid|exec)/ { print $3 }'`
|
||||
n=$(find -sx $MP /dev/null -type f \
|
||||
\( \( ! -perm +010 -and -perm +001 \) -or \
|
||||
\( ! -perm +020 -and -perm +002 \) -or \
|
||||
\( ! -perm +040 -and -perm +004 \) \) \
|
||||
-exec ls -liTd \{\} \+ | tee /dev/stderr | wc -l)
|
||||
[ $n -gt 0 ] && rc=1 || rc=0
|
||||
;;
|
||||
esac
|
||||
|
||||
exit $rc
|
@ -3,6 +3,7 @@
|
||||
.include <bsd.own.mk>
|
||||
|
||||
FILES= 100.chksetuid \
|
||||
110.neggrpperm \
|
||||
200.chkmounts \
|
||||
300.chkuid0 \
|
||||
400.passwdless \
|
||||
|
@ -482,6 +482,14 @@ Set to
|
||||
.Dq Li YES
|
||||
to compare the modes and modification times of setuid executables with
|
||||
the previous day's values.
|
||||
.It Va daily_status_security_neggrpperm_enable
|
||||
.Pq Vt bool
|
||||
Set to
|
||||
.Dq Li YES
|
||||
to check for files where the group of a file has less permissions than
|
||||
the world at large.
|
||||
When users are in more than 14 supplemental groups these negative
|
||||
permissions may not be enforced via NFS shares.
|
||||
.It Va daily_status_security_chkmounts_enable
|
||||
.Pq Vt bool
|
||||
Set to
|
||||
|
Loading…
Reference in New Issue
Block a user