jcoffey-dev 1170130dc9 Fix shell injection in the Zimbra backup and restore scripts
Both scripts built a command string by interpolating user input into
bash -c:

    sudo -u zimbra bash -c "... -m '$EMAIL' ..."

The single quotes inside the double-quoted string are not protection --
the outer shell expands $EMAIL first. An address of

    x' ; id ; echo '

closes the quote and runs arbitrary commands. Both scripts require root
and invoke this through sudo -u zimbra, so injected commands execute as
the account that owns the entire mail store. Verified against the exact
quoting pattern before and after the change.

Fixed by single-quoting the script body so nothing is interpolated, and
passing values as positional arguments. The bash -c wrapper is kept
deliberately rather than calling zmmailbox directly, since it may depend
on shell setup and this could not be tested against a live Zimbra.

Two related holes in the same input paths:

- $EMAIL is also part of the backup filename, so a "/" wrote outside
  $BACKUP_DIR. Now validated as a plain address.
- The restore prompt took a filename and concatenated it into a path, so
  "../../etc/shadow" escaped $BACKUP_DIR. Now rejects anything
  containing a separator.

Also switched the backup listing from `ls | grep "$EMAIL"` to a find
with grep -F: unquoted the address was treated as a regex, so "." in it
matched any character.
2026-08-22 22:09:28 -07:00
2025-05-17 10:06:49 -07:00
2025-05-17 10:06:21 -07:00
2025-05-17 10:06:49 -07:00
2025-05-17 10:06:49 -07:00
2025-05-17 10:06:49 -07:00
2025-05-17 10:06:49 -07:00
2025-05-17 10:06:49 -07:00
2025-06-12 16:03:33 -07:00
2025-05-17 10:06:49 -07:00
2025-05-17 10:06:49 -07:00
2025-05-17 10:06:49 -07:00
2025-05-17 10:06:49 -07:00
2025-05-17 10:06:49 -07:00

Linux System Administration Scripts

Automate routine tasks: This project provides a collection of Bash scripts to automate common Linux system administration duties. Automating daily sysadmin tasks improves efficiency and consistency by reducing manual repetition and the risk of human error. Each script is designed to be distribution-agnostic, using only standard base utilities (e.g. rsync, tar, awk, grep, netstat/ss, systemctl) available on most Linux systems. All scripts are released under the GNU GPL v3.0 license and include usage information in their headers.

Included Scripts

  • backup.sh Backup Utility: Archive directories into compressed tarballs for backups.
  • restore.sh Restore Utility: Restore files from backup archives.
  • disk_cleanup.sh Disk Usage & Cleanup: Report disk usage and identify large files; optionally clean package caches and temporary files to free space.
  • log_inspect.sh Log Inspection: Search within log files or tail the latest system logs for troubleshooting.
  • log_rotate.sh Log Rotation: Compress and rotate old log files to prevent excessive disk usage
  • network_info.sh Network & Firewall Info: Show network interface details, routing table, open listening ports, and basic firewall (iptables) rules.
  • process_monitor.sh Process Management: List top resource-consuming processes and allow termination of processes by name or PID.
  • security_audit.sh Security Audit: Scan for security issues like world-writable files, SUID/SGID executables, and open network ports.
  • service_manager.sh Service Management: Start, stop, restart, or check status of system services, and enable/disable services at boot.
  • sys_monitor.sh System Monitoring: Display system uptime, resource utilization (CPU, memory, disk), and top processes.
  • update_system.sh System Updates: Apply available package updates and patches (works with apt, yum/dnf, zypper, pacman).
  • user_manage.sh User and Group Management: Create or remove user accounts and groups, modify user group memberships, and lock/unlock accounts.
  • zimbra_backup.sh - Create a backup for a zimbra mailbox.
  • zimbra_restore.sh - Restore a backup for a zimbra mailbox.
  • rsync_magic.sh - A smart Bash script that wraps rsync for safe, flexible, and efficient file synchronization and backups.
S
Description
Imported from github.com during the 2026-09-20 standup (local dir: SysAdminAutomation)
Readme GPL-3.0
106 KiB
Languages
Shell 100%