|
@@ -22,12 +22,13 @@ Validate system configuration.
|
|
|
|
|
|
Configuration: none
|
|
|
|
|
|
-### concierge-secaudit
|
|
|
+### concierge-permaudit
|
|
|
|
|
|
Audit filesystem permissions for possible security issues:
|
|
|
-* World-readable private keys (ssh, Let's Encrypt) and passwords (Git, SVN, Sympa, Dolibarr, ...)O
|
|
|
+* World-readable private keys (ssh, Let's Encrypt) and passwords (Git, SVN, Sympa, Dolibarr, ...)
|
|
|
* World-writable configuration files and scripts (/etc/init.d/*, /etc/profile, ...)
|
|
|
* World-writable executable search path ($PATH), python search path, and perl include path
|
|
|
+* Sensitive information stored in the wrong place (passwords in /etc/passwd rather than /etc/shadow)
|
|
|
|
|
|
This tool only does file permissions checks, and does it imperfectly.
|
|
|
You should not rely on this single tool for security auditing.
|