5342a22448
Bastille is a system hardening / lockdown program which enhances the security of a Unix host. It configures daemons, system settings and firewalls to be more secure. It can shut off unneeded services like rcp and rlogin, and helps create "chroot jails" that help limit the vulnerability of common Internet services like Web services and DNS. This tool currently hardens Red Hat (Fedora Core, Enterprise and Legacy/Classic), SuSE, Debian, Gentoo, Mandrake Linux, HP-UX, Mac OS X and Turbo Linux. If run in the preferred interactive mode, it can teach you a good deal about security while personalizing your system security state. Bastille can also assess and report on the state of a system, which may serve as an aid to security administrators, auditors and system administrators who wish to investigate the state of their system's hardening without making changes to such. This assessment functionality has only been tested on Red Hat Linux (Fedora, Legacy, Enterprise) and SUSE systems.
256 lines
7.8 KiB
Text
256 lines
7.8 KiB
Text
bin,XFree86,'/usr/X11R6/bin/XFree86'
|
|
bin,Xwrapper,'/usr/X11R6/bin/Xwrapper'
|
|
|
|
bin,accton,'/usr/sbin/accton'
|
|
bin,accton,'/sbin/accton',RH6.2,MN9.2,MN10.0,MN10.1,MN2006.0
|
|
bin,dpkg,'/usr/bin/dpkg',DB
|
|
bin,apt-get,'/usr/sbin/apt-get',DB
|
|
bin,at,'/usr/bin/at'
|
|
bin,bash,'/bin/bash'
|
|
bin,cardctl,'/sbin/cardctl'
|
|
bin,chattr,'/usr/bin/chattr'
|
|
bin,chgrp,'/bin/chgrp'
|
|
bin,chkconfig,'/sbin/chkconfig'
|
|
bin,chmod,'/bin/chmod'
|
|
bin,chown,'/bin/chown'
|
|
bin,cksum,'/usr/bin/cksum'
|
|
bin,cp,'/bin/cp'
|
|
bin,crontab,'/usr/bin/crontab'
|
|
bin,cupsd,'/usr/sbin/cupsd'
|
|
bin,diff,'/usr/bin/diff'
|
|
bin,dos,'/usr/bin/dos'
|
|
bin,dump,'/sbin/dump'
|
|
bin,echo,'/bin/echo'
|
|
bin,grep,'/bin/grep'
|
|
bin,grep,'/usr/bin/grep',SE
|
|
bin,groupadd,'/usr/sbin/groupadd'
|
|
bin,inndstart,'/usr/bin/inndstart'
|
|
bin,killall,'/usr/bin/killall'
|
|
bin,lilo,'/sbin/lilo'
|
|
bin,ln,'/bin/ln'
|
|
bin,logger,'/usr/bin/logger'
|
|
bin,lpd,'/usr/sbin/lpd'
|
|
bin,lpd,'/usr/lib/cups/daemon/cups-lpd',MN9.2,MN10.0,MN10.1,MN2006.0
|
|
bin,lppasswd,'/usr/bin/lppasswd'
|
|
bin,lpq,'/usr/bin/lpq'
|
|
bin,lpr,'/usr/bin/lpr'
|
|
bin,lprm,'/usr/bin/lprm'
|
|
bin,lpstat,'/usr/bin/lpstat'
|
|
bin,md5sum,'/usr/bin/md5sum'
|
|
bin,mknod,'/bin/mknod'
|
|
bin,more,'/usr/bin/more'
|
|
bin,mount,'/bin/mount'
|
|
bin,mv,'/bin/mv'
|
|
bin,named-xfer,'/usr/sbin/named-xfer'
|
|
bin,ping,'/bin/ping'
|
|
bin,ping6,'/usr/sbin/ping6',RH7.0,RH7.1,RH7.2,RH7.3,RH8.0,RH9,RHEL2
|
|
bin,ping6,'/bin/ping6',DB,RHEL3,RHFC1,RHFC2,RHFC3,RHFC4,RHFC5,SE9.1,SE9.2,SE9.3,SE10.0,SESLES9
|
|
bin,ping6,'/usr/bin/ping6',MN9.2,MN10.0,MN10.1,MN2006.0
|
|
bin,ps,'/bin/ps'
|
|
bin,rcp,'/usr/bin/rcp'
|
|
bin,rdist,'/usr/bin/rdist'
|
|
bin,restore,'/sbin/restore'
|
|
bin,rexec,'/usr/bin/rexec'
|
|
bin,rexecd,'/usr/sbin/in.rexecd'
|
|
bin,rlogin,'/usr/bin/rlogin'
|
|
bin,rlogind,'/usr/sbin/in.rlogind'
|
|
bin,rm,'/bin/rm'
|
|
bin,rmdir,'/bin/rmdir'
|
|
bin,rpm,'/bin/rpm'
|
|
bin,rsh,'/usr/bin/rsh'
|
|
bin,rcp,'/usr/bin/rcp'
|
|
bin,rshd,'/usr/sbin/in.rshd'
|
|
bin,sendmail,'/usr/sbin/sendmail'
|
|
bin,smbmnt,'/usr/bin/smbmnt'
|
|
bin,startinnfeed,'/usr/bin/startinnfeed'
|
|
bin,sulogin,'/sbin/sulogin'
|
|
bin,touch,'/usr/bin/touch'
|
|
bin,traceroute,'/usr/sbin/traceroute'
|
|
|
|
bin,traceroute6,'/bin/traceroute6'
|
|
bin,traceroute6,'/usr/sbin/traceroute6',RH7.0,RH7.1,RH7.2,RH7.3,RH8.0,RH9,RHEL2,MN9.2,MN10.0,MN10.1,MN2006.0
|
|
bin,traceroute6,'/usr/bin/traceroute6',DB
|
|
|
|
bin,umount,'/bin/umount'
|
|
bin,useradd,'/usr/sbin/useradd'
|
|
bin,usernetctl,'/usr/sbin/usernetctl'
|
|
|
|
|
|
dir,floppy,'/mnt/floppy'
|
|
dir,floppy,'/floppy',DB
|
|
|
|
dir,home,'/home'
|
|
|
|
dir,initd,'/etc/rc.d/init.d'
|
|
dir,initd,'/etc/init.d',DB,SE,SLES
|
|
|
|
dir,log,'/var/log'
|
|
dir,pamd,'/etc/pam.d'
|
|
|
|
dir,rcd,'/etc/rc.d'
|
|
dir,rcd,'/etc',DB
|
|
|
|
dir,sbin,'/sbin'
|
|
dir,xinetd.d,'/etc/xinetd.d'
|
|
|
|
|
|
file,accton,'/usr/sbin/accton'
|
|
file,accton,'/sbin/accton',RH6.2
|
|
|
|
file,banners_makefile,'/usr/share/doc/tcp_wrappers-7.5/Banners.Makefile'
|
|
file,banners_makefile,'/usr/share/doc/tcp_wrappers-7.6/Banners.Makefile',RH7.2,RHEL2,RHEL3
|
|
file,banners_makefile,'/usr/share/doc/packages/tcp_wrappers-7.6/Banners.Makefile',TB7.0
|
|
|
|
file,chkconfig_apmd,'/etc/rc.d/rc3.d/S26apmd'
|
|
file,chkconfig_apmd,'/etc/rc3.d/S26apmd',DB
|
|
file,chkconfig_apmd,'/etc/rc.config',SE
|
|
file,initd_apmd,'/etc/init.d/apmd'
|
|
|
|
file,initd_acpid,'/etc/init.d/acpid'
|
|
|
|
file,chkconfig_audit,'/etc/rc3.d/S20audit'
|
|
file,initd_audit,'/etc/init.d/audit'
|
|
|
|
file,chkconfig_dhcpd,'/etc/rc.d/rc3.d/S65dhcpd'
|
|
file,chkconfig_dhcpd,'/etc/rc3.d/S65dhcpd',DB
|
|
file,chkconfig_dhcpd,'/etc/rc.config',SE
|
|
file,initd_dhcpd,'/etc/init.d/dhcpd'
|
|
|
|
file,chkconfig_gated,'/etc/rc.d/rc3.d/S32gated'
|
|
file,chkconfig_gated,'/etc/rc3.d/S32gated',DB
|
|
file,initd_gated,'/etc/init.d/gated'
|
|
|
|
file,chkconfig_gpm,'/etc/rc.d/rc3.d/S85gpm'
|
|
file,chkconfig_gpm,'/etc/rc3.d/S20gpm',DB
|
|
file,chkconfig_gpm,'/etc/rc.config',SE
|
|
file,initd_gpm,'/etc/init.d/gpm'
|
|
|
|
file,chkconfig_httpd,'/etc/rc.d/rc3.d/S85httpd'
|
|
file,chkconfig_httpd,'/etc/rc3.d/S91httpd',DB
|
|
file,initd_httpd,'/etc/init.d/httpd'
|
|
file,initd_httpd2,'/etc/init.d/httpd2'
|
|
|
|
file,chkconfig_innd,'/etc/rc.d/rc3.d/S95innd'
|
|
file,chkconfig_innd,'/etc/rc3.d/S95innd',DB
|
|
file,initd_innd,'/etc/init.d/innd'
|
|
|
|
file,chkconfig_kudzu,'/etc/init.d/kudzu'
|
|
file,initd_kudzu,'/etc/init.d/kudzu'
|
|
|
|
file,chkconfig_named,'/etc/rc.d/rc3.d/S55named'
|
|
file,chkconfig_named,'/etc/rc3.d/S15named',DB
|
|
file,initd_named,'/etc/init.d/named'
|
|
|
|
file,chkconfig_nfs,'/etc/rc.d/rc3.d/S60nfs'
|
|
file,chkconfig_nfs,'/etc/rc3.d/S60nfs',DB
|
|
file,chkconfig_nfs,'/etc/rc.config',SE
|
|
file,initd_nfs,'/etc/init.d/nfs'
|
|
|
|
file,chkconfig_pcmcia,'/etc/rc.d/rc3.d/S45pcmcia'
|
|
file,chkconfig_pcmcia,'/etc/rc3.d/S45pcmcia',DB
|
|
file,chkconfig_pcmcia,'/etc/rc.config',SE
|
|
file,initd_pcmcia,'/etc/init.d/pcmcia'
|
|
|
|
file,initd_mDNSResponder,'/etc/init.d/mDNSResponder'
|
|
file,initd_avahi-daemon,'/etc/init.d/avahi-daemon'
|
|
file,initd_avahi-dnsconfd,'/etc/init.d/avahi-dnsconfd'
|
|
|
|
file,initd_bluetooth,'/etc/init.d/bluetooth'
|
|
|
|
file,initd_hpoj,'/etc/init.d/hpoj'
|
|
|
|
file,initd_isdn,'/etc/init.d/isdn'
|
|
|
|
file,chkconfig_routed,'/etc/rc.d/rc3.d/S55gated'
|
|
file,chkconfig_routed,'/etc/rc3.d/S55gated',DB
|
|
file,initd_routed,'/etc/init.d/routed'
|
|
|
|
file,chkconfig_snmpd,'/etc/rc.d/rc3.d/S50snmpd'
|
|
file,chkconfig_snmpd,'/etc/rc3.d/S50snmpd',DB
|
|
file,initd_snmpd,'/etc/init.d/snmpd'
|
|
|
|
file,chkconfig_vsftpd,'/etc/rc.d/rc3.d/S60vsftpd'
|
|
file,initd_vsftpd,'/etc/init.d/vsftpd'
|
|
|
|
file,chkconfig_ypbind,'/etc/rc.d/rc3.d/S17ypbind'
|
|
file,chkconfig_ypbind,'/etc/rc3.d/S17ypbind',DB
|
|
file,chkconfig_ypbind,'/etc/rc.config',SE
|
|
file,initd_ypbind,'/etc/init.d/ypbind'
|
|
|
|
file,cron.allow,'/etc/cron.allow'
|
|
file,cron.allow,'/var/spool/cron/allow',SE
|
|
file,csh.login,'/etc/csh.login'
|
|
file,cupsd,'/usr/sbin/cupsd'
|
|
file,ftpaccess,'/etc/ftpaccess'
|
|
file,gcc,'/usr/bin/gcc'
|
|
file,g++,'/usr/bin/g++'
|
|
file,gdm.conf,/etc/X11/gdm/gdm.conf
|
|
file,group,'/etc/group'
|
|
file,passwd,'/etc/passwd'
|
|
file,shadow,'/etc/shadow'
|
|
|
|
file,grub.conf,'/etc/grub.conf'
|
|
file,grub.conf,'/boot/grub/grub.conf',RH9,RHEL,RHFC
|
|
file,grub.conf,'/boot/grub/menu.lst',SE,MN
|
|
file,hosts.allow,'/etc/hosts.allow'
|
|
file,hosts.deny,'/etc/hosts.deny'
|
|
|
|
file,httpd,'/usr/sbin/httpd'
|
|
file,httpd,'/usr/sbin/apache',DB
|
|
|
|
file,httpd2,'/usr/sbin/httpd2'
|
|
|
|
file,httpd.conf,'/etc/httpd/conf/httpd.conf'
|
|
file,httpd.conf,'/etc/apache/httpd.conf',DB
|
|
file,httpd.conf,'/etc/httpd/httpd.conf',SE7.2 SE7.3 SE8.0
|
|
file,httpd.conf,'/etc/apache2/httpd.conf',SE9.0,SE9.1,SE9.2,SE9.3,SLES
|
|
file,httpd.conf,'/etc/httpd/conf/httpd2.conf',MN10.1
|
|
# SuSE breaks httpd.conf into many files after 8.
|
|
file,listen.conf,'/etc/apache2/listen.conf',SE9.0,SE9.1,SE9.2,SE9.3,SLES
|
|
file,suse-default-server.conf,'/etc/apache2/default-server.conf',SE9.0,SE9.1,SE9.2,SE9.3,SLES
|
|
|
|
file,httpd_access.conf,'/etc/httpd/conf/httpd.conf'
|
|
file,httpd_access.conf,'/etc/apache/access.conf',DB2
|
|
file,httpd_access.conf,'/etc/apache/httpd.conf',DB3
|
|
file,httpd_access.conf,'/etc/httpd/conf/access.conf',RH6.0,RH6.1
|
|
file,httpd_access.conf,'/etc/httpd/httpd.conf',SE7.2 SE7.3 SE8.0
|
|
file,httpd_access.conf,'/etc/apache2/httpd.conf',SE9.0,SE9.1,SE9.2,SE9.3,SLES
|
|
file,httpd_access.conf,'/etc/httpd/conf/commonhttpd.conf',MN10.1
|
|
|
|
file,inetd.conf,'/etc/inetd.conf'
|
|
file,inittab,'/etc/inittab'
|
|
file,issue,'/etc/issue'
|
|
|
|
file,kdmrc,'/usr/share/config/kdmrc'
|
|
file,kdmrc,'/etc/kde/kdm/kdmrc',MN10.1
|
|
|
|
file,lilo.conf,'/etc/lilo.conf'
|
|
file,limits.conf,'/etc/security/limits.conf'
|
|
file,lpd,'/usr/sbin/lpd'
|
|
file,lpr,'/usr/bin/lpr'
|
|
file,motd,'/etc/motd'
|
|
file,mtab,'/etc/mtab'
|
|
file,named,'/usr/sbin/named'
|
|
file,pam_access.conf,'/etc/security/access.conf'
|
|
file,pamd_passwd,'/etc/pam.d/passwd'
|
|
file,profile,'/etc/profile'
|
|
file,rc.config,'/etc/rc.config'
|
|
file,rc.local,'/etc/rc.local'
|
|
file,rootprofile,'/root/.bash_profile'
|
|
file,rsh,'/usr/bin/rsh'
|
|
file,rcp,'/usr/bin/rcp'
|
|
file,securetty,'/etc/securetty'
|
|
file,sendmail.cf,'/etc/sendmail.cf'
|
|
file,sysctl.conf,'/etc/sysctl.conf'
|
|
file,syslog.conf,'/etc/syslog.conf'
|
|
file,sysconfig_audit,'/etc/sysconfig/audit'
|
|
file,sysconfig_named,'/etc/sysconfig/named'
|
|
file,sysconfig_sendmail,'/etc/sysconfig/sendmail'
|
|
file,tcpd,'/usr/sbin/tcpd'
|
|
file,xinetd.conf,'/etc/xinetd.conf'
|
|
|
|
file,ypserv,'/etc/rc.d/init.d/ypserv'
|
|
file,ypserv,'/etc/init.d/ypserv',DB
|
|
file,ypserv,'/etc/rc.config',SE
|
|
|
|
file,zprofile,'/etc/zprofile'
|