Same with security groups. Gartner has some "best practice" doc somewhere, someone loads that into a security tool, the tool flags things, and these checkboxes must go from red to green. The technical hurdles to comply or actual value do not matter.
Same with security groups. Gartner has some "best practice" doc somewhere, someone loads that into a security tool, the tool flags things, and these checkboxes must go from red to green. The technical hurdles to comply or actual value do not matter.
They try to tailor a lot of these things to the OS/distribution, but fail in the most wonderful ways.
A recent example: they're aware of RHEL. They're also aware of 'firewalld'.
However, they have not managed to realize that this is simply a management interface to other firewalls -- imposing standards on a long-deprecated backend; iptables
Meanwhile, using incredibly inefficient and 'portable' command lines. ie: using find in such a way that an LDAP query happens for every file
Refusing to use the arguments available to the operating system they 'tailor' for. Ultimately timing out once you hold a certain number of files.
I don't have a good example of the command, but it was basically looking for 'worldly' permissions that were too open. It's important to note the users/groups could be discarded/ignored.
They were using 'find ... -exec ls -ld {} \;', which does an LDAP lookup on each result to resolve UIDs and GIDs to names.
They could have made the process far more efficient with either the native '-ls' argument built into find, or adding '-n' to the exec'd 'ls'
Either would skip the name resolution/domain. At a certain number of results/files the expense is too high, causing the job to time out
I like to call what I do "taking the coward's way out" -- using FreeIPA
My team setup the infrastructure in question and I've been too slow to learn it. FreeIPA is nice for quick/easy deployments.
I'm not sure how well it "scales", but it's great for getting comfortable with the "Domain Language" (sorry, pun)
The 'ls' output is honestly superfluous, though - 'find' will report the paths.
I won't even get into how these are batched/time limited. If not this, it'd be something else eventually
I'm not up on EKS-ELB these days, but if the nodes only allow ingress to NodePorts from the ELB, then it seems like those findings should be suppressed in most orgs.
If the SecEng team was partnering with the delivery team they'd know that before sending the report.