HEX
Server: nginx/1.16.1
System: Linux ecs-04358622 4.19.90-2107.6.0.0100.oe1.bclinux.x86_64 #1 SMP Wed Dec 1 19:59:44 CST 2021 x86_64
User: nginx (994)
PHP: 8.0.0
Disabled: NONE
Upload Files
File: //opt/BCLinux/bse/secure_check/c20_syslogAuth
#!/bin/sh

#=======================================================
InsertSection "check if record the auth events"

SYSLOG_CONF="/etc/rsyslog.conf /etc/syslog.conf"


for i in ${SYSLOG_CONF}
do
    if [ -s ${i} ];then
        cp -np ${i} ${i}_bak
        grep "auth.none \{1,\}\/var\/log\/.\{1,\}" ${i}|grep -v "#" |wc -l | while read count
        do
            if [ $count -lt 1 ];then
                echo "c20" >> $RESULT_FILE
                echo "" >> $RESULT_FILE
                logtext "WRN_C20: $(loadtext TXT_WRN_C20)"
                logtext "Suggestion: $(loadtext TXT_SUG_C20)"
                Display --indent 2 --text "- Check if there have auth.none set... " --result WARNING --color RED
                AddHP 0 1
            else
                logtext "The security audit modle auth.none is set, checking OK"
                Display --indent 2 --text "- Check if there have auth.none set... " --result OK --color GREEN
                AddHP 1 1
            fi
        done

    fi
done