Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add SCA Policy for HP-UX B.11.31 #10696

Closed
dariommr opened this issue Oct 29, 2021 · 5 comments · Fixed by #15157
Closed

Add SCA Policy for HP-UX B.11.31 #10696

dariommr opened this issue Oct 29, 2021 · 5 comments · Fixed by #15157
Assignees
Labels
feed/sca Security Configuration Assessment policies related issues reporter/operations team/threatintel Threat Intelligence team

Comments

@dariommr
Copy link
Member

dariommr commented Oct 29, 2021

Wazuh version Component Install type Install method Platform
4.2.3-rev SCA Agent Packages HP-UX B.11.31

Hello Team,
I am reaching you with this request for Security Assessment Policies for HP-UX B.11.31.

The only document I found is this, and it is from 2009 and for version 11i: https://www.cisecurity.org/wp-content/uploads/2017/04/CIS_HP-UX_11i_Benchmark_v1.5.0.pdf

I hope this could be helpful.

There will be two different policies for the same OS, one will use the bastille tool from HP, the other one will use standard UNIX commands

@jcruzlp
Copy link
Contributor

jcruzlp commented Nov 9, 2021

Branch for tracking the changes and progress: https://github.com/wazuh/wazuh/tree/10696-hpux-sca

Added literature to all checks, only remains to add rules that must be tested when the machine is provided,
Some of them probably will be removed, but in this way, we can maximize the use of the machine.

The created SCA seems to work correctly in the test we performed:
image

The only thing remaining is to verify that the values correlate with what we need and then is ready to make, also is necessary to create SPECS for this, since it's a new one.

@maumrsms
Copy link
Member

maumrsms commented Feb 1, 2022

Hello team,
I've tried to add the policies worked here but they don't seem to work:
image
image
image
image

Now checking the rules I noticed we're using some Bastille related files. For example:
image

I haven't seen any mention about this nor its configuration (I'm not even sure if Bastille comes out-of-the-box in HP-UX).
I imagine that some specific configuration would be needed on it too (files ownership in /var/opt/sec_mgmt/bastille/log/Assessment at least)
Could you please provide more information about this?

@maumrsms
Copy link
Member

maumrsms commented Feb 2, 2022

Hello team,

I've just confirmed that this solution requires Bastille to be installed in /opt/sec_mgmt/bastille/ for the Agent to be able to create it source files in /var/opt/sec_mgmt/bastille/log/Assessment.

I managed to replicate the situation in a different box after renaming the Bastille binary (/opt/sec_mgmt/bastille/bin/bastille):
image
image
With the binary out, the Agent was not able to generate iits source files in /var/opt/sec_mgmt/bastille/log/Assessment, thus, most items as "Not Applicable"

@sebastiandbustos
Copy link
Member

Hello Team,
The customer informs the HP-UX policy is working with the exception of 2 checks, here is the information provided by the customer with the checks and the errors:

21039
Configure IPFilter to allow only select communication.
Invalid path or wrong permissions to run command 'ipf -v -l'

21133 - Resolve "unowned" files and directories.
Timeout overtaken running command 'find / ( -nouser -o -nogroup )'

Please let me know.
Thank you.

@sebastiandbustos
Copy link
Member

Jose Izquierdo provided the corrected policy, updating the issue with the file.

cis_hpux_11i.zip

@72nomada 72nomada assigned 72nomada and unassigned jcruzlp Feb 24, 2022
@72nomada 72nomada changed the title SCA Policy for HP-UX B.11.31 Add SCA Policy for HP-UX B.11.31 Jun 6, 2022
@72nomada 72nomada added team/threatintel Threat Intelligence team and removed threatintel/sca labels Jun 26, 2022
@vikman90 vikman90 added this to the Release 4.4.0 milestone Aug 29, 2022
@72nomada 72nomada added the feed/sca Security Configuration Assessment policies related issues label Oct 11, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feed/sca Security Configuration Assessment policies related issues reporter/operations team/threatintel Threat Intelligence team
Projects
No open projects
Status: Done
Development

Successfully merging a pull request may close this issue.

6 participants