second
هذا الالتزام موجود في:
73
q1-deploy-monitor/health-check.sh
Normal file
73
q1-deploy-monitor/health-check.sh
Normal file
@@ -0,0 +1,73 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Ghaymah Automated Security Check
|
||||
set -uo pipefail
|
||||
|
||||
echo "=========================================="
|
||||
echo " Ghaymah Automated Security Check "
|
||||
echo "=========================================="
|
||||
|
||||
TARGET_DOMAIN="ghaymah.systems"
|
||||
TARGET_PORT="443"
|
||||
WARNINGS=0
|
||||
|
||||
require_tool() {
|
||||
if ! command -v "$1" >/dev/null 2>&1; then
|
||||
echo "❌ ERROR: required tool '$1' not found. Skipping this check."
|
||||
return 1
|
||||
fi
|
||||
return 0
|
||||
}
|
||||
|
||||
# 1. Check Open Ports (is SSH port 22 exposed on this host?)
|
||||
echo "[1] Checking Network Ports (local host exposure)..."
|
||||
if require_tool nc; then
|
||||
if nc -z -v -w5 localhost 22 2>/dev/null; then
|
||||
echo "⚠️ WARNING: Port 22 (SSH) is OPEN on this host. Restrict it to a Bastion/VPN only."
|
||||
WARNINGS=$((WARNINGS+1))
|
||||
else
|
||||
echo "✅ Port 22 is properly closed or filtered on this host."
|
||||
fi
|
||||
fi
|
||||
|
||||
# 2. Check SSL/TLS Certificate validity for the public-facing domain
|
||||
echo ""
|
||||
echo "[2] Checking SSL Certificate for $TARGET_DOMAIN..."
|
||||
if require_tool openssl; then
|
||||
EXPIRATION_DATE=$(echo | openssl s_client -servername "$TARGET_DOMAIN" -connect "$TARGET_DOMAIN:$TARGET_PORT" 2>/dev/null \
|
||||
| openssl x509 -noout -enddate 2>/dev/null | cut -d= -f2)
|
||||
|
||||
if [ -n "$EXPIRATION_DATE" ]; then
|
||||
echo "✅ SSL Certificate is valid. Expires on: $EXPIRATION_DATE"
|
||||
else
|
||||
echo "❌ ERROR: Could not retrieve SSL certificate. Check connection or HTTPS configuration."
|
||||
WARNINGS=$((WARNINGS+1))
|
||||
fi
|
||||
fi
|
||||
|
||||
# 3. Check File Permissions — integrity check, NOT a "secrets" check.
|
||||
# /etc/passwd holds account metadata (not password hashes — those live
|
||||
# in /etc/shadow). What matters here is that it's NOT writable by
|
||||
# anyone but root; 644 (or 600) is the safe baseline.
|
||||
echo ""
|
||||
echo "[3] Checking File Integrity Permissions..."
|
||||
if require_tool stat; then
|
||||
SENSITIVE_FILE="/etc/passwd"
|
||||
PERMISSIONS=$(stat -c "%a" "$SENSITIVE_FILE" 2>/dev/null)
|
||||
|
||||
if [ "$PERMISSIONS" == "644" ] || [ "$PERMISSIONS" == "600" ]; then
|
||||
echo "✅ Permissions for $SENSITIVE_FILE are secure ($PERMISSIONS) — not writable by non-root users."
|
||||
else
|
||||
echo "⚠️ WARNING: Permissions for $SENSITIVE_FILE are $PERMISSIONS (expected 644 or 600). This may allow unauthorized writes."
|
||||
WARNINGS=$((WARNINGS+1))
|
||||
fi
|
||||
fi
|
||||
|
||||
echo ""
|
||||
echo "=========================================="
|
||||
if [ "$WARNINGS" -eq 0 ]; then
|
||||
echo " ✅ All checks passed "
|
||||
else
|
||||
echo " ⚠️ Scan completed with $WARNINGS warning(s)"
|
||||
fi
|
||||
echo "=========================================="
|
||||
المرجع في مشكلة جديدة
حظر مستخدم