aboutsummaryrefslogtreecommitdiffstats
path: root/conf/level.default
diff options
context:
space:
mode:
authorEugeni Dodonov <eugeni@mandriva.org>2009-01-06 21:31:46 +0000
committerEugeni Dodonov <eugeni@mandriva.org>2009-01-06 21:31:46 +0000
commitff31c9236b1fd7465ea9687fc735e8af882e780e (patch)
treeeec89033b4ad0b2459fbb91fa6dd39077eeaf407 /conf/level.default
parentab984707253940bf5ced3a379699e8d0dc757fa6 (diff)
downloadmsec-ff31c9236b1fd7465ea9687fc735e8af882e780e.tar
Diffstat
-rw-r--r--conf/perm.35
-rw-r--r--
Conflicts: Makefile cron-sh/security_check.sh share/msec.py
Diffstat (limited to 'conf/level.default')
-rw-r--r--conf/level.default54
1 files changed, 54 insertions, 0 deletions
diff --git a/conf/level.default b/conf/level.default
new file mode 100644
index 0000000..f9c0f7f
--- /dev/null
+++ b/conf/level.default
@@ -0,0 +1,54 @@
+ENABLE_APPARMOR=no
+ALLOW_X_CONNECTIONS=local
+CHECK_WRITABLE=yes
+ENABLE_IP_SPOOFING_PROTECTION=yes
+MAIL_EMPTY_CONTENT=no
+ACCEPT_BROADCASTED_ICMP_ECHO=yes
+CHECK_PERMS=yes
+CHECK_USER_FILES=yes
+ENABLE_SUDO=wheel
+ALLOW_XSERVER_TO_LISTEN=no
+CHECK_CHKROOTKIT=yes
+SHELL_HISTORY_SIZE=-1
+ALLOW_REBOOT=yes
+CHECK_SUID_ROOT=yes
+SYSLOG_WARN=yes
+ENABLE_AT_CRONTAB=yes
+ACCEPT_BOGUS_ERROR_RESPONSES=no
+CHECK_PASSWD=yes
+PASSWORD_HISTORY=0
+CHECK_SUID_MD5=yes
+CHECK_SHOSTS=yes
+MAIL_USER=root
+ALLOW_AUTOLOGIN=yes
+ENABLE_PAM_WHEEL_FOR_SU=no
+CHECK_SHADOW=yes
+ALLOW_ROOT_LOGIN=yes
+CHECK_UNOWNED=no
+ENABLE_CONSOLE_LOG=yes
+ALLOW_USER_LIST=yes
+ENABLE_DNS_SPOOFING_PROTECTION=yes
+CREATE_SERVER_LINK=default
+ENABLE_PASSWORD=yes
+NOTIFY_WARN=yes
+WIN_PARTS_UMASK=no
+CHECK_OPEN_PORT=yes
+SHELL_TIMEOUT=0
+ALLOW_REMOTE_ROOT_LOGIN=without_password
+ENABLE_LOG_STRANGE_PACKETS=yes
+USER_UMASK=022
+CHECK_RPM=yes
+ENABLE_SULOGIN=no
+ENABLE_PAM_ROOT_FROM_WHEEL=no
+MAIL_WARN=yes
+ALLOW_XAUTH_FROM_ROOT=yes
+CHECK_SECURITY=yes
+ACCEPT_ICMP_ECHO=yes
+PASSWORD_LENGTH=4,0,0
+AUTHORIZE_SERVICES=yes
+ROOT_UMASK=022
+ENABLE_MSEC_CRON=yes
+TTY_WARN=no
+ENABLE_POLICYKIT=yes
+CHECK_SGID=yes
+CHECK_PROMISC=no
ff --git a/conf/perm.snf b/conf/perm.snf
new file mode 100644
index 0000000..848054b
--- /dev/null
+++ b/conf/perm.snf
@@ -0,0 +1,72 @@
+# Welcome in Level 4, aka secure & usable.
+###
+/bin/ root.root 711
+/boot/ root.root 700
+/dev/ root.root 711
+/dev/audio* root.audio 600
+/dev/dsp* root.audio 600
+/etc/ root.adm 711
+/etc/conf.modules root.adm 640
+/etc/cron.daily/ root.adm 750
+/etc/cron.hourly/ root.adm 750
+/etc/cron.monthly/ root.adm 750
+/etc/cron.weekly/ root.adm 750
+/etc/crontab root.adm 640
+/etc/dhcpcd/ root.adm 750
+/etc/dhcpcd/* root.adm 640
+/etc/esd.conf root.audio 640
+/etc/ftpaccess root.adm 640
+/etc/ftpconversions root.adm 640
+/etc/ftpgroups root.adm 640
+/etc/ftphosts root.adm 640
+/etc/ftpusers root.adm 640
+/etc/gettydefs root.adm 640
+/etc/hosts.allow root.adm 640
+/etc/hosts.deny root.adm 640
+/etc/hosts.equiv root.adm 640
+/etc/inetd.conf root.adm 640
+/etc/rc.d/init.d/ root.adm 750
+/etc/rc.d/init.d/syslog root.adm 740
+/etc/inittab root.adm 640
+/etc/ld.so.conf root.adm 640
+/etc/lilo.conf root.adm 600
+/etc/modules.conf root.adm 640
+/etc/motd root.adm 644
+/etc/printcap root.lp 640
+/etc/profile.d/* root.root 755
+/etc/rc.d/ root.adm 640
+/etc/securetty root.root 640
+/etc/sendmail.cf root.adm 640
+/etc/shutdown.allow root.root 600
+/etc/ssh_config root.root 644
+/etc/ssh_host_key root.adm 640
+/etc/ssh_host_key.pub root.adm 644
+/etc/sshd_config root.adm 640
+/etc/syslog.conf root.adm 640
+/etc/updatedb.conf root.adm 640
+/home/ root.adm 751
+/home/* current 700
+/lib/ root.adm 751
+/mnt/ root.adm 750
+/root/ root.root 700
+/sbin/ root.adm 751
+/tmp/ root.root 1777
+/usr/ root.adm 751
+/usr/* root.adm 751
+/usr/X11R6/ root.xgrp 751
+/usr/bin/ root.adm 751
+/usr/sbin/ root.adm 751
+/var/ root.root 755
+/var/log/ root.root 711
+/var/log/* root.root 600
+/var/log/squidGuard squid.squid 751
+/var/log/squid squid.squid 751
+/var/log/security/ root.root 700
+/var/log/security/* root.root 600
+/var/spool/mail/ root.mail 771
+/var/tmp root.root 1777
+/var/lib/monitoring httpd-naat.admin 2770
+/var/lib/naat root.admin 2770
+/var/log/httpd-naat httpd-naat.admin 750
+/var/www-naat httpd-naat.admin 750
+/var/log/snort snort.snort 750