Files
SysAdminAutomation/security_audit.sh
T
jcoffey-dev 5d417f3c4c Change the copyright holder to Coffey Labs
The scripts were attributed to LINUXexpert.org, which is being retired as a
site and is no longer where this work lives. Coffey Labs is the organisation
these projects belong to.

One line per script, fifteen of them, and nothing else. LICENSE is deliberately
untouched: its "Copyright (C) <year> <name of author>" lines are GPL boilerplate
showing you how to write your own notice, and the Free Software Foundation's
own copyright on the licence text is not ours to edit.

Both git contributors are the same person, so there is no third-party copyright
here that could not be restated.
2026-08-30 01:26:45 -07:00

53 lines
2.1 KiB
Bash

#!/bin/bash
# security_audit.sh - Check for common security issues (permissions, open ports)
#
# Copyright (C) 2025 Coffey Labs
#
# This program is free software: you can redistribute it and/or modify it
# under the terms of the GNU General Public License as published by the
# Free Software Foundation, version 3 of the License.
#
# This program is distributed in the hope that it will be useful, but
# WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
# or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
# for more details.
#
# You should have received a copy of the GNU General Public License along
# with this program. If not, see <https://www.gnu.org/licenses/>.
#
# Usage: security_audit.sh (no arguments)
# Description: Lists world-writable files/dirs, SUID/SGID files, and listening ports.
#
# Run as root for a complete picture: as an unprivileged user, find
# cannot descend into directories it may not read, so a clean report
# below is not the same as a clean system.
set -euo pipefail
# Each find below ends in `|| true`. find exits non-zero when it could
# not read some directory -- routine here, since we deliberately walk the
# whole filesystem -- and without this, set -e would abort the audit part
# way through and still look like it had finished.
# World-writable files (perm bits: others have write)
echo "==== World-Writable Files (potentially unsafe) ===="
find / -xdev -type f -perm -0002 -printf '%M %u %g %p\n' 2>/dev/null || true
# World-writable directories without sticky bit
echo -e "\n==== World-Writable Directories (no sticky bit) ===="
find / -xdev -type d -perm -0002 ! -perm -1000 -printf '%M %u %g %p\n' 2>/dev/null || true
# SUID/SGID files (files with setuid or setgid bits)
echo -e "\n==== SUID/SGID Files ===="
find / -xdev \( -perm -4000 -o -perm -2000 \) -printf '%M %u %g %p\n' 2>/dev/null || true
# Open listening ports
echo -e "\n==== Listening Network Ports ===="
if command -v ss &> /dev/null; then
ss -tulwn
elif command -v netstat &> /dev/null; then
netstat -tuln
else
echo "No command available to list network ports."
fi