Add files via upload

This commit is contained in:
Ostantia 2023-04-09 23:26:43 +02:00 committed by GitHub
parent 46036b305a
commit 33a1a28459
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
9 changed files with 342 additions and 0 deletions

67
Dockerfile Normal file
View File

@ -0,0 +1,67 @@
FROM ubuntu:20.04
#~The open Monosphere Project~
#Version : 1.0
#Autor : Siphonight :)
#Defining variables and build settings
WORKDIR /
USER root
#Setting default settings, please change them at run
ENV PORT=22
ENV BASTIONUSER="bastion"
ENV BASTIONPASS="bastion"
ENV HOSTNAME="monosphere-bastion"
ENV MONOSPHERE_VERSION="0.4.1 Alpha"
#Preparations
#Updating
RUN apt update -y && apt upgrade -y
#Installing required dependencies
RUN apt install -y ssh gawk anacron auditd audispd-plugins rsyslog
#Creation and configuration of the Monosphere scripts directory
RUN mkdir /root/scripts
#Starting bastion configurations
#Configuring Failsafe SSH relauncher
ADD ssh-launcher.sh /root/scripts/
#Configuring monosphere ssh banner
ADD monosphere_banner.txt /root/scripts/
RUN echo "Monosphere version is $MONOSPHERE_VERSION" >> /root/scripts/monosphere_banner.txt
#Adding the entrypoint file to the configuration
ADD entrypoint.sh /root/scripts/
#Adding the aditd configuration and rules files
ADD auditd.conf /etc/audit/auditd.conf
ADD ssh-monitor.rules /etc/audit/rules.d/ssh-monitor.rules
#Adding the server menu script files
#Preparing the custom scripts directory
RUN mkdir -p /opt/custom/scripts
ADD authorized_servers.txt /opt/public/servers/
ADD server_menu.sh /opt/public/scripts/
#Adding the server custom ssh configuration file
ADD sshd_config /root/scripts/
#Configuring anacrontab scheduler
RUN echo "#---Bastion configurations ! CHANGE AT YOUR OWN RISK !---" >> /etc/anacrontab
RUN echo "5 5 sshrelauncher bash /root/scripts/ssh-launcher.sh" >> /etc/anacrontab
#Configuring SSHD daemon bastion
#Changing SSHD moduli
RUN awk '$5 >= 3071' /etc/ssh/moduli > /etc/ssh/moduli.tmp && mv /etc/ssh/moduli.tmp /etc/ssh/moduli
#Backuping the SSHD config file
RUN cp -r /etc/ssh/sshd_config /etc/ssh/sshd_config.backup
#Adding the config file of SSHD
RUN rm -rf /etc/ssh/sshd_config
RUN cp -r /root/scripts/sshd_config /etc/ssh/
RUN chmod 644 /etc/ssh/sshd_config
#Activating scripts
RUN chown -R root:root /root/scripts
RUN chmod 700 /root/scripts/*.sh
#Port exposition
EXPOSE 22
#Issuing start entrypoint
CMD ["/bin/bash", "/root/scripts/entrypoint.sh"]

19
auditd.conf Normal file
View File

@ -0,0 +1,19 @@
log_file = /var/log/audit/audit.log
log_format = RAW
log_group = root
priority_boost = 4
flush = INCREMENTAL_ASYNC
freq = 50
num_logs = 5
dispatcher = /sbin/audispd
name_format = NONE
## Set the maximum file size and the action to take when the limit is reached
max_log_file = 30
max_log_file_action = ROTATE
space_left = 75
space_left_action = SYSLOG
action_mail_acct = root
admin_space_left = 50
admin_space_left_action = SUSPEND
disk_full_action = SUSPEND
disk_error_action = SUSPEND

2
authorized_servers.txt Normal file
View File

@ -0,0 +1,2 @@
172.17.0.1 test1 jpeg,george
172.17.0.2 test2 george

43
entrypoint.sh Normal file
View File

@ -0,0 +1,43 @@
hostname ${HOSTNAME}
echo "Monosphere anacron scheduler is starting..."
service anacron start
echo "Monosphere anacron scheduler is successfully started"
echo "Monosphere sshd service daemon is verifying its configuration..."
sshd -t
echo "Monosphere sshd service daemon configuration verified"
echo "Monosphere rsyslog daemon is starting..."
service rsyslog start
echo "Monosphere rsyslog daemon is successfully started"
echo "Monosphere auditd daemon is starting..."
service auditd start
echo "Monosphere auditd daemon is successfully started"
echo "Monosphere sshd service daemon is starting..."
service ssh start
echo "Monosphere sshd service daemon is successfully started"
echo "Monosphere is enabling custom scripts..."
chown -R root:root /opt/custom
chmod 700 /opt/custom/scripts/*.sh
bash /opt/custom/scripts/*.sh
echo "Monosphere custom scripts are successfully enabled"
echo "Monosphere is configuring public directory..."
chown -R root:root /opt/public
chmod -R 755 /opt/public
echo "Monosphere public directory successfully configured"
echo "Monosphere is creating the bastion user, I hope you changed the default user info..."
adduser --disabled-password --gecos "" ${BASTIONUSER} --shell /bin/bash #/usr/sbin/nologin
echo "${BASTIONUSER}:${BASTIONPASS}" | chpasswd
mkdir /home/${BASTIONUSER}/.ssh
chown ${BASTIONUSER}:${BASTIONUSER} /home/${BASTIONUSER}/.ssh
echo "Monosphere have created the bastion user"
echo "Monosphere bastion is successfully started"
# Keep the container running
tail -f /dev/null

11
monosphere_banner.txt Normal file
View File

@ -0,0 +1,11 @@
@@@@@@@@@@[Welcome to the Monosphere bastion]@@@@@@@@@@
Authorized personnel only is allowed to come here.
If you're not authorized personnel, please disconnect
from this interface this instant.
-------------------------------------------------------
Monosphere is logging the current connection.
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@

33
server_menu.sh Normal file
View File

@ -0,0 +1,33 @@
#!/bin/bash
AUTHORIZED_SERVERS_FILE="/opt/public/servers/authorized_servers.txt"
USER_SERVERS=$(grep -w "$(whoami)" $AUTHORIZED_SERVERS_FILE)
if [ -z "$USER_SERVERS" ]; then
echo "Vous n'avez pas l'autorisation de vous connecter à un serveur."
exit 1
fi
echo "Veuillez sélectionner un serveur auquel vous connecter :"
counter=1
declare -A server_map
while read -r line; do
ip=$(echo "$line" | cut -d ' ' -f 1)
custom_name=$(echo "$line" | cut -d ' ' -f 2)
server_map[$counter]=$ip
echo "$counter) $custom_name - $ip"
counter=$((counter + 1))
done <<< "$USER_SERVERS"
read -r -p "Votre choix (1-${#server_map[@]}): " choice
if [ -z "${server_map[$choice]}" ]; then
echo "Sélection invalide."
exit 1
fi
selected_server="${server_map[$choice]}"
echo "Connexion à $selected_server..."
ssh "$selected_server"

20
ssh-launcher.sh Normal file
View File

@ -0,0 +1,20 @@
#!/bin/bash
# Vérifier si le service SSH est en cours d'exécution
ssh_pid=$(pgrep sshd)
if [ ! -z "$ssh_pid" ]; then
echo "Le service SSH est en cours d'exécution."
else
echo "Le service SSH n'est pas en cours d'exécution. Tentative de démarrage..."
sudo service ssh start
# Vérifier à nouveau si SSH est en cours d'exécution
ssh_pid=$(pgrep sshd)
if [ ! -z "$ssh_pid" ]; then
echo "Le service SSH a été démarré avec succès."
else
echo "Échec du démarrage du service SSH. Veuillez vérifier les logs pour plus de détails."
fi
fi

21
ssh-monitor.rules Normal file
View File

@ -0,0 +1,21 @@
# Monitor the use of SSH private keys
-w /etc/ssh/ssh_host_key -p rwa -k ssh_key
-w /etc/ssh/ssh_host_rsa_key -p rwa -k ssh_key
-w /etc/ssh/ssh_host_dsa_key -p rwa -k ssh_key
-w /etc/ssh/ssh_host_ecdsa_key -p rwa -k ssh_key
-w /etc/ssh/ssh_host_ed25519_key -p rwa -k ssh_key
# Monitor SSH configuration files
-w /etc/ssh/ssh_config -p rwa -k ssh_config
-w /etc/ssh/sshd_config -p rwa -k ssh_config
# Monitor the use of the ssh command
-a exit,always -F arch=b64 -S execve -F path=/usr/bin/ssh -k ssh_exec
# Monitor session initiation, including timestamp and user information
-w /var/run/utmp -p wa -k session
-w /var/log/wtmp -p wa -k session
-w /var/log/btmp -p wa -k session
# Monitor user commands
-a exit,always -F arch=b64 -S execve -F auid>=1000 -F auid!=4294967295 -k user_commands

126
sshd_config Normal file
View File

@ -0,0 +1,126 @@
# $OpenBSD: sshd_config,v 1.103 2018/04/09 20:41:22 tj Exp $
# This is the sshd server system-wide configuration file. See
# sshd_config(5) for more information.
# This sshd was compiled with PATH=/usr/bin:/bin:/usr/sbin:/sbin
# The strategy used for options in the default sshd_config shipped with
# OpenSSH is to specify options with their default value where
# possible, but leave them commented. Uncommented options override the
# default value.
Include /etc/ssh/sshd_config.d/*.conf
Port 22
#AddressFamily any
#ListenAddress 0.0.0.0
#ListenAddress ::
HostKey /etc/ssh/ssh_host_ed25519_key
HostKey /etc/ssh/ssh_host_ecdsa_key
HostKey /etc/ssh/ssh_host_rsa_key
# Ciphers and keying
#RekeyLimit default none
# Logging
#SyslogFacility AUTH
LogLevel VERBOSE
# Authentication:
#LoginGraceTime 2m
PermitRootLogin no
#StrictModes yes
MaxAuthTries 6
#MaxSessions 10
#PubkeyAuthentication yes
# Expect .ssh/authorized_keys2 to be disregarded by default in future.
#AuthorizedKeysFile .ssh/authorized_keys .ssh/authorized_keys2
#AuthorizedPrincipalsFile none
#AuthorizedKeysCommand none
#AuthorizedKeysCommandUser nobody
# For this to work you will also need host keys in /etc/ssh/ssh_known_hosts
#HostbasedAuthentication no
# Change to yes if you don't trust ~/.ssh/known_hosts for
# HostbasedAuthentication
#IgnoreUserKnownHosts no
# Don't read the user's ~/.rhosts and ~/.shosts files
#IgnoreRhosts yes
# To disable tunneled clear text passwords, change to no here!
PasswordAuthentication yes
#PermitEmptyPasswords no
# Change to yes to enable challenge-response passwords (beware issues with
# some PAM modules and threads)
ChallengeResponseAuthentication no
# Kerberos options
#KerberosAuthentication no
#KerberosOrLocalPasswd yes
#KerberosTicketCleanup yes
#KerberosGetAFSToken no
# GSSAPI options
#GSSAPIAuthentication no
#GSSAPICleanupCredentials yes
#GSSAPIStrictAcceptorCheck yes
#GSSAPIKeyExchange no
# Set this to 'yes' to enable PAM authentication, account processing,
# and session processing. If this is enabled, PAM authentication will
# be allowed through the ChallengeResponseAuthentication and
# PasswordAuthentication. Depending on your PAM configuration,
# PAM authentication via ChallengeResponseAuthentication may bypass
# the setting of "PermitRootLogin without-password".
# If you just want the PAM account and session checks to run without
# PAM authentication, then enable this but set PasswordAuthentication
# and ChallengeResponseAuthentication to 'no'.
UsePAM yes
AllowAgentForwarding no
#AllowTcpForwarding yes
#GatewayPorts no
X11Forwarding no
#X11DisplayOffset 10
#X11UseLocalhost yes
PermitTTY yes
PrintMotd no
#PrintLastLog yes
#TCPKeepAlive yes
#PermitUserEnvironment no
#Compression delayed
#ClientAliveInterval 0
#ClientAliveCountMax 3
#UseDNS no
#PidFile /var/run/sshd.pid
#MaxStartups 10:30:100
#PermitTunnel no
#ChrootDirectory none
#VersionAddendum none
# no default banner path
Banner /root/scripts/monosphere_banner.txt
# Allow client to pass locale environment variables
AcceptEnv LANG LC_*
# override default of no subsystems
Subsystem sftp /usr/lib/ssh/sftp-server -f AUTHPRIV -l INFO
#---Bastion configurations ! CHANGE AT YOUR OWN RISK !---
KexAlgorithms curve25519-sha256@libssh.org,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256
Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr
MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,umac-128@openssh.com
PubkeyAcceptedKeyTypes sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com
AllowStreamLocalForwarding no
Match User *,!ubuntu
ForceCommand /opt/public/scripts/server_menu.sh
X11Forwarding no