Commit Graph

  • 5230b22876 Merge pull request #287 from draios/prepare-for-0.8.0 Mark Stemm 2017-10-09 17:15:38 -07:00
  • 1676333d7b Docs changes for 0.8.0 Mark Stemm 2017-10-09 15:16:39 -07:00
  • 4a8ac8d164 Merge pull request #259 from draios/more-beta-updates Mark Stemm 2017-10-09 15:09:09 -07:00
  • e1044629cb Work around unknown users in containers wrt setuid Mark Stemm 2017-10-09 13:15:39 -07:00
  • 080305c7a0 Adjust for new severity Mark Stemm 2017-10-09 13:05:12 -07:00
  • 26d5ea0123 Merge pull request #286 from draios/no-config-when-validate-rules Mark Stemm 2017-10-09 12:50:56 -07:00
  • 53ca4349f9 Add ability to validate rules file Mark Stemm 2017-10-09 12:02:23 -07:00
  • 0fcd01f98d Let git modify nssdb Mark Stemm 2017-10-09 10:37:33 -07:00
  • 1b591dc4f3 Misc build-related fixes Mark Stemm 2017-10-09 10:36:35 -07:00
  • 43b773e9b2 Misc gem/ruby/bundler changes Mark Stemm 2017-10-09 10:34:41 -07:00
  • 0d88c3020d Let qualys perform more actions. Mark Stemm 2017-10-06 13:43:30 -07:00
  • 33a28cc173 Let node running yarn spawn shells. Mark Stemm 2017-10-05 08:54:35 -07:00
  • a68d2ad769 Let bundle spawn shells. Mark Stemm 2017-10-05 08:44:13 -07:00
  • a921012a6c let logdna-agent spawn shells. Mark Stemm 2017-10-04 16:11:00 -07:00
  • 08afb75009 Add /etc/hrmconfig as a safe directory. Mark Stemm 2017-09-29 15:34:52 -07:00
  • 823c105f54 Let systemd-udevd spawn shells Mark Stemm 2017-09-29 15:12:20 -07:00
  • bde8d67330 Let psql read sensitive files. Mark Stemm 2017-09-29 15:12:08 -07:00
  • 9504d420f0 Add more jenkins spawners. Mark Stemm 2017-09-29 15:11:20 -07:00
  • 4f5ab79c69 Add xray-rabbitmq shell spawning programs. Mark Stemm 2017-09-29 15:10:28 -07:00
  • 6540a856fa Let adclient write below etc. Mark Stemm 2017-09-25 08:45:16 -07:00
  • c3c171c7e5 More centrify changes. Mark Stemm 2017-09-25 08:36:35 -07:00
  • 011cb2f030 Also let mailq setuid. Mark Stemm 2017-09-25 08:24:48 -07:00
  • 59ab40d457 Let centrify spawn shells. Mark Stemm 2017-09-25 08:20:28 -07:00
  • cf5397f701 Change level for sshkit binaries. Mark Stemm 2017-09-25 08:17:54 -07:00
  • cff8ca428a The right program was mailq Mark Stemm 2017-09-25 08:11:46 -07:00
  • d9cb1e2b27 Let adclient/certutil spawn shells/write below etc Mark Stemm 2017-09-25 07:51:18 -07:00
  • 96992d7ac3 Add scripts possibly run by sshkit Mark Stemm 2017-09-25 07:44:15 -07:00
  • a22099c8c3 Let adclient spawn shells. Mark Stemm 2017-09-25 07:42:53 -07:00
  • 0e009fc89a Let smmsp setuid. Mark Stemm 2017-09-25 07:41:30 -07:00
  • 1a41eeada7 Add ability to augment sensitive file reads Mark Stemm 2017-09-21 08:40:52 -07:00
  • fefb8ba614 Allow puppet to run shells. Mark Stemm 2017-09-21 08:31:43 -07:00
  • 2bc9d35d37 Let nfsnobody become themself. Mark Stemm 2017-09-21 08:25:35 -07:00
  • 09748fcbb3 Allow writes to /etc/motd Mark Stemm 2017-09-21 08:25:08 -07:00
  • a0e88417fc Add more container innocuous cmdlines Mark Stemm 2017-09-20 18:42:33 -07:00
  • e44ce9a8d3 Add calico/node as a trusted container. Mark Stemm 2017-09-20 18:25:11 -07:00
  • c4c5d2f585 Let chef read sensitive files Mark Stemm 2017-09-20 18:22:11 -07:00
  • 340ee2ece7 Add general ability to augment write_etc_common Mark Stemm 2017-09-20 18:20:35 -07:00
  • 00dd3c47c0 Allow systemd --version as a "user mgmt binary" Mark Stemm 2017-09-19 16:54:48 -07:00
  • 7c8a85158a Decrease terminal shell in container to debug Mark Stemm 2017-09-13 17:13:11 -07:00
  • d0650688d5 Let mysql_ssl_rsa_s spawn shells Mark Stemm 2017-09-06 15:42:21 -07:00
  • 425196f974 Let weave spawn shells. Mark Stemm 2017-08-25 09:26:09 -07:00
  • 70d6e8de2f Add more ancestors for tracking. Mark Stemm 2017-08-25 09:25:52 -07:00
  • 6dfdadf527 Also let runc:[1:CHILD] count as an entrypoint. Mark Stemm 2017-08-25 08:16:39 -07:00
  • 606af16f27 Let updatedb.findut spawn shells. Mark Stemm 2017-08-25 08:16:21 -07:00
  • 3b5f959de9 Add additional node/edi command lines. Mark Stemm 2017-08-25 08:08:02 -07:00
  • a4d3d4d731 Also let docker-runc denote an entrypoint. Mark Stemm 2017-08-25 08:05:58 -07:00
  • 276ab9139f Let hddtemp.postins(t) write below etc. Mark Stemm 2017-08-25 07:48:32 -07:00
  • ee02571889 Add x2go binaries as a list Mark Stemm 2017-08-25 07:47:53 -07:00
  • 6aa2373acd More x-related shell spawners Mark Stemm 2017-08-24 14:14:11 -07:00
  • b0cf038e1d Another uid to same uid case. Mark Stemm 2017-08-24 14:13:37 -07:00
  • 548790c663 Add more run by macros for h2o/Passenger Mark Stemm 2017-08-24 14:12:18 -07:00
  • 151d1e67c5 Add an additional scripting-running-command combo Mark Stemm 2017-08-24 14:11:01 -07:00
  • 68cca84ba6 Also let tini spawn shells in containers. Mark Stemm 2017-08-24 10:26:13 -07:00
  • 46f993fa40 Let fluentd write multiple files Mark Stemm 2017-08-24 10:25:34 -07:00
  • 42167e53cc Let chef write below etc. Mark Stemm 2017-08-24 10:23:31 -07:00
  • 4e7fcf3f88 Let java running sbt spawn shells Mark Stemm 2017-08-24 10:22:27 -07:00
  • 64a014c356 Look for qualys at various places in the heirarchy Mark Stemm 2017-08-24 10:09:12 -07:00
  • ac82dd4b54 Let timeout run shells. Mark Stemm 2017-08-24 10:08:29 -07:00
  • 70e49161b1 Let pkt-agent become themself. Mark Stemm 2017-08-24 08:59:33 -07:00
  • 1cdacc1494 Add macro to easily augment shell rule Mark Stemm 2017-08-24 08:58:09 -07:00
  • ca9e1ebfef Add x2go programs Mark Stemm 2017-08-24 08:57:26 -07:00
  • 6be38a3237 Add more nomachine binaries. Mark Stemm 2017-08-24 08:57:00 -07:00
  • bf1f2cb2fd Let coreos update_engine write below dev. Mark Stemm 2017-08-24 08:56:26 -07:00
  • ac70325522 Add more debugging for shells Mark Stemm 2017-08-23 16:50:58 -07:00
  • 608d4e234f Let tini spawn shells Mark Stemm 2017-08-23 16:50:32 -07:00
  • d21fb408d4 Let locales.postins write below /etc Mark Stemm 2017-08-23 16:46:10 -07:00
  • aaa294abd1 Add additional build-like shells Mark Stemm 2017-08-23 16:45:44 -07:00
  • 8e46db05c6 More specific control of some /etc files Mark Stemm 2017-08-23 16:37:38 -07:00
  • 4efda9cb97 Add nomachine binaries. Mark Stemm 2017-08-23 16:32:22 -07:00
  • 57c1b33562 Let /etc/locale.gen be written Mark Stemm 2017-08-23 16:31:40 -07:00
  • 75a44a67f9 Use pmatch instead of fd.directory Mark Stemm 2017-08-22 14:24:18 -07:00
  • fbfd540ad2 More user management exclusions. Mark Stemm 2017-08-22 14:18:32 -07:00
  • e88c9ec8e3 Add more shell spawners. Mark Stemm 2017-08-22 14:15:44 -07:00
  • 3202704950 Add more logging on process ancestors. Mark Stemm 2017-08-22 14:07:54 -07:00
  • 689c02666f Allow innocuous user management commands Mark Stemm 2017-08-22 14:05:21 -07:00
  • 12de2e4119 Make safe etc directories a list. Mark Stemm 2017-08-21 17:30:27 -07:00
  • cb7dab61e8 Let chef binaries run shells. Mark Stemm 2017-08-21 17:18:55 -07:00
  • 9791881444 Let mesos-slave, phusion passenger spawn shells Mark Stemm 2017-08-16 11:06:12 -07:00
  • 84b3543cc0 Let logrotate spawn shells in containers. Mark Stemm 2017-08-11 15:43:08 -07:00
  • 71fee6753b Let qualys write below /etc Mark Stemm 2017-08-11 15:42:44 -07:00
  • 7ff2f66437 Let node running npm spawn shells. Mark Stemm 2017-08-11 15:41:39 -07:00
  • 1f008d6c39 Let needrestart run shells. Mark Stemm 2017-08-11 15:40:31 -07:00
  • dc44655ec2 Change how we detect entrypoints. Mark Stemm 2017-08-09 10:12:03 -07:00
  • ef9e045a40 Add more ancestors Mark Stemm 2017-08-09 10:10:41 -07:00
  • 0ec46feef2 Make setuid binaries a list Mark Stemm 2017-08-09 10:09:33 -07:00
  • 2ebe9e06a8 More build-related changes + exposing more info Mark Stemm 2017-08-02 16:07:04 -07:00
  • 33974c6912 More server progs Mark Stemm 2017-08-01 18:02:23 -07:00
  • 9883656882 More shell/build related changes Mark Stemm 2017-07-28 16:16:58 -07:00
  • d5a107b15f More beta updates, almost all shell related: Mark Stemm 2017-07-27 17:01:36 -07:00
  • b208008be1 Fix parent_python_running_sdchecks Mark Stemm 2017-07-26 14:01:03 -07:00
  • 6397c3a556 Add additional command line. Mark Stemm 2017-07-21 12:17:45 -07:00
  • 1221399ac5 Allow writes below /etc/nginx/conf.d Mark Stemm 2017-07-14 09:14:16 -07:00
  • de3ca31b15 Allow certbot to spawn shells. Mark Stemm 2017-07-12 18:25:36 -07:00
  • 463ade2b1d Add 3dt as a meos program. Mark Stemm 2017-07-12 18:25:16 -07:00
  • 1c645862e1 Allow systemd-sysuser to write below /etc. Mark Stemm 2017-07-06 17:08:18 -07:00
  • f123313389 Let certbot write below etc. Mark Stemm 2017-07-05 16:26:02 -07:00
  • 1753d16962 Add easy way to add to container shell cmdlines Mark Stemm 2017-07-05 14:44:17 -07:00
  • 61f738826c Add additional command lines. Mark Stemm 2017-07-05 14:24:32 -07:00
  • 7ae765bfc9 Include container image in shell in container rule Mark Stemm 2017-07-05 14:23:10 -07:00
  • f6b3068259 Let vpn binaries write below /etc. Mark Stemm 2017-07-05 14:22:38 -07:00