Lynis v1.5.9 Released

Lynis v1.5.9 Released

Lynis is an auditing tool which tests and gathers (security) information from Unix based systems. The audience for this tool are security and system auditors, network specialists and system maintainers.

Some of the (future) features and usage options:

  • System and security audit checks
  • File Integrity Assessment
  • System and file forensics
  • Usage of templates/baselines (reporting and monitoring)
  • Extended debugging features

This tool is tested or confirmed to work with at least: AIX, Linux, FreeBSD, OpenBSD, Mac OS X, Solaris. See website for the full list of tested operating systems.

lynis-screenshot

 

Changelog v1.5.9 (2014-07-31)

New:

  • New NetBSD test for vulnerable software packages [PKGS-7380]
  • Test if Debian based systems need a reboot [KRNL-5830]
  • Test for running Sendmail daemon [MAIL-8880]
  • Test for availability of mtree [FINT-4330]
  • Check for lp daemon (printing) [PRNT-2314]
  • Added Qmail status detection [MAIL-8860]
  • New NetBSD boot loader test [BOOT-5126]
  • Added test for automation tools like Cfengine and Puppet [TOOL-5002]
  • Added KRNL-5830 control to website
  • Added detection for Puppet
  • Added tooling category

Changes:

  • Security repository test extended with /etc/apt/sources.list.d [PKGS-7388]
  • Added exception case for CUPS configuration (listen statement) [PRNT-2308]
  • Improved detection of TMOUT setting in shell profile file [SHLL-6220]
  • Perform promiscuous interfaces test for NetBSD as well [NETW-3014]
  • Perform swap partition parameters test on all systems [FILE-6336]
  • Also check password file on DragonFlyBSD and NetBSD [AUTH-9208]
  • Show message regarding toor user for all systems [AUTH-9204]
  • Check for available interfaces on NetBSD as well [NETW-3004]
  • Extended UFS file system test with FFS support [FILE-6329]
  • Improvements for step-tickers file test [TIME-3160]
  • Perform sockstat test for NetBSD [NETW-3012]
  • Gather IP addresses for NetBSD [NETW-3008]
  • Test MAC addresses on NetBSD [NETW-3006]
  • Added /usr/X11R7/bin directory to search for binaries
  • Improved full qualified domain name (FQDN) check for Linux
  • Don’t show follow-up hints when there are no warnings or suggestions
  • Improved IsRunning function to better target processes
  • Several smaller adjustments in text and descriptions
  • Extended ReportException function with logging text
  • Improved GetHostID function for NetBSD and Solaris
  • Added printing_daemon and mail_daemon to report
  • Binaries extended with tools like kstat, puppet

 

More Information:

Download Lynis v1.5.9

 

MaxiSoler

www.artssec.com @maxisoler