diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..b2f0ff4 --- /dev/null +++ b/Dockerfile @@ -0,0 +1,67 @@ +FROM ubuntu:20.04 +#~The open Monosphere Project~ +#Version : 1.0 +#Autor : Siphonight :) + +#Defining variables and build settings +WORKDIR / +USER root +#Setting default settings, please change them at run +ENV PORT=22 +ENV BASTIONUSER="bastion" +ENV BASTIONPASS="bastion" +ENV HOSTNAME="monosphere-bastion" +ENV MONOSPHERE_VERSION="0.4.1 Alpha" + +#Preparations +#Updating +RUN apt update -y && apt upgrade -y +#Installing required dependencies +RUN apt install -y ssh gawk anacron auditd audispd-plugins rsyslog +#Creation and configuration of the Monosphere scripts directory +RUN mkdir /root/scripts + + +#Starting bastion configurations +#Configuring Failsafe SSH relauncher +ADD ssh-launcher.sh /root/scripts/ +#Configuring monosphere ssh banner +ADD monosphere_banner.txt /root/scripts/ +RUN echo "Monosphere version is $MONOSPHERE_VERSION" >> /root/scripts/monosphere_banner.txt +#Adding the entrypoint file to the configuration +ADD entrypoint.sh /root/scripts/ +#Adding the aditd configuration and rules files +ADD auditd.conf /etc/audit/auditd.conf +ADD ssh-monitor.rules /etc/audit/rules.d/ssh-monitor.rules +#Adding the server menu script files +#Preparing the custom scripts directory +RUN mkdir -p /opt/custom/scripts +ADD authorized_servers.txt /opt/public/servers/ +ADD server_menu.sh /opt/public/scripts/ +#Adding the server custom ssh configuration file +ADD sshd_config /root/scripts/ + +#Configuring anacrontab scheduler +RUN echo "#---Bastion configurations ! CHANGE AT YOUR OWN RISK !---" >> /etc/anacrontab +RUN echo "5 5 sshrelauncher bash /root/scripts/ssh-launcher.sh" >> /etc/anacrontab + +#Configuring SSHD daemon bastion +#Changing SSHD moduli +RUN awk '$5 >= 3071' /etc/ssh/moduli > /etc/ssh/moduli.tmp && mv /etc/ssh/moduli.tmp /etc/ssh/moduli +#Backuping the SSHD config file +RUN cp -r /etc/ssh/sshd_config /etc/ssh/sshd_config.backup +#Adding the config file of SSHD +RUN rm -rf /etc/ssh/sshd_config +RUN cp -r /root/scripts/sshd_config /etc/ssh/ +RUN chmod 644 /etc/ssh/sshd_config + +#Activating scripts +RUN chown -R root:root /root/scripts +RUN chmod 700 /root/scripts/*.sh + +#Port exposition +EXPOSE 22 + + +#Issuing start entrypoint +CMD ["/bin/bash", "/root/scripts/entrypoint.sh"] diff --git a/auditd.conf b/auditd.conf new file mode 100644 index 0000000..4b407ec --- /dev/null +++ b/auditd.conf @@ -0,0 +1,19 @@ +log_file = /var/log/audit/audit.log +log_format = RAW +log_group = root +priority_boost = 4 +flush = INCREMENTAL_ASYNC +freq = 50 +num_logs = 5 +dispatcher = /sbin/audispd +name_format = NONE +## Set the maximum file size and the action to take when the limit is reached +max_log_file = 30 +max_log_file_action = ROTATE +space_left = 75 +space_left_action = SYSLOG +action_mail_acct = root +admin_space_left = 50 +admin_space_left_action = SUSPEND +disk_full_action = SUSPEND +disk_error_action = SUSPEND diff --git a/authorized_servers.txt b/authorized_servers.txt new file mode 100644 index 0000000..60c0ccd --- /dev/null +++ b/authorized_servers.txt @@ -0,0 +1,2 @@ +172.17.0.1 test1 jpeg,george +172.17.0.2 test2 george diff --git a/entrypoint.sh b/entrypoint.sh new file mode 100644 index 0000000..1c6e5b4 --- /dev/null +++ b/entrypoint.sh @@ -0,0 +1,43 @@ +hostname ${HOSTNAME} +echo "Monosphere anacron scheduler is starting..." +service anacron start +echo "Monosphere anacron scheduler is successfully started" + +echo "Monosphere sshd service daemon is verifying its configuration..." +sshd -t +echo "Monosphere sshd service daemon configuration verified" + +echo "Monosphere rsyslog daemon is starting..." +service rsyslog start +echo "Monosphere rsyslog daemon is successfully started" + +echo "Monosphere auditd daemon is starting..." +service auditd start +echo "Monosphere auditd daemon is successfully started" + +echo "Monosphere sshd service daemon is starting..." +service ssh start +echo "Monosphere sshd service daemon is successfully started" + +echo "Monosphere is enabling custom scripts..." +chown -R root:root /opt/custom +chmod 700 /opt/custom/scripts/*.sh +bash /opt/custom/scripts/*.sh +echo "Monosphere custom scripts are successfully enabled" + +echo "Monosphere is configuring public directory..." +chown -R root:root /opt/public +chmod -R 755 /opt/public +echo "Monosphere public directory successfully configured" + +echo "Monosphere is creating the bastion user, I hope you changed the default user info..." +adduser --disabled-password --gecos "" ${BASTIONUSER} --shell /bin/bash #/usr/sbin/nologin +echo "${BASTIONUSER}:${BASTIONPASS}" | chpasswd +mkdir /home/${BASTIONUSER}/.ssh +chown ${BASTIONUSER}:${BASTIONUSER} /home/${BASTIONUSER}/.ssh +echo "Monosphere have created the bastion user" + +echo "Monosphere bastion is successfully started" + +# Keep the container running +tail -f /dev/null diff --git a/monosphere_banner.txt b/monosphere_banner.txt new file mode 100644 index 0000000..0c533be --- /dev/null +++ b/monosphere_banner.txt @@ -0,0 +1,11 @@ + +@@@@@@@@@@[Welcome to the Monosphere bastion]@@@@@@@@@@ +Authorized personnel only is allowed to come here. +If you're not authorized personnel, please disconnect +from this interface this instant. + +------------------------------------------------------- +Monosphere is logging the current connection. + +@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ + diff --git a/server_menu.sh b/server_menu.sh new file mode 100644 index 0000000..e5289bf --- /dev/null +++ b/server_menu.sh @@ -0,0 +1,33 @@ +#!/bin/bash + +AUTHORIZED_SERVERS_FILE="/opt/public/servers/authorized_servers.txt" +USER_SERVERS=$(grep -w "$(whoami)" $AUTHORIZED_SERVERS_FILE) + +if [ -z "$USER_SERVERS" ]; then + echo "Vous n'avez pas l'autorisation de vous connecter à un serveur." + exit 1 +fi + +echo "Veuillez sélectionner un serveur auquel vous connecter :" + +counter=1 +declare -A server_map +while read -r line; do + ip=$(echo "$line" | cut -d ' ' -f 1) + custom_name=$(echo "$line" | cut -d ' ' -f 2) + server_map[$counter]=$ip + echo "$counter) $custom_name - $ip" + counter=$((counter + 1)) +done <<< "$USER_SERVERS" + +read -r -p "Votre choix (1-${#server_map[@]}): " choice + +if [ -z "${server_map[$choice]}" ]; then + echo "Sélection invalide." + exit 1 +fi + +selected_server="${server_map[$choice]}" +echo "Connexion à $selected_server..." +ssh "$selected_server" + diff --git a/ssh-launcher.sh b/ssh-launcher.sh new file mode 100644 index 0000000..a6eed0d --- /dev/null +++ b/ssh-launcher.sh @@ -0,0 +1,20 @@ +#!/bin/bash + +# Vérifier si le service SSH est en cours d'exécution +ssh_pid=$(pgrep sshd) + +if [ ! -z "$ssh_pid" ]; then + echo "Le service SSH est en cours d'exécution." +else + echo "Le service SSH n'est pas en cours d'exécution. Tentative de démarrage..." + sudo service ssh start + + # Vérifier à nouveau si SSH est en cours d'exécution + ssh_pid=$(pgrep sshd) + if [ ! -z "$ssh_pid" ]; then + echo "Le service SSH a été démarré avec succès." + else + echo "Échec du démarrage du service SSH. Veuillez vérifier les logs pour plus de détails." + fi +fi + diff --git a/ssh-monitor.rules b/ssh-monitor.rules new file mode 100644 index 0000000..f999328 --- /dev/null +++ b/ssh-monitor.rules @@ -0,0 +1,21 @@ +# Monitor the use of SSH private keys +-w /etc/ssh/ssh_host_key -p rwa -k ssh_key +-w /etc/ssh/ssh_host_rsa_key -p rwa -k ssh_key +-w /etc/ssh/ssh_host_dsa_key -p rwa -k ssh_key +-w /etc/ssh/ssh_host_ecdsa_key -p rwa -k ssh_key +-w /etc/ssh/ssh_host_ed25519_key -p rwa -k ssh_key + +# Monitor SSH configuration files +-w /etc/ssh/ssh_config -p rwa -k ssh_config +-w /etc/ssh/sshd_config -p rwa -k ssh_config + +# Monitor the use of the ssh command +-a exit,always -F arch=b64 -S execve -F path=/usr/bin/ssh -k ssh_exec + +# Monitor session initiation, including timestamp and user information +-w /var/run/utmp -p wa -k session +-w /var/log/wtmp -p wa -k session +-w /var/log/btmp -p wa -k session + +# Monitor user commands +-a exit,always -F arch=b64 -S execve -F auid>=1000 -F auid!=4294967295 -k user_commands diff --git a/sshd_config b/sshd_config new file mode 100644 index 0000000..84395fc --- /dev/null +++ b/sshd_config @@ -0,0 +1,126 @@ +# $OpenBSD: sshd_config,v 1.103 2018/04/09 20:41:22 tj Exp $ + +# This is the sshd server system-wide configuration file. See +# sshd_config(5) for more information. + +# This sshd was compiled with PATH=/usr/bin:/bin:/usr/sbin:/sbin + +# The strategy used for options in the default sshd_config shipped with +# OpenSSH is to specify options with their default value where +# possible, but leave them commented. Uncommented options override the +# default value. + +Include /etc/ssh/sshd_config.d/*.conf + +Port 22 +#AddressFamily any +#ListenAddress 0.0.0.0 +#ListenAddress :: + +HostKey /etc/ssh/ssh_host_ed25519_key +HostKey /etc/ssh/ssh_host_ecdsa_key +HostKey /etc/ssh/ssh_host_rsa_key + +# Ciphers and keying +#RekeyLimit default none + +# Logging +#SyslogFacility AUTH +LogLevel VERBOSE + +# Authentication: + +#LoginGraceTime 2m +PermitRootLogin no +#StrictModes yes +MaxAuthTries 6 +#MaxSessions 10 + +#PubkeyAuthentication yes + +# Expect .ssh/authorized_keys2 to be disregarded by default in future. +#AuthorizedKeysFile .ssh/authorized_keys .ssh/authorized_keys2 + +#AuthorizedPrincipalsFile none + +#AuthorizedKeysCommand none +#AuthorizedKeysCommandUser nobody + +# For this to work you will also need host keys in /etc/ssh/ssh_known_hosts +#HostbasedAuthentication no +# Change to yes if you don't trust ~/.ssh/known_hosts for +# HostbasedAuthentication +#IgnoreUserKnownHosts no +# Don't read the user's ~/.rhosts and ~/.shosts files +#IgnoreRhosts yes + +# To disable tunneled clear text passwords, change to no here! +PasswordAuthentication yes +#PermitEmptyPasswords no + +# Change to yes to enable challenge-response passwords (beware issues with +# some PAM modules and threads) +ChallengeResponseAuthentication no + +# Kerberos options +#KerberosAuthentication no +#KerberosOrLocalPasswd yes +#KerberosTicketCleanup yes +#KerberosGetAFSToken no + +# GSSAPI options +#GSSAPIAuthentication no +#GSSAPICleanupCredentials yes +#GSSAPIStrictAcceptorCheck yes +#GSSAPIKeyExchange no + +# Set this to 'yes' to enable PAM authentication, account processing, +# and session processing. If this is enabled, PAM authentication will +# be allowed through the ChallengeResponseAuthentication and +# PasswordAuthentication. Depending on your PAM configuration, +# PAM authentication via ChallengeResponseAuthentication may bypass +# the setting of "PermitRootLogin without-password". +# If you just want the PAM account and session checks to run without +# PAM authentication, then enable this but set PasswordAuthentication +# and ChallengeResponseAuthentication to 'no'. +UsePAM yes + +AllowAgentForwarding no +#AllowTcpForwarding yes +#GatewayPorts no +X11Forwarding no +#X11DisplayOffset 10 +#X11UseLocalhost yes +PermitTTY yes +PrintMotd no +#PrintLastLog yes +#TCPKeepAlive yes +#PermitUserEnvironment no +#Compression delayed +#ClientAliveInterval 0 +#ClientAliveCountMax 3 +#UseDNS no +#PidFile /var/run/sshd.pid +#MaxStartups 10:30:100 +#PermitTunnel no +#ChrootDirectory none +#VersionAddendum none + +# no default banner path +Banner /root/scripts/monosphere_banner.txt + +# Allow client to pass locale environment variables +AcceptEnv LANG LC_* + +# override default of no subsystems +Subsystem sftp /usr/lib/ssh/sftp-server -f AUTHPRIV -l INFO + +#---Bastion configurations ! CHANGE AT YOUR OWN RISK !--- +KexAlgorithms curve25519-sha256@libssh.org,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256 +Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr +MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,umac-128@openssh.com +PubkeyAcceptedKeyTypes sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com +AllowStreamLocalForwarding no +Match User *,!ubuntu + ForceCommand /opt/public/scripts/server_menu.sh + X11Forwarding no