From af88ccb5ebb84939a5cae9eda2ff085434dd319b Mon Sep 17 00:00:00 2001 From: yoavrotems Date: Sun, 26 May 2019 15:10:46 +0300 Subject: [PATCH 1/3] Update 1.1.25.sh --- cfg/1.1.0/1.1.25.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/cfg/1.1.0/1.1.25.sh b/cfg/1.1.0/1.1.25.sh index 5b3fd58..a41888b 100644 --- a/cfg/1.1.0/1.1.25.sh +++ b/cfg/1.1.0/1.1.25.sh @@ -1 +1 @@ -df --local -P | awk {'if (NR!=1) print $6'} | xargs -I '{}' find '{}' -xdev -type d \( -perm -0002 -a ! -perm -1000 \) 2>/dev/null +df --local -P | awk {'if (NR!=1) print $6'} | xargs -I '{}' find '{}' -xdev -type d \( -perm -0002 -a ! -perm -1000 \) 2>/dev/null | head -n 100 From 2602610bf04779f772395e5946854454b3731b65 Mon Sep 17 00:00:00 2001 From: yoavrotems Date: Thu, 26 Sep 2019 00:20:21 +0300 Subject: [PATCH 2/3] Update definitions.yaml Return test 1.1.25 to be regular --- cfg/1.1.0/definitions.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/cfg/1.1.0/definitions.yaml b/cfg/1.1.0/definitions.yaml index a39b6a1..ac11655 100644 --- a/cfg/1.1.0/definitions.yaml +++ b/cfg/1.1.0/definitions.yaml @@ -564,7 +564,7 @@ groups: - id: 1.1.25 description: "Ensure sticky bit is set on all world-writable directories" - audit: "./1.1.25.sh" + audit: "df --local -P | awk {'if (NR!=1) print $6'} | xargs -I '{}' find '{}' -xdev -type d \\( -perm -0002 -a ! -perm -1000 \\) 2>/dev/null | head -n 100" tests: test_items: - flag: "" From 415c371cc298772812b4ce1ae815d4ba0855db6b Mon Sep 17 00:00:00 2001 From: yoavrotems Date: Thu, 26 Sep 2019 00:21:05 +0300 Subject: [PATCH 3/3] Delete 1.1.25.sh Remove this because it returned to the yaml file --- cfg/1.1.0/1.1.25.sh | 1 - 1 file changed, 1 deletion(-) delete mode 100644 cfg/1.1.0/1.1.25.sh diff --git a/cfg/1.1.0/1.1.25.sh b/cfg/1.1.0/1.1.25.sh deleted file mode 100644 index a41888b..0000000 --- a/cfg/1.1.0/1.1.25.sh +++ /dev/null @@ -1 +0,0 @@ -df --local -P | awk {'if (NR!=1) print $6'} | xargs -I '{}' find '{}' -xdev -type d \( -perm -0002 -a ! -perm -1000 \) 2>/dev/null | head -n 100