-
Notifications
You must be signed in to change notification settings - Fork 17
/
hardeningone.8
executable file
·98 lines (91 loc) · 2.58 KB
/
hardeningone.8
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
.TH HardeningOne 8 "15 December 2009" "1.08" "Unix System Administrator's Manual"
.SH "NAME"
\fB
\fB
\fB
HardeningOne \fP\- Run an system and security audit on the system
\fB
.SH "SYNOPSIS"
.nf
.fam C
\fBhardeningone\fP \-\-check-all(\-c) [other options]
.fam T
.fi
.SH "DESCRIPTION"
\fBhardeningone\fP is an auditing tool for Unix (specialists). It checks the system
and software configuration and logs all the found information into a log file
for debugging purposes, and in a report file suitable to create fancy looking
auditing reports.
\fBhardeningone\fP can be run as a cronjob, or from the command line. It needs to have
full access to the system, so running it as root (or with sudo rights) is
required.
.PP
The following system areas may be checked:
.IP
\- Boot loader files
.IP
\- Configuration files
.IP
\- Common files by software packages
.IP
\- Directories and files related to logging and auditing
.SH "OPTIONS"
.TP
.B \-\-auditor <full name>
Define the name of the auditor/pen-tester. When a full name is used, add double
quotes, like "Michael Boelen".
.TP
.B \-\-checkall (or \-c)
\fBhardeningone\fP performs a full check of the system, printing out the results of
each test to stdout. Additional information will be saved into a log file
(default is /var/log/hardeningone.log).
.IP
In case the outcome of a scan needs to be automated, use the report file.
.TP
.B \-\-check\-update (or \-\-info)
Show program, database and update information
.TP
.B \-\-cronjob
Perform automatic scan with cron safe options (no colors, no questions, no
breaks).
.TP
.B \-\-no\-colors
Do not use colors for messages, warnings and sections.
.TP
.B \-\-no\-log
Redirect all logging information to /dev/null, prevent sensitive information to
be written to disk.
.TP
.B \-\-quick (\-Q)
Do a quick scan (don't wait for user input)
.TP
.B \-\-quiet (\-q)
Try to run as silent as possible, showing only warnings. This option activates
\-\-quick as well.
.TP
.B \-\-reverse\-colors
Optimize screen output for light backgrounds.
.TP
.B \-\-tests TEST-IDs
Only run the specific test(s). When using multiple tests, add quotes around the
line.
.RE
.PP
.RS
Multiple parameters are allowed, though some parameters can only be used together
with others. When running hardeningone without any parameters, help will be shown and
the program will exit.
.RE
.PP
.SH "BUGS"
There are no known bugs. Bugs can be reported directly to author.
.RE
.PP
.SH "LICENSING"
hardeningone is licensed under the GPL v3 license and under development by Michael
Boelen.
.RE
.PP
.SH "CONTACT INFORMATION"
Project related questions and comments should be asked via
http://.