Bastille Hardening Assessment Report

ScoreWeights File
10.00 / 10.00 Bastille Default Weights

ItemQuestionStateWeightScore Contrib
generalperms_1_1Are more restrictive permissions on the administration utilities set?Yes00.00
suidmountIs SUID status for mount/umount disabled?Yes11.00
suidpingIs SUID status for ping disabled?Yes11.00
suiddumpIs SUID status for dump and restore disabled?Yes11.00
suidcardIs SUID status for cardctl disabled?Yes11.00
suidatIs SUID status for at disabled?Yes11.00
suiddosIs SUID status for DOSEMU disabled?Yes11.00
suidnewsIs SUID status for news server tools disabled?Yes11.00
suidprintIs SUID status for printing utilities disabled?Yes11.00
suidrtoolAre the r-tools disabled?Yes11.00
suidusernetctlIs SUID status for usernetctl disabled?Yes11.00
suidtraceIs SUID status for traceroute disabled?Yes11.00
suidXwrapperIs SUID status for Xwrapper disabled?Yes11.00
suidXFree86Is SUID status for XFree86 disabled?Yes11.00


protectrhostAre clear-text r-protocols that use IP-based authentication disabled?Yes00.00
passwdageIs password aging enforced?Yes11.00
password_strength_linuxAre longer, stronger passwords required?Yes11.00
cronuserIs the use of cron restricted to administrative accounts?Yes11.00
umaskynIs the default umask set to a minimal value?Yes11.00
rootttyloginsAre root logins on tty's 1-6 prohibited?Yes11.00
removeaccountsHave extraneous accounts been deleted?Yes00.00
removegroupsHave extraneous groups been deleted?Yes00.00


protectgrubIs the GRUB prompt password-protected?Yes11.00
protectliloIs the LILO prompt password-protected?Yes11.00
lilodelayIs the LILO delay time zero?Yes00.00
secureinittabIs CTRL-ALT-DELETE rebooting disabled?Yes00.00
passsumIs single-user mode password-protected?Yes11.00


tcpd_default_denyIs a default-deny on TCP Wrappers and xinetd set?Yes11.00
deactivate_telnetIs the telnet service disabled on this system?Yes11.00
deactivate_ftpIs inetd's FTP service disabled on this system?Yes11.00
bannersAre "Authorized Use" messages displayed at log-in time?Yes11.00


compilerAre the gcc and/or g++ compiler disabled?Yes11.00


moreloggingHas additional logging been added?Yes11.00
pacctIs process accounting set up?Yes11.00
lausIs LAuS active?Yes11.00


apmdIs apmd disabled?Yes11.00
remotefsAre NFS and Samba deactivated?Yes11.00
pcmciaAre PCMCIA services disabled?Yes11.00
dhcpdIs the DHCP daemon disabled?Yes11.00
gpmIs GPM disabled?Yes11.00
inndIs the news server daemon disabled?Yes11.00
disable_routedIs routed deactivated?Yes11.00
disable_gatedIs gated deactivated?Yes11.00
nis_serverAre NIS server programs deactivated?Yes11.00
nis_clientAre NIS client programs deactivated?Yes11.00
snmpdIs SNMPD disabled?Yes11.00
disable_kudzuIs kudzu's run at boot deactivated?Yes11.00


sendmaildaemonIs sendmail's daemon mode disabled?Yes11.00
sendmailcronDoes sendmail process the queue via cron?Yes00.00
vrfyexpnAre the VRFY and EXPN sendmail commands disabled?Yes11.00


chrootbindIs named in a chroot jail and is it set to run as a non-root user?Yes00.00
namedoffIs named deactivated?Yes11.00


apacheoffIs the Apache Web server deactivated?Yes11.00
bindapachelocalIs the Web server bound to listen only to the localhost?Yes00.00
bindapachenicIs the Web server bound to a particular interface?Yes00.00
symlinkIs the following of symbolic links deactivated?Yes11.00
ssiAre server-side includes deactivated?Yes11.00
cgiAre CGI scripts disabled?Yes11.00
apacheindexAre indexes disabled?Yes11.00


printingIs printing disabled?Yes11.00
printing_cupsIs printing disabled?Yes11.00
printing_cups_lpd_legacyIs CUPS' legacy LPD support disabled?Yes11.00


userftpAre user privileges on the FTP daemon disabled?Yes11.00
anonftpIs anonymous download disabled?Yes11.00