Lynis is an auditing tool for Unix (specialists). It scans the system and available software, to detect security issues. Beside security related information it will also scan for general system information, installed packages and configuration mistakes.
This is a tool that might be useful for both penetration testers performing white box tests and system admins trying to secure their own systems.
This software aims in assisting automated auditing, software patch management, vulnerability and malware scanning of Unix based systems. It can be run without prior installation, so inclusion on read only storage is no problem (USB stick, CD/DVD).
What is Lynis NOT:
- Not a hardening tool: Lynis does not fix things automatically, it only reports (and makes suggestions).
Security specialists, penetration testers, system auditors, system/network managers.
Examples of audit tests:
- Available authentication methods
- Expired SSL certificates
- Outdated software
- User accounts without password
- Incorrect file permissions
- Firewall auditing
You can download Lynis 1.1.7 here:
Or you can read more here.
Recent in Countermeasures:
- Noted Chinese Hacker Wicked Rose Heading Antivirus Company Anvisoft
- HoneyDrive – Honeypots In A Box
- Microsoft Patches Critical Security Vulnerabilities In Windows, Office, IE, Exchange & SQL Server
- Lynis 1.2.6 Released – UNIX System & Security Auditing Tool
- SpikeSource Spike PHP Security Audit Tool
- Babel Enterprise – Cross Platform System Auditing Tool
Most Read in Countermeasures:
- AJAX: Is your application secure enough? - 117,834 views
- Password Hasher Firefox Extension - 115,941 views
- NDR or Backscatter Spam – How Non Delivery Reports Become a Nuisance - 57,461 views