TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Lynis – Security auditing and hardening tool, for Unix-based systems

67 pointsby Qision7 months ago

3 comments

josephcsible7 months ago
Rules like <a href="https:&#x2F;&#x2F;cisofy.com&#x2F;lynis&#x2F;controls&#x2F;HRDN-7222&#x2F;" rel="nofollow">https:&#x2F;&#x2F;cisofy.com&#x2F;lynis&#x2F;controls&#x2F;HRDN-7222&#x2F;</a> make me think the whole thing is snake oil. There is <i>zero</i> security benefit to making publicly-available compilers not be world-readable.
评论 #42097714 未加载
评论 #42097639 未加载
评论 #42098990 未加载
patrakov6 months ago
Rules like <a href="https:&#x2F;&#x2F;cisofy.com&#x2F;lynis&#x2F;controls&#x2F;AUTH-9282&#x2F;" rel="nofollow">https:&#x2F;&#x2F;cisofy.com&#x2F;lynis&#x2F;controls&#x2F;AUTH-9282&#x2F;</a> are something that NIST calls outdated and dangerous password practice, but foreign security bodies mandate. Go figure.<p>Also, the suggestion from <a href="https:&#x2F;&#x2F;cisofy.com&#x2F;lynis&#x2F;controls&#x2F;NAME-4404&#x2F;" rel="nofollow">https:&#x2F;&#x2F;cisofy.com&#x2F;lynis&#x2F;controls&#x2F;NAME-4404&#x2F;</a> is just wrong on systems with nss_myhostname (from systemd) configured.
评论 #42105035 未加载
kosolam7 months ago
Seems like a good thing. Anyone here has experience with this tool?
评论 #42095405 未加载
评论 #42094711 未加载
评论 #42099198 未加载
评论 #42094720 未加载