File: //opt/BCLinux/bse/secure_check/c20_syslogAuth
#!/bin/sh
#=======================================================
InsertSection "check if record the auth events"
SYSLOG_CONF="/etc/rsyslog.conf /etc/syslog.conf"
for i in ${SYSLOG_CONF}
do
if [ -s ${i} ];then
cp -np ${i} ${i}_bak
grep "auth.none \{1,\}\/var\/log\/.\{1,\}" ${i}|grep -v "#" |wc -l | while read count
do
if [ $count -lt 1 ];then
echo "c20" >> $RESULT_FILE
echo "" >> $RESULT_FILE
logtext "WRN_C20: $(loadtext TXT_WRN_C20)"
logtext "Suggestion: $(loadtext TXT_SUG_C20)"
Display --indent 2 --text "- Check if there have auth.none set... " --result WARNING --color RED
AddHP 0 1
else
logtext "The security audit modle auth.none is set, checking OK"
Display --indent 2 --text "- Check if there have auth.none set... " --result OK --color GREEN
AddHP 1 1
fi
done
fi
done