| FAIL | 1.1.1 | filesystem | /tmp is a separate partition or tmpfs/tmp is not a separate mount fix: Mount /tmp as tmpfs or a dedicated partition with nodev,nosuid,noexec. |
| FAIL | 1.1.2 | filesystem | Sticky bit set on all world-writable directories/tmp/phantomjs /tmp/phantomjs/phantomjs-2.1.1-linux-x86_64.tar.bz2-extract-1778273066038 fix: chmod +t on each directory listed in the evidence. |
| PASS | 1.5.1 | filesystem | Core dumps are restrictedfs.suid_dumpable = 0 |
| PASS | 1.5.2 | filesystem | ASLR is enabledkernel.randomize_va_space = 2 |
| PASS | 1.7.1 | filesystem | Login banner files owned by root and not group/world-writable/etc/issue mode=0o644 owner=0:0 /etc/issue.net mode=0o644 owner=0:0 |
| PASS | 3.3.1 | network | IP forwarding disabled (unless a router)net.ipv4.ip_forward = 0 |
| FAIL | 3.3.2 | network | ICMP redirects are not acceptednet.ipv4.conf.all.accept_redirects = 1 net.ipv4.conf.default.accept_redirects = 1 fix: Set net.ipv4.conf.all.accept_redirects = 0 and .default.accept_redirects = 0. |
| FAIL | 3.3.3 | network | Source-routed packets are not acceptednet.ipv4.conf.all.accept_source_route = 0 net.ipv4.conf.default.accept_source_route = 1 fix: Set net.ipv4.conf.all.accept_source_route = 0 and .default.accept_source_route = 0. |
| PASS | 3.3.9 | network | TCP SYN cookies enablednet.ipv4.tcp_syncookies = 1 |
| FAIL | 3.5 | network | A host firewall is active (nftables/iptables/firewalld/ufw)probed: nft, iptables; no active ruleset found fix: Enable and configure one host firewall (e.g. 'ufw enable' or firewalld/nftables). |
| SKIP | 5.1.20 | ssh | SSH root login is disabled or key-onlysshd configuration not found |
| SKIP | 5.1.a | ssh | SSH password authentication disabled (keys only)sshd configuration not found |
| SKIP | 5.1.21 | ssh | SSH empty passwords are not permittedsshd configuration not found |
| SKIP | 5.1.13 | ssh | SSH X11 forwarding disabledsshd configuration not found |
| SKIP | 5.1.1 | ssh | sshd_config owned by root and mode 600/etc/ssh/sshd_config not present |
| SKIP | 5.1.3 | ssh | SSH private host keys not readable by othersno host keys found |
| PASS | 5.4.2.1 | accounts | root is the only UID-0 accountUID 0 accounts: root |
| PASS | 5.4.2.x | accounts | No accounts with empty password fieldsno empty password fields in /etc/shadow |
| FAIL | 5.4.1.1 | accounts | Password expiry policy set (PASS_MAX_DAYS <= 365)PASS_MAX_DAYS = 99999 fix: Set PASS_MAX_DAYS 365 (or your policy) in /etc/login.defs and per-user with chage. |
| FAIL | 5.4.3.3 | accounts | Default umask is 027 or stricterUMASK = 022 fix: Set 'umask 027' in /etc/login.defs (UMASK) and shell profile files. |
| PASS | 6.1.1 | permissions | /etc/passwd owned by root, mode 644 or stricter/etc/passwd mode=0o644 owner=0:0 |
| PASS | 6.1.3 | permissions | /etc/group owned by root, mode 644 or stricter/etc/group mode=0o644 owner=0:0 |
| PASS | 6.1.5 | permissions | /etc/shadow owned by root, mode 640 or stricter/etc/shadow mode=0o640 owner=0:42 |
| PASS | 6.1.7 | permissions | /etc/gshadow owned by root, mode 640 or stricter/etc/gshadow mode=0o640 owner=0:42 |
| SKIP | 5.1.2 | permissions | /etc/crontab owned by root, mode 600 or stricter/etc/crontab not present |
| FAIL | 6.1.9 | permissions | No world-writable regular files/root/.local/share/uv/tools/.lock /tmp/uv-setuptools-e189ac0c3b795765.lock /tmp/uv-setuptools-135e46068b9a98be.lock /tmp/uv-setuptools-f340a9adbea9fcc6.lock /tmp/uv-ce9cd633bb00c47d.lock /home/claude/.cache/uv/sdists-v9/index/a9e76d7595fd976e/odfpy/1.4.1/.lock /home/claude/.cache/uv/sdists-v9/index/a9e76d7595fd976e/pyoo/1.4/.lock /home/claude/.cache/uv/sdists-v9/index/a9e76d7595fd976e/path-and-address/2.0.1/.lock /opt/node22/etc/npmrc fix: Review each file in the evidence; chmod o-w or delete. |
| FAIL | 6.1.10 | permissions | No unowned or ungrouped files/root/.local/bin/uvx /root/.local/bin/uv /usr/local/bin/golangci-lint /opt/node20/share /opt/node20/share/doc /opt/node20/share/doc/node /opt/node20/share/doc/node/gdbinit /opt/node20/share/doc/node/lldb_commands.py /opt/node20/share/man /opt/node20/share/man/man1 /opt/node20/share/man/man1/node.1 /opt/node20/README.md /opt/node20/LICENSE /opt/node20/lib /opt/node20/lib/node_modules /opt/node20/lib/node_modules/corepack /opt/node20/lib/node_modules/corepack/dist /opt/node20/lib/node_modules/corepack/dist/npx.js /opt/node20/lib/node_modules/corepack/dist/yarn.js /opt/node20/lib/node_modules/corepack/dist/pnpm.js fix: chown files in the evidence to a valid user/group, or remove them. |
| PASS | 6.2.1 | logging | A system log daemon is active (rsyslog/syslog-ng/journald)rsyslogd running (pid 1108) |
| FAIL | 6.3.1 | logging | auditd is installed and runningauditd not installed fix: Install auditd ('apt/yum install audit'), enable the service, and load rules. |