mirror of
https://github.com/ovh/debian-cis.git
synced 2025-09-04 21:48:23 +02:00
feat: add debian12 scripts
- nftables_loopback_is_configured.sh -> 4.2.6 - nftables_established_connections.sh -> 4.2.7 - iptables_flushed_with_nftables.sh -> 4.2.3 - ufw_loopback_is_configured.sh -> 4.1.4 - ufw_outbound_connection.sh -> 4.1.5 - ufw_default_deny.sh -> 4.1.7 - ufw_rules_them_all.sh -> 4.1.6
This commit is contained in:
28
tests/hardening/ufw_loopback_is_configured.sh
Normal file
28
tests/hardening/ufw_loopback_is_configured.sh
Normal file
@@ -0,0 +1,28 @@
|
||||
# shellcheck shell=bash
|
||||
# run-shellcheck
|
||||
test_audit() {
|
||||
describe prepare test
|
||||
apt install -y ufw
|
||||
|
||||
describe Running on blank host
|
||||
register_test retvalshouldbe 1
|
||||
# shellcheck disable=2154
|
||||
run blank "${CIS_CHECKS_DIR}/${script}.sh" --audit-all
|
||||
|
||||
# we can not apply the fix, unless running on a privileged container
|
||||
# we manually update the rules file
|
||||
describe fix the situation
|
||||
# shellcheck disable=2129
|
||||
echo '-A ufw-user-input -i lo -j ACCEPT' >>/etc/ufw/user.rules
|
||||
echo '-A ufw-user-output -o lo -j ACCEPT' >>/etc/ufw/user.rules
|
||||
echo '-A ufw-user-input -s 127.0.0.0/8 -j DROP' >>/etc/ufw/user.rules
|
||||
echo '-A ufw-user-input -s ::1 -j DROP' >>/etc/ufw/user6.rules
|
||||
|
||||
describe Checking resolved state
|
||||
register_test retvalshouldbe 0
|
||||
run resolved "${CIS_CHECKS_DIR}/${script}.sh" --audit-all
|
||||
|
||||
describe clean test
|
||||
apt purge -y ufw
|
||||
apt autoremove -y
|
||||
}
|
Reference in New Issue
Block a user