cis-lite v0.3.0 - vm

Ubuntu 24.04.4 LTS · kernel 6.18.44-fc-v37 · 2026-09-23T08:14:53+00:00 · run as uid 0
55%
12 passed · 10 failed · 7 skipped
FAIL1.1.1filesystem/tmp is a separate partition or tmpfs
/tmp is not a separate mount

fix: Mount /tmp as tmpfs or a dedicated partition with nodev,nosuid,noexec.

FAIL1.1.2filesystemSticky bit set on all world-writable directories
/tmp/phantomjs
/tmp/phantomjs/phantomjs-2.1.1-linux-x86_64.tar.bz2-extract-1778273066038

fix: chmod +t on each directory listed in the evidence.

PASS1.5.1filesystemCore dumps are restricted
fs.suid_dumpable = 0
PASS1.5.2filesystemASLR is enabled
kernel.randomize_va_space = 2
PASS1.7.1filesystemLogin banner files owned by root and not group/world-writable
/etc/issue mode=0o644 owner=0:0
/etc/issue.net mode=0o644 owner=0:0
PASS3.3.1networkIP forwarding disabled (unless a router)
net.ipv4.ip_forward = 0
FAIL3.3.2networkICMP redirects are not accepted
net.ipv4.conf.all.accept_redirects = 1
net.ipv4.conf.default.accept_redirects = 1

fix: Set net.ipv4.conf.all.accept_redirects = 0 and .default.accept_redirects = 0.

FAIL3.3.3networkSource-routed packets are not accepted
net.ipv4.conf.all.accept_source_route = 0
net.ipv4.conf.default.accept_source_route = 1

fix: Set net.ipv4.conf.all.accept_source_route = 0 and .default.accept_source_route = 0.

PASS3.3.9networkTCP SYN cookies enabled
net.ipv4.tcp_syncookies = 1
FAIL3.5networkA host firewall is active (nftables/iptables/firewalld/ufw)
probed: nft, iptables; no active ruleset found

fix: Enable and configure one host firewall (e.g. 'ufw enable' or firewalld/nftables).

SKIP5.1.20sshSSH root login is disabled or key-only
sshd configuration not found
SKIP5.1.asshSSH password authentication disabled (keys only)
sshd configuration not found
SKIP5.1.21sshSSH empty passwords are not permitted
sshd configuration not found
SKIP5.1.13sshSSH X11 forwarding disabled
sshd configuration not found
SKIP5.1.1sshsshd_config owned by root and mode 600
/etc/ssh/sshd_config not present
SKIP5.1.3sshSSH private host keys not readable by others
no host keys found
PASS5.4.2.1accountsroot is the only UID-0 account
UID 0 accounts: root
PASS5.4.2.xaccountsNo accounts with empty password fields
no empty password fields in /etc/shadow
FAIL5.4.1.1accountsPassword expiry policy set (PASS_MAX_DAYS <= 365)
PASS_MAX_DAYS = 99999

fix: Set PASS_MAX_DAYS 365 (or your policy) in /etc/login.defs and per-user with chage.

FAIL5.4.3.3accountsDefault umask is 027 or stricter
UMASK = 022

fix: Set 'umask 027' in /etc/login.defs (UMASK) and shell profile files.

PASS6.1.1permissions/etc/passwd owned by root, mode 644 or stricter
/etc/passwd mode=0o644 owner=0:0
PASS6.1.3permissions/etc/group owned by root, mode 644 or stricter
/etc/group mode=0o644 owner=0:0
PASS6.1.5permissions/etc/shadow owned by root, mode 640 or stricter
/etc/shadow mode=0o640 owner=0:42
PASS6.1.7permissions/etc/gshadow owned by root, mode 640 or stricter
/etc/gshadow mode=0o640 owner=0:42
SKIP5.1.2permissions/etc/crontab owned by root, mode 600 or stricter
/etc/crontab not present
FAIL6.1.9permissionsNo world-writable regular files
/root/.local/share/uv/tools/.lock
/tmp/uv-setuptools-e189ac0c3b795765.lock
/tmp/uv-setuptools-135e46068b9a98be.lock
/tmp/uv-setuptools-f340a9adbea9fcc6.lock
/tmp/uv-ce9cd633bb00c47d.lock
/home/claude/.cache/uv/sdists-v9/index/a9e76d7595fd976e/odfpy/1.4.1/.lock
/home/claude/.cache/uv/sdists-v9/index/a9e76d7595fd976e/pyoo/1.4/.lock
/home/claude/.cache/uv/sdists-v9/index/a9e76d7595fd976e/path-and-address/2.0.1/.lock
/opt/node22/etc/npmrc

fix: Review each file in the evidence; chmod o-w or delete.

FAIL6.1.10permissionsNo unowned or ungrouped files
/root/.local/bin/uvx
/root/.local/bin/uv
/usr/local/bin/golangci-lint
/opt/node20/share
/opt/node20/share/doc
/opt/node20/share/doc/node
/opt/node20/share/doc/node/gdbinit
/opt/node20/share/doc/node/lldb_commands.py
/opt/node20/share/man
/opt/node20/share/man/man1
/opt/node20/share/man/man1/node.1
/opt/node20/README.md
/opt/node20/LICENSE
/opt/node20/lib
/opt/node20/lib/node_modules
/opt/node20/lib/node_modules/corepack
/opt/node20/lib/node_modules/corepack/dist
/opt/node20/lib/node_modules/corepack/dist/npx.js
/opt/node20/lib/node_modules/corepack/dist/yarn.js
/opt/node20/lib/node_modules/corepack/dist/pnpm.js

fix: chown files in the evidence to a valid user/group, or remove them.

PASS6.2.1loggingA system log daemon is active (rsyslog/syslog-ng/journald)
rsyslogd running (pid 1108)
FAIL6.3.1loggingauditd is installed and running
auditd not installed

fix: Install auditd ('apt/yum install audit'), enable the service, and load rules.