Vulnerability scanner for Linux and FreeBSD
github.com
github.com
Instead of dealing with this thing, I suggest looking at some existing system management tools like Landscape for Ubuntu or Spacewalk for CentOS/RHEL to handle managed updates... or learning how to set up a cron job to email you when security updates are available.
I appreciate tools like this because they are single purpose and can be easily be retrofitted to old systems.
Also, yum security plugin does not work on centos because security errata are not published in repo. So you have to hack it even with spacewalk.
This tool definitely meets a need in the EL ecosystem.
Really "agentless" is all a lie. The "agent" in most cases is usually sshd and you can really do better.
Also for this kind of software it makes sense to simply leverage the underlying configuration management system the admin is using. If they're using chef/puppet/cfengine they push out the client over the top of an agent-based protocol. If they're using ansible or salt they'll deploy it "agentless"-ly.
They've actually done more work to support this root-trust remote management model when they could have simplified the problem domain to just running their code (as an agent) and reporting on the one host its running on.
It seems to have been developed to tick off a buzzword ("agentless") which could have been avoided altogether.
No thank you.
But the part I'm concerned about is that they seem to think that having password-less sudo is a security win.
I thought they were saying they don't want people's passwords. People reuse them, naive people giving up an actual root password, etc.
Not sure they mean always using NOPASSWORD is good for security.
The pam module requires you to forward a remote connection to your ssh agent - when you connect to a compromised server your attacker can authenticate to other machines as you.
An ssh key for root is simpler and safer.
NOPASSWORD is pretty sane for remote access, my objection would be to any sudo escalation at all on the target.
> What Vuls Doesn't Do
>
> Vuls doesn't update the vulnerable packages.
...ok, so please just stick to stuff like unprivileged sha1sum/dpkg/rpm/stat etc.If vuls absolutely needs some superuser privilege, it makes sense to grant some limited privs via setcap bits (though this would mean it would probably lose the "agentless" feature).
http://askubuntu.com/questions/470383/how-to-avoid-prompt-pa...
But there is a problem with sudo with password via ssh.
For example...
userA .... 'watch w' on serverA
userB ... 'ssh serverA echo sudopassword | sudo -S command'
userA can steal of root password on ServerA because plain sudo password is displayed by w command.So, I disable -ask-sudo-password for security reasons. https://github.com/future-architect/vuls/pull/148
I recommend to define minimum commands in /etc/sudoers on target servers.
CentOS, RHEL
vuls ALL=(root) NOPASSWD: /usr/bin/yum, /bin/echo
Ubuntu, Debian
vuls ALL=(root) NOPASSWD: /usr/bin/apt-get, /usr/bin/apt-cache
Vuls can scan without root on FreeBSD and Amazon Linux. // install aptitude
cmd = util.PrependProxyEnv("apt-get install --force-yes -y aptitude")
I really don't like saying bad things about someone's project, but a "scanner" really really really shouldn't be making configuration changes to boxes, especially without prompting.* Don't use root where you don't need to - can you parse package lists / vulnerability databases as a normal user?
* Would the design be better inverted? Systems push their list of installed packages / versions to your application to be checked.
> * Don't use root where you don't need to - can you parse package lists / vulnerability databases as a normal user?
Yes, Vuls can scan without root on FreeBSD and Amazon Linux. If you know how to scan without root on CentOS, Debian, RHEL, Ubuntu, please let me know. I also do'nt want to use root.
> * Would the design be better inverted? Systems push their list of installed packages / versions to your application to be checked.
Not so easy. The package version, release name is not semantic versioning format.This is a output of show package versions command on Ubuntu.
locales 2.13+git20120306-21
login 1:4.1.5.1-1.1ubuntu7
lsb-base 9.20160110
make 4.1-6
mawk 1.3.3-17ubuntu2
mime-support 3.59ubuntu1
multiarch-support 2.21-0ubuntu5
Impossible!!For details, see the flow chart in Scanning Flow section. https://github.com/future-architect/vuls#scanning-flow
While Rust does solve some of the problems that C++ creates, there's no substitute for good programming and thorough testing.
That happens to be more a factor of not wanting to rebuild everything from scratch than anything else.
Go reference implementation is fully bootstrapped in Go.
D guys a few months ago ported their frontend to D.
C#, VB.NET and F# compilers are botstrapped nowadays. With .NET Native, maybe some other parts could eventually be re-written.
The OpenJDK gets less C++ with each release and there is the plan that when AOT lands, they will slowly migrate other parts to Java as well.
Of course trying to write an optimizer from scratch that beats LLVM or GCC backends is an herculean task, hence why most projects happen to use them as backends.
But please don't think of Rust (or anything else) as a silver bullet. If you are doing systems programming you are going to deal with unsafe code somewhat frequently. And, by not being exposed to this kind of programming often enough, it's possible that more errors will slip through the cracks.
Then there's a whole class of errors that cannot be prevented by memory safe languages. They cannot prevent crappy practices.
If you're running FreeBSD, I would recommend not giving SSH access to a third party tool for running something that Charlie Root is e-mailing you about daily anyway.
yes.
Vuls issues below command.
FreeBSD ... pkg audit -F
RHEL ... yum plugin security
Amazon LInux ... yum plugin security
CentOS ... analyze changelogs
Debian ... analyze changelogs
Ubuntu ... analyze changelogsIt is useful to analyze vulnerabilities that are detected by Vuls.
Vuls issues pkg audit -F and parse the results, and then send notification via slack or email with some additionarl informaiton ( NVD data )