Last active
October 29, 2020 07:28
-
-
Save kotakanbe/5e7ff3ca54bb8232d6cf1a75af18262d to your computer and use it in GitHub Desktop.
Revisions
-
kotakanbe revised this gist
Sep 1, 2020 . No changes.There are no files selected for viewing
-
kotakanbe revised this gist
Sep 1, 2020 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -184,7 +184,7 @@ host centos7.6.1810 359 installed, 63 updatable 今回はCentOSをスキャンしたので`--redhat`をつけて実行します。Ubuntuなどほかのディストリビューションの場合は対応するオプションを付けてフェッチしてください。オプションの詳細は下記ページを参考にして下さい。 - [vulsctl/docker/oval.sh](https://github.com/vulsio/vulsctl/blob/master/docker/oval.sh) - [kotakanbe/goval-dictionary](https://github.com/kotakanbe/goval-dictionary) ```bash -
kotakanbe revised this gist
Sep 1, 2020 . No changes.There are no files selected for viewing
-
kotakanbe revised this gist
Sep 1, 2020 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -333,7 +333,7 @@ $ ./tui.sh もし他のLinuxディストリビューションをスキャンする場合は、同じように対応するOVALを事前に準備して下さい。詳細はドキュメントを参考にして下さい。 - [vulsctl/oval.sh](https://github.com/vulsio/vulsctl/blob/master/docker/oal.sh) - [kotakanbe/goval-dictionary](https://github.com/kotakanbe/goval-dictionary) --- -
kotakanbe revised this gist
Sep 1, 2020 . 1 changed file with 2 additions and 2 deletions.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -333,7 +333,7 @@ $ ./tui.sh もし他のLinuxディストリビューションをスキャンする場合は、同じように対応するOVALを事前に準備して下さい。詳細はドキュメントを参考にして下さい。 - [vulsctl/oval.sh](https://github.com/vulsio/vulsctl/blob/master/doccker/oal.sh) - [kotakanbe/goval-dictionary](https://github.com/kotakanbe/goval-dictionary) --- @@ -602,7 +602,7 @@ Gemやpipなどのプログラミング言語のパッケージマネージャ - yarn.lock - Cargo.lock では試しにGitHubにあった[古いRedmineのGemfile.lock](https://github.com/41studio/redmine/blob/master/Gemfile.lock)をスキャンしてみましょう。 まずスキャン対象サーバ上でwgetで古いGemfile.lockを取得します。 -
kotakanbe revised this gist
Sep 1, 2020 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -602,7 +602,7 @@ Gemやpipなどのプログラミング言語のパッケージマネージャ - yarn.lock - Cargo.lock では試しにGitHubにあった[古いRedmineのGemfile.lock](https://github.com/41studio/redmine/blob/master/docker/Gemfile.lock)をスキャンしてみましょう。 まずスキャン対象サーバ上でwgetで古いGemfile.lockを取得します。 -
kotakanbe revised this gist
Sep 1, 2020 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -333,7 +333,7 @@ $ ./tui.sh もし他のLinuxディストリビューションをスキャンする場合は、同じように対応するOVALを事前に準備して下さい。詳細はドキュメントを参考にして下さい。 - [vulsctl/oval.sh](https://github.com/vulsio/vulsctl/blob/master/docker/oval.sh) - [kotakanbe/goval-dictionary](https://github.com/kotakanbe/goval-dictionary) --- -
kotakanbe revised this gist
Sep 1, 2020 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -272,7 +272,7 @@ Total: 111 (High:57 Medium:39 Low:15 ?:0), 35/111 Fixed, 359 installed, 63 updat Vulsにはターミナル上で結果を確認可能なTerminalベースのビューアが付属しています。こちらで結果を確認してみましょう。 [vulsctl/tui.sh](https://github.com/vulsio/vulsctl/blob/master/docker/tui.sh)を使ってコンソール上で結果を確認します。 Tabでペインを移動し、矢印やjkで移動します。Ctrl-Cで終了します。 詳細は[ドキュメント](https://vuls.io/docs/en/usage-tui.html)を参照ください。 -
kotakanbe revised this gist
Sep 1, 2020 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -216,7 +216,7 @@ $ ls -alh oval.sqlite3 さて脆弱性DBの準備が整いましたので、レポートを実行します。 [vulsctl/report.sh](https://github.com/vulsio/vulsctl/blob/master/docker/report.sh)を使って結果を表示します。 scan.shで作成されたJSONの情報と、先程取得したRed Hatが提供するOVALを用いてスキャン対象サーバに潜在するCVE-IDを特定します。 詳細は[ドキュメント](https://vuls.io/docs/en/usage-report.html)を参照ください。 -
kotakanbe revised this gist
Sep 1, 2020 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -184,7 +184,7 @@ host centos7.6.1810 359 installed, 63 updatable 今回はCentOSをスキャンしたので`--redhat`をつけて実行します。Ubuntuなどほかのディストリビューションの場合は対応するオプションを付けてフェッチしてください。オプションの詳細は下記ページを参考にして下さい。 - [vulsctl/oval.sh](https://github.com/vulsio/vulsctl/blob/master/docker/oval.sh) - [kotakanbe/goval-dictionary](https://github.com/kotakanbe/goval-dictionary) ```bash -
kotakanbe revised this gist
Sep 1, 2020 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -131,7 +131,7 @@ keyPathはHostOS内のパスではなく、Dockerコンテナ内のパスを指 それでは、先程用意した設定ファイルを用いて実際にスキャンしてみましょう。 [vulsctl/scan.sh](https://github.com/vulsio/vulsctl/blob/master/docker/scan.sh)はconfig.tomlで設定された情報を元に実際にスキャンするスクリプトです。 スキャン結果はJSON形式で`$PWD/results`以下に保存され、report時に利用されます。 スキャン対象サーバはコマンドライン引数で指定可能です。今回は`host`を指定しているため、config.tomlに定義された[servers.host]をスキャンします。 Vulsはconfig.tomlに定義されたSSH接続情報を用いて、スキャン対象サーバに実際にSSHで接続し、スキャン対象サーバ上でコマンドを発行します。 スキャンのモードはいくつかありますが、今回はconfig.tomlで何も指定していないためデフォルトの[fastスキャンモード](https://vuls.io/docs/en/architecture-fast-scan.html)でスキャンされます。 -
kotakanbe revised this gist
Sep 1, 2020 . No changes.There are no files selected for viewing
-
kotakanbe revised this gist
Aug 31, 2020 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -1,7 +1,7 @@ # Vulsチュートリアル [Vuls](https://github.com/future-architect/vuls)は、Linux / FreeBSD, Container, WordPress, アプリケーション依存ライブラリ、Network機器、ミドルウェアの既知の脆弱性を検知するツールです。 このチュートリアルは、Vulsの簡単セットアップツールである、[Vulsctl](https://github.com/vulsio/vulsctl)を用いて -
kotakanbe revised this gist
Aug 31, 2020 . 1 changed file with 4 additions and 16 deletions.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -693,22 +693,10 @@ $ ./update-all.sh --- ## Misc - [WordPress](https://vuls.io/docs/ja/usage-scan-wordpress.html#scan-wordpress-core-plugin-theme) - [Slack Notification](https://vuls.io/docs/ja/usage-settings.html#slack-section) - [Scan running containers](https://vuls.io/docs/ja/usage-scan.html#example-scan-running-containers-docker-lxd-lxc) -
kotakanbe revised this gist
Aug 31, 2020 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -672,7 +672,7 @@ $ ./tui.sh [vuls.io/usage-report](https://vuls.io/docs/en/usage-report.html) |オプション|説明| |:-|:-| | -debug | デバッグ用フラグ。発行しているコマンドがわかる | | -cvss-over | CVSSスコアでフィルタ| | -ignore-unfixed | パッチがまだない脆弱性は非表示 | -
kotakanbe revised this gist
Aug 31, 2020 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -672,7 +672,7 @@ $ ./tui.sh [vuls.io/usage-report](https://vuls.io/docs/en/usage-report.html) |オプション|説明| |-|:-| | -debug | デバッグ用フラグ。発行しているコマンドがわかる | | -cvss-over | CVSSスコアでフィルタ| | -ignore-unfixed | パッチがまだない脆弱性は非表示 | -
kotakanbe revised this gist
Aug 31, 2020 . 1 changed file with 2 additions and 2 deletions.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -671,8 +671,8 @@ $ ./tui.sh [vuls.io/usage-report](https://vuls.io/docs/en/usage-report.html) |オプション|説明| |-|-| | -debug | デバッグ用フラグ。発行しているコマンドがわかる | | -cvss-over | CVSSスコアでフィルタ| | -ignore-unfixed | パッチがまだない脆弱性は非表示 | -
kotakanbe revised this gist
Aug 31, 2020 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -588,7 +588,7 @@ Vulsはアプリケーションの依存ライブラリのスキャンに対応 ## アプリケーションのライブラリ脆弱性の検知(lock file指定) Gemやpipなどのプログラミング言語のパッケージマネージャのバージョン固定用ロックファイルを解析し、そこに定義されている依存ライブラリに潜在する脆弱性を検知可能です。(内部で[aquasecurity/trivy](https://github.com/aquasecurity/trivy)を呼んでいます) [ドキュメント](https://vuls.io/docs/en/usage-scan-non-os-packages.html#library-vulns-scan)はこちらです。 -
kotakanbe revised this gist
Aug 31, 2020 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -588,7 +588,7 @@ Vulsはアプリケーションの依存ライブラリのスキャンに対応 ## アプリケーションのライブラリ脆弱性の検知(lock file指定) Gemやpipなどのプログラミング言語のパッケージマネージャのバージョン固定用ロックファイルを解析し、そこに定義されている依存ライブラリに潜在する脆弱性を検知可能です。(内部で[knqyf263/trivy](https://github.com/aquasecurity/trivy)を呼んでいます) [ドキュメント](https://vuls.io/docs/en/usage-scan-non-os-packages.html#library-vulns-scan)はこちらです。 -
kotakanbe revised this gist
Aug 31, 2020 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -578,7 +578,7 @@ Vulsはアプリケーションの依存ライブラリのスキャンに対応 - [LockFile Scan](https://vuls.io/docs/en/usage-scan-non-os-packages.html#library-vulns-scan) - [GitHub Integration](https://vuls.io/docs/en/usage-scan-non-os-packages.html#usage-integrate-with-github-security-alerts) - [OWASP Dependency check](https://vuls.io/docs/en/usage-scan-non-os-packages.html#usage-integrate-with-owasp-dependency-check-to-automatic-update-when-the-libraries-are-updated-experimental) 詳細は[Document](https://vuls.io/docs/en/usage-scan-non-os-packages.html)を参照してください。 -
kotakanbe revised this gist
Aug 31, 2020 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -577,7 +577,7 @@ Vulsはアプリケーションの依存ライブラリのスキャンに対応 複数の方法があり、それぞれ向き不向きがあるので実際に試してみるのがよいでしょう。 - [LockFile Scan](https://vuls.io/docs/en/usage-scan-non-os-packages.html#library-vulns-scan) - [GitHub Integration](https://vuls.io/docs/en/usage-scan-non-os-packages.html#usage-integrate-with-github-security-alerts) - OWASP Dependency check 詳細は[Document](https://vuls.io/docs/en/usage-scan-non-os-packages.html)を参照してください。 -
kotakanbe revised this gist
Aug 31, 2020 . No changes.There are no files selected for viewing
-
kotakanbe revised this gist
Aug 31, 2020 . 1 changed file with 2 additions and 2 deletions.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -576,8 +576,8 @@ Vulsはアプリケーションの依存ライブラリのスキャンに対応 複数の方法があり、それぞれ向き不向きがあるので実際に試してみるのがよいでしょう。 - [LockFile Scan](https://vuls.io/docs/en/usage-scan-non-os-packages.html#library-vulns-scan) - [GitHub Integration - OWASP Dependency check 詳細は[Document](https://vuls.io/docs/en/usage-scan-non-os-packages.html)を参照してください。 -
kotakanbe revised this gist
Aug 31, 2020 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -576,7 +576,7 @@ Vulsはアプリケーションの依存ライブラリのスキャンに対応 複数の方法があり、それぞれ向き不向きがあるので実際に試してみるのがよいでしょう。 - [Lockファイルスキャン](https://vuls.io/docs/en/usage-scan-non-os-packages.html#library-vulns-scan) - GitHub Integration - OWASP Dependency check -
kotakanbe revised this gist
Aug 31, 2020 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -61,7 +61,7 @@ $ cd vulsctl $ git pull ``` これ以降の操作は**vulsctl/dockerディレクトリ内で作業します** ```bash $ cd docker -
kotakanbe revised this gist
Aug 31, 2020 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -54,7 +54,7 @@ remote: Total 14 (delta 4), reused 12 (delta 2), pack-reused 0 Unpacking objects: 100% (14/14), done. ``` 以前vulsctlをセットアップ済みの環境の場合は最新化して下さい。 ```bash $ cd vulsctl -
kotakanbe revised this gist
Aug 31, 2020 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -31,7 +31,7 @@ Vulsセットアップ用のLinuxマシンを一台準備して下さい。 今回はCentOS 7を例に説明します。 SSHで接続してgitをインストールします。 ```bash $ sudo yum install git -
kotakanbe revised this gist
Aug 31, 2020 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -10,7 +10,7 @@ - アプリケーション依存ライブラリ脆弱性スキャン - ネットワーク機器OSのCPEスキャン を解説します。 VulsはDockerHub上にDockerイメージを提供しており、その公式イメージを使ったチュートリアルとなります。Docker Hub公式レポジトリは[こちら](https://hub.docker.com/orgs/vuls/repositories)。 -
kotakanbe revised this gist
Aug 31, 2020 . No changes.There are no files selected for viewing
-
kotakanbe revised this gist
Aug 31, 2020 . 1 changed file with 1 addition and 1 deletion.There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode charactersOriginal file line number Diff line number Diff line change @@ -3,7 +3,7 @@ [Vuls](https://github.com/future-architect/vuls)は、Linux / FreeBSD, Container, WordPress, アプリケーション依存ライブラリ、Network機器、ミドルウェアの既知の脆弱性を検知するツールである。 このチュートリアルは、Vulsの簡単セットアップツールである、[Vulsctl](https://github.com/vulsio/vulsctl)を用いて - HostOS(CentOS)の脆弱性をリモートスキャン - SSHでUbuntuをリモートスキャン
NewerOlder