Merge pull request #18 in IAAS/cis-hardening from dev/thibault.dewailly/fix6.15 to master

* commit 'c1a45d1df172e0f3c715759b3dd71873fd58559d':
  Fixed 6.15 netstat analysis
This commit is contained in:
Thibault Dewailly 2016-04-25 08:41:43 +02:00
commit 7b73604461

View File

@ -14,7 +14,8 @@ set -u # One variable unset, it's over
# This function will be called if the script status is on enabled / audit mode # This function will be called if the script status is on enabled / audit mode
audit () { audit () {
info "Checking netport ports opened" info "Checking netport ports opened"
eval 'RESULT=$(netstat -an | grep LIST | grep ":25[[:space:]]")' RESULT=$(netstat -an | grep LIST | grep ":25[[:space:]]") || :
RESULT=${RESULT:-}
debug "Result is $RESULT" debug "Result is $RESULT"
if [ -z "$RESULT" ]; then if [ -z "$RESULT" ]; then
ok "Nothing listens on 25 port, probably unix socket configured" ok "Nothing listens on 25 port, probably unix socket configured"
@ -31,7 +32,8 @@ audit () {
# This function will be called if the script status is on enabled mode # This function will be called if the script status is on enabled mode
apply () { apply () {
info "Checking netport ports opened" info "Checking netport ports opened"
eval 'RESULT=$(netstat -an | grep LIST | grep ":25[[:space:]]")' RESULT=$(netstat -an | grep LIST | grep ":25[[:space:]]") || :
RESULT=${RESULT:-}
debug "Result is $RESULT" debug "Result is $RESULT"
if [ -z "$RESULT" ]; then if [ -z "$RESULT" ]; then
ok "Nothing listens on 25 port, probably unix socket configured" ok "Nothing listens on 25 port, probably unix socket configured"