141 lines
7.1 KiB
Plaintext
141 lines
7.1 KiB
Plaintext
Permissions audit 2026-06-14T06:37:59+00:00
|
|
|
|
=== Worker user ===
|
|
user nginx;
|
|
1 root 0:00 nginx: master process nginx -g daemon off;
|
|
20 nginx 0:00 nginx: worker process
|
|
21 nginx 0:00 nginx: worker process
|
|
22 nginx 0:00 nginx: worker process
|
|
23 nginx 0:00 nginx: worker process
|
|
24 nginx 0:00 nginx: worker process
|
|
25 nginx 0:00 nginx: worker process
|
|
26 nginx 0:00 nginx: worker process
|
|
27 nginx 0:00 nginx: worker process
|
|
28 nginx 0:00 nginx: worker process
|
|
29 nginx 0:00 nginx: worker process
|
|
30 nginx 0:00 nginx: worker process
|
|
31 nginx 0:00 nginx: worker process
|
|
32 nginx 0:00 nginx: worker process
|
|
33 nginx 0:00 nginx: worker process
|
|
34 nginx 0:00 nginx: worker process
|
|
35 nginx 0:00 nginx: worker process
|
|
36 nginx 0:00 nginx: worker process
|
|
37 nginx 0:00 nginx: worker process
|
|
38 nginx 0:00 nginx: worker process
|
|
39 nginx 0:00 nginx: worker process
|
|
|
|
=== Config permissions ===
|
|
total 40
|
|
drwxr-xr-x 1 root root 4096 Jun 14 05:28 .
|
|
drwxr-xr-x 1 root root 4096 Jun 14 05:28 ..
|
|
drwxrwxrwx 1 root root 4096 Jun 14 04:56 conf.d
|
|
-rw-r--r-- 1 root root 1077 Feb 5 2025 fastcgi.conf
|
|
-rw-r--r-- 1 root root 1007 Feb 5 2025 fastcgi_params
|
|
-rw-r--r-- 1 root root 43 Jun 14 06:37 htpasswd
|
|
-rw-r--r-- 1 root root 5349 Feb 5 2025 mime.types
|
|
lrwxrwxrwx 1 root root 22 Apr 16 2025 modules -> /usr/lib/nginx/modules
|
|
-rwxrwxrwx 1 root root 1233 Jun 14 06:27 nginx.conf
|
|
-rw-r--r-- 1 root root 636 Feb 5 2025 scgi_params
|
|
drwxrwxrwx 1 root root 4096 Jun 14 06:37 ssl
|
|
-rw-r--r-- 1 root root 664 Feb 5 2025 uwsgi_params
|
|
-rwxrwxrwx 1 root root 1233 Jun 14 06:27 /etc/nginx/nginx.conf
|
|
FAIL: nginx can write nginx.conf
|
|
|
|
=== Web root permissions ===
|
|
total 0
|
|
drwxrwxrwx 1 root root 4096 Jun 14 04:56 .
|
|
drwxrwxrwx 1 root root 4096 Jun 14 04:55 ..
|
|
-rwxrwxrwx 1 root root 138 Jun 14 04:56 index.html
|
|
FAIL: nginx can write web root
|
|
|
|
=== TLS certificates and keys ===
|
|
total 40
|
|
drwxrwxrwx 1 root root 4096 Jun 14 06:37 .
|
|
drwxr-xr-x 1 root root 4096 Jun 14 05:28 ..
|
|
-rw-r--r-- 1 root root 1814 Jun 14 06:37 ca.crt
|
|
-rw------- 1 root root 3272 Jun 14 06:37 ca.key
|
|
-rw-r--r-- 1 root root 1448 Jun 14 06:37 client.crt
|
|
-rw------- 1 root root 1704 Jun 14 06:37 client.key
|
|
-rw-r--r-- 1 root root 3254 Jun 14 06:37 fullchain.crt
|
|
-rw-r--r-- 1 root root 1440 Jun 14 06:37 server.crt
|
|
-rw------- 1 root root 1704 Jun 14 06:37 server.key
|
|
-rw-r--r-- 1 root root 1131 Jun 14 06:37 untrusted.crt
|
|
-rw------- 1 root root 1704 Jun 14 06:37 untrusted.key
|
|
OK: nginx cannot read private key
|
|
|
|
=== htpasswd ===
|
|
-rw-r--r-- 1 root root 43 Jun 14 06:37 /etc/nginx/htpasswd
|
|
OK: nginx cannot write htpasswd
|
|
|
|
=== Logs ===
|
|
total 8
|
|
drwxr-xr-x 2 root root 4096 Jun 14 05:18 .
|
|
drwxr-xr-x 1 root root 4096 Apr 16 2025 ..
|
|
lrwxrwxrwx 1 root root 11 Apr 16 2025 access.log -> /dev/stdout
|
|
lrwxrwxrwx 1 root root 11 Apr 16 2025 error.log -> /dev/stderr
|
|
|
|
=== Temp/cache paths ===
|
|
total 28
|
|
drwxr-xr-x 7 root root 4096 Jun 14 05:18 .
|
|
drwxr-xr-x 1 root root 4096 Apr 16 2025 ..
|
|
drwx------ 2 nginx root 4096 Jun 14 05:18 client_temp
|
|
drwx------ 2 nginx root 4096 Jun 14 05:18 fastcgi_temp
|
|
drwx------ 2 nginx root 4096 Jun 14 05:18 proxy_temp
|
|
drwx------ 2 nginx root 4096 Jun 14 05:18 scgi_temp
|
|
drwx------ 2 nginx root 4096 Jun 14 05:18 uwsgi_temp
|
|
client_body_temp_path /var/cache/nginx/client_temp;
|
|
proxy_temp_path /var/cache/nginx/proxy_temp;
|
|
|
|
=== Attack surface audit 2026-06-14T06:38:00+00:00 ===
|
|
--- nginx -V ---
|
|
nginx version: nginx/1.26.3
|
|
built by gcc 13.2.1 20240309 (Alpine 13.2.1_git20240309)
|
|
built with OpenSSL 3.3.0 9 Apr 2024 (running with OpenSSL 3.3.3 11 Feb 2025)
|
|
TLS SNI support enabled
|
|
configure arguments: --prefix=/etc/nginx --sbin-path=/usr/sbin/nginx --modules-path=/usr/lib/nginx/modules --conf-path=/etc/nginx/nginx.conf --error-log-path=/var/log/nginx/error.log --http-log-path=/var/log/nginx/access.log --pid-path=/var/run/nginx.pid --lock-path=/var/run/nginx.lock --http-client-body-temp-path=/var/cache/nginx/client_temp --http-proxy-temp-path=/var/cache/nginx/proxy_temp --http-fastcgi-temp-path=/var/cache/nginx/fastcgi_temp --http-uwsgi-temp-path=/var/cache/nginx/uwsgi_temp --http-scgi-temp-path=/var/cache/nginx/scgi_temp --with-perl_modules_path=/usr/lib/perl5/vendor_perl --user=nginx --group=nginx --with-compat --with-file-aio --with-threads --with-http_addition_module --with-http_auth_request_module --with-http_dav_module --with-http_flv_module --with-http_gunzip_module --with-http_gzip_static_module --with-http_mp4_module --with-http_random_index_module --with-http_realip_module --with-http_secure_link_module --with-http_slice_module --with-http_ssl_module --with-http_stub_status_module --with-http_sub_module --with-http_v2_module --with-http_v3_module --with-mail --with-mail_ssl_module --with-stream --with-stream_realip_module --with-stream_ssl_module --with-stream_ssl_preread_module --with-cc-opt='-Os -fstack-clash-protection -Wformat -Werror=format-security -fno-plt -g' --with-ld-opt='-Wl,--as-needed,-O1,--sort-common -Wl,-z,pack-relative-relocs'
|
|
--- load_module ---
|
|
(none)
|
|
--- optional modules in config ---
|
|
application/x-perl pl pm;
|
|
# П.4: auth_request
|
|
auth_request /auth;
|
|
--- autoindex ---
|
|
autoindex off;
|
|
# П.21: autoindex off
|
|
autoindex off;
|
|
--- limit_except / request_method ---
|
|
# П.7: limit_except
|
|
limit_except GET POST {
|
|
--- proxy_pass / upstream ---
|
|
upstream approved_backend {
|
|
upstream slow_upstream {
|
|
proxy_pass http://auth-mock:9999/validate;
|
|
proxy_pass_request_body off;
|
|
proxy_pass http://approved_backend/;
|
|
proxy_pass http://approved_backend/;
|
|
# П.13: error log через недоступный upstream
|
|
proxy_pass http://127.0.0.1:59999/;
|
|
proxy_pass http://approved_backend/status;
|
|
proxy_pass http://approved_backend/status;
|
|
proxy_pass http://slow_upstream/;
|
|
--- ssi ---
|
|
(ssi off)
|
|
|
|
=== Code execution control audit 2026-06-14T06:38:01+00:00 ===
|
|
application/x-perl pl pm;
|
|
root /usr/share/nginx/html/public;
|
|
root /usr/share/nginx/html/errors;
|
|
internal;
|
|
alias /usr/share/nginx/html/public/;
|
|
alias /usr/share/nginx/html/public/;
|
|
alias /usr/share/nginx/html/public/;
|
|
internal;
|
|
# П.8: internal
|
|
internal;
|
|
alias /usr/share/nginx/html/protected/;
|
|
alias /usr/share/nginx/html/files/;
|
|
alias /usr/share/nginx/html/public/;
|
|
root /usr/share/nginx/html/public;
|
|
--- SCRIPT_FILENAME ---
|
|
(no fastcgi)
|