Add files via upload
This commit is contained in:
parent
46036b305a
commit
33a1a28459
67
Dockerfile
Normal file
67
Dockerfile
Normal file
@ -0,0 +1,67 @@
|
||||
FROM ubuntu:20.04
|
||||
#~The open Monosphere Project~
|
||||
#Version : 1.0
|
||||
#Autor : Siphonight :)
|
||||
|
||||
#Defining variables and build settings
|
||||
WORKDIR /
|
||||
USER root
|
||||
#Setting default settings, please change them at run
|
||||
ENV PORT=22
|
||||
ENV BASTIONUSER="bastion"
|
||||
ENV BASTIONPASS="bastion"
|
||||
ENV HOSTNAME="monosphere-bastion"
|
||||
ENV MONOSPHERE_VERSION="0.4.1 Alpha"
|
||||
|
||||
#Preparations
|
||||
#Updating
|
||||
RUN apt update -y && apt upgrade -y
|
||||
#Installing required dependencies
|
||||
RUN apt install -y ssh gawk anacron auditd audispd-plugins rsyslog
|
||||
#Creation and configuration of the Monosphere scripts directory
|
||||
RUN mkdir /root/scripts
|
||||
|
||||
|
||||
#Starting bastion configurations
|
||||
#Configuring Failsafe SSH relauncher
|
||||
ADD ssh-launcher.sh /root/scripts/
|
||||
#Configuring monosphere ssh banner
|
||||
ADD monosphere_banner.txt /root/scripts/
|
||||
RUN echo "Monosphere version is $MONOSPHERE_VERSION" >> /root/scripts/monosphere_banner.txt
|
||||
#Adding the entrypoint file to the configuration
|
||||
ADD entrypoint.sh /root/scripts/
|
||||
#Adding the aditd configuration and rules files
|
||||
ADD auditd.conf /etc/audit/auditd.conf
|
||||
ADD ssh-monitor.rules /etc/audit/rules.d/ssh-monitor.rules
|
||||
#Adding the server menu script files
|
||||
#Preparing the custom scripts directory
|
||||
RUN mkdir -p /opt/custom/scripts
|
||||
ADD authorized_servers.txt /opt/public/servers/
|
||||
ADD server_menu.sh /opt/public/scripts/
|
||||
#Adding the server custom ssh configuration file
|
||||
ADD sshd_config /root/scripts/
|
||||
|
||||
#Configuring anacrontab scheduler
|
||||
RUN echo "#---Bastion configurations ! CHANGE AT YOUR OWN RISK !---" >> /etc/anacrontab
|
||||
RUN echo "5 5 sshrelauncher bash /root/scripts/ssh-launcher.sh" >> /etc/anacrontab
|
||||
|
||||
#Configuring SSHD daemon bastion
|
||||
#Changing SSHD moduli
|
||||
RUN awk '$5 >= 3071' /etc/ssh/moduli > /etc/ssh/moduli.tmp && mv /etc/ssh/moduli.tmp /etc/ssh/moduli
|
||||
#Backuping the SSHD config file
|
||||
RUN cp -r /etc/ssh/sshd_config /etc/ssh/sshd_config.backup
|
||||
#Adding the config file of SSHD
|
||||
RUN rm -rf /etc/ssh/sshd_config
|
||||
RUN cp -r /root/scripts/sshd_config /etc/ssh/
|
||||
RUN chmod 644 /etc/ssh/sshd_config
|
||||
|
||||
#Activating scripts
|
||||
RUN chown -R root:root /root/scripts
|
||||
RUN chmod 700 /root/scripts/*.sh
|
||||
|
||||
#Port exposition
|
||||
EXPOSE 22
|
||||
|
||||
|
||||
#Issuing start entrypoint
|
||||
CMD ["/bin/bash", "/root/scripts/entrypoint.sh"]
|
||||
19
auditd.conf
Normal file
19
auditd.conf
Normal file
@ -0,0 +1,19 @@
|
||||
log_file = /var/log/audit/audit.log
|
||||
log_format = RAW
|
||||
log_group = root
|
||||
priority_boost = 4
|
||||
flush = INCREMENTAL_ASYNC
|
||||
freq = 50
|
||||
num_logs = 5
|
||||
dispatcher = /sbin/audispd
|
||||
name_format = NONE
|
||||
## Set the maximum file size and the action to take when the limit is reached
|
||||
max_log_file = 30
|
||||
max_log_file_action = ROTATE
|
||||
space_left = 75
|
||||
space_left_action = SYSLOG
|
||||
action_mail_acct = root
|
||||
admin_space_left = 50
|
||||
admin_space_left_action = SUSPEND
|
||||
disk_full_action = SUSPEND
|
||||
disk_error_action = SUSPEND
|
||||
2
authorized_servers.txt
Normal file
2
authorized_servers.txt
Normal file
@ -0,0 +1,2 @@
|
||||
172.17.0.1 test1 jpeg,george
|
||||
172.17.0.2 test2 george
|
||||
43
entrypoint.sh
Normal file
43
entrypoint.sh
Normal file
@ -0,0 +1,43 @@
|
||||
hostname ${HOSTNAME}
|
||||
echo "Monosphere anacron scheduler is starting..."
|
||||
service anacron start
|
||||
echo "Monosphere anacron scheduler is successfully started"
|
||||
|
||||
echo "Monosphere sshd service daemon is verifying its configuration..."
|
||||
sshd -t
|
||||
echo "Monosphere sshd service daemon configuration verified"
|
||||
|
||||
echo "Monosphere rsyslog daemon is starting..."
|
||||
service rsyslog start
|
||||
echo "Monosphere rsyslog daemon is successfully started"
|
||||
|
||||
echo "Monosphere auditd daemon is starting..."
|
||||
service auditd start
|
||||
echo "Monosphere auditd daemon is successfully started"
|
||||
|
||||
echo "Monosphere sshd service daemon is starting..."
|
||||
service ssh start
|
||||
echo "Monosphere sshd service daemon is successfully started"
|
||||
|
||||
echo "Monosphere is enabling custom scripts..."
|
||||
chown -R root:root /opt/custom
|
||||
chmod 700 /opt/custom/scripts/*.sh
|
||||
bash /opt/custom/scripts/*.sh
|
||||
echo "Monosphere custom scripts are successfully enabled"
|
||||
|
||||
echo "Monosphere is configuring public directory..."
|
||||
chown -R root:root /opt/public
|
||||
chmod -R 755 /opt/public
|
||||
echo "Monosphere public directory successfully configured"
|
||||
|
||||
echo "Monosphere is creating the bastion user, I hope you changed the default user info..."
|
||||
adduser --disabled-password --gecos "" ${BASTIONUSER} --shell /bin/bash #/usr/sbin/nologin
|
||||
echo "${BASTIONUSER}:${BASTIONPASS}" | chpasswd
|
||||
mkdir /home/${BASTIONUSER}/.ssh
|
||||
chown ${BASTIONUSER}:${BASTIONUSER} /home/${BASTIONUSER}/.ssh
|
||||
echo "Monosphere have created the bastion user"
|
||||
|
||||
echo "Monosphere bastion is successfully started"
|
||||
|
||||
# Keep the container running
|
||||
tail -f /dev/null
|
||||
11
monosphere_banner.txt
Normal file
11
monosphere_banner.txt
Normal file
@ -0,0 +1,11 @@
|
||||
|
||||
@@@@@@@@@@[Welcome to the Monosphere bastion]@@@@@@@@@@
|
||||
Authorized personnel only is allowed to come here.
|
||||
If you're not authorized personnel, please disconnect
|
||||
from this interface this instant.
|
||||
|
||||
-------------------------------------------------------
|
||||
Monosphere is logging the current connection.
|
||||
|
||||
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
|
||||
|
||||
33
server_menu.sh
Normal file
33
server_menu.sh
Normal file
@ -0,0 +1,33 @@
|
||||
#!/bin/bash
|
||||
|
||||
AUTHORIZED_SERVERS_FILE="/opt/public/servers/authorized_servers.txt"
|
||||
USER_SERVERS=$(grep -w "$(whoami)" $AUTHORIZED_SERVERS_FILE)
|
||||
|
||||
if [ -z "$USER_SERVERS" ]; then
|
||||
echo "Vous n'avez pas l'autorisation de vous connecter à un serveur."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "Veuillez sélectionner un serveur auquel vous connecter :"
|
||||
|
||||
counter=1
|
||||
declare -A server_map
|
||||
while read -r line; do
|
||||
ip=$(echo "$line" | cut -d ' ' -f 1)
|
||||
custom_name=$(echo "$line" | cut -d ' ' -f 2)
|
||||
server_map[$counter]=$ip
|
||||
echo "$counter) $custom_name - $ip"
|
||||
counter=$((counter + 1))
|
||||
done <<< "$USER_SERVERS"
|
||||
|
||||
read -r -p "Votre choix (1-${#server_map[@]}): " choice
|
||||
|
||||
if [ -z "${server_map[$choice]}" ]; then
|
||||
echo "Sélection invalide."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
selected_server="${server_map[$choice]}"
|
||||
echo "Connexion à $selected_server..."
|
||||
ssh "$selected_server"
|
||||
|
||||
20
ssh-launcher.sh
Normal file
20
ssh-launcher.sh
Normal file
@ -0,0 +1,20 @@
|
||||
#!/bin/bash
|
||||
|
||||
# Vérifier si le service SSH est en cours d'exécution
|
||||
ssh_pid=$(pgrep sshd)
|
||||
|
||||
if [ ! -z "$ssh_pid" ]; then
|
||||
echo "Le service SSH est en cours d'exécution."
|
||||
else
|
||||
echo "Le service SSH n'est pas en cours d'exécution. Tentative de démarrage..."
|
||||
sudo service ssh start
|
||||
|
||||
# Vérifier à nouveau si SSH est en cours d'exécution
|
||||
ssh_pid=$(pgrep sshd)
|
||||
if [ ! -z "$ssh_pid" ]; then
|
||||
echo "Le service SSH a été démarré avec succès."
|
||||
else
|
||||
echo "Échec du démarrage du service SSH. Veuillez vérifier les logs pour plus de détails."
|
||||
fi
|
||||
fi
|
||||
|
||||
21
ssh-monitor.rules
Normal file
21
ssh-monitor.rules
Normal file
@ -0,0 +1,21 @@
|
||||
# Monitor the use of SSH private keys
|
||||
-w /etc/ssh/ssh_host_key -p rwa -k ssh_key
|
||||
-w /etc/ssh/ssh_host_rsa_key -p rwa -k ssh_key
|
||||
-w /etc/ssh/ssh_host_dsa_key -p rwa -k ssh_key
|
||||
-w /etc/ssh/ssh_host_ecdsa_key -p rwa -k ssh_key
|
||||
-w /etc/ssh/ssh_host_ed25519_key -p rwa -k ssh_key
|
||||
|
||||
# Monitor SSH configuration files
|
||||
-w /etc/ssh/ssh_config -p rwa -k ssh_config
|
||||
-w /etc/ssh/sshd_config -p rwa -k ssh_config
|
||||
|
||||
# Monitor the use of the ssh command
|
||||
-a exit,always -F arch=b64 -S execve -F path=/usr/bin/ssh -k ssh_exec
|
||||
|
||||
# Monitor session initiation, including timestamp and user information
|
||||
-w /var/run/utmp -p wa -k session
|
||||
-w /var/log/wtmp -p wa -k session
|
||||
-w /var/log/btmp -p wa -k session
|
||||
|
||||
# Monitor user commands
|
||||
-a exit,always -F arch=b64 -S execve -F auid>=1000 -F auid!=4294967295 -k user_commands
|
||||
126
sshd_config
Normal file
126
sshd_config
Normal file
@ -0,0 +1,126 @@
|
||||
# $OpenBSD: sshd_config,v 1.103 2018/04/09 20:41:22 tj Exp $
|
||||
|
||||
# This is the sshd server system-wide configuration file. See
|
||||
# sshd_config(5) for more information.
|
||||
|
||||
# This sshd was compiled with PATH=/usr/bin:/bin:/usr/sbin:/sbin
|
||||
|
||||
# The strategy used for options in the default sshd_config shipped with
|
||||
# OpenSSH is to specify options with their default value where
|
||||
# possible, but leave them commented. Uncommented options override the
|
||||
# default value.
|
||||
|
||||
Include /etc/ssh/sshd_config.d/*.conf
|
||||
|
||||
Port 22
|
||||
#AddressFamily any
|
||||
#ListenAddress 0.0.0.0
|
||||
#ListenAddress ::
|
||||
|
||||
HostKey /etc/ssh/ssh_host_ed25519_key
|
||||
HostKey /etc/ssh/ssh_host_ecdsa_key
|
||||
HostKey /etc/ssh/ssh_host_rsa_key
|
||||
|
||||
# Ciphers and keying
|
||||
#RekeyLimit default none
|
||||
|
||||
# Logging
|
||||
#SyslogFacility AUTH
|
||||
LogLevel VERBOSE
|
||||
|
||||
# Authentication:
|
||||
|
||||
#LoginGraceTime 2m
|
||||
PermitRootLogin no
|
||||
#StrictModes yes
|
||||
MaxAuthTries 6
|
||||
#MaxSessions 10
|
||||
|
||||
#PubkeyAuthentication yes
|
||||
|
||||
# Expect .ssh/authorized_keys2 to be disregarded by default in future.
|
||||
#AuthorizedKeysFile .ssh/authorized_keys .ssh/authorized_keys2
|
||||
|
||||
#AuthorizedPrincipalsFile none
|
||||
|
||||
#AuthorizedKeysCommand none
|
||||
#AuthorizedKeysCommandUser nobody
|
||||
|
||||
# For this to work you will also need host keys in /etc/ssh/ssh_known_hosts
|
||||
#HostbasedAuthentication no
|
||||
# Change to yes if you don't trust ~/.ssh/known_hosts for
|
||||
# HostbasedAuthentication
|
||||
#IgnoreUserKnownHosts no
|
||||
# Don't read the user's ~/.rhosts and ~/.shosts files
|
||||
#IgnoreRhosts yes
|
||||
|
||||
# To disable tunneled clear text passwords, change to no here!
|
||||
PasswordAuthentication yes
|
||||
#PermitEmptyPasswords no
|
||||
|
||||
# Change to yes to enable challenge-response passwords (beware issues with
|
||||
# some PAM modules and threads)
|
||||
ChallengeResponseAuthentication no
|
||||
|
||||
# Kerberos options
|
||||
#KerberosAuthentication no
|
||||
#KerberosOrLocalPasswd yes
|
||||
#KerberosTicketCleanup yes
|
||||
#KerberosGetAFSToken no
|
||||
|
||||
# GSSAPI options
|
||||
#GSSAPIAuthentication no
|
||||
#GSSAPICleanupCredentials yes
|
||||
#GSSAPIStrictAcceptorCheck yes
|
||||
#GSSAPIKeyExchange no
|
||||
|
||||
# Set this to 'yes' to enable PAM authentication, account processing,
|
||||
# and session processing. If this is enabled, PAM authentication will
|
||||
# be allowed through the ChallengeResponseAuthentication and
|
||||
# PasswordAuthentication. Depending on your PAM configuration,
|
||||
# PAM authentication via ChallengeResponseAuthentication may bypass
|
||||
# the setting of "PermitRootLogin without-password".
|
||||
# If you just want the PAM account and session checks to run without
|
||||
# PAM authentication, then enable this but set PasswordAuthentication
|
||||
# and ChallengeResponseAuthentication to 'no'.
|
||||
UsePAM yes
|
||||
|
||||
AllowAgentForwarding no
|
||||
#AllowTcpForwarding yes
|
||||
#GatewayPorts no
|
||||
X11Forwarding no
|
||||
#X11DisplayOffset 10
|
||||
#X11UseLocalhost yes
|
||||
PermitTTY yes
|
||||
PrintMotd no
|
||||
#PrintLastLog yes
|
||||
#TCPKeepAlive yes
|
||||
#PermitUserEnvironment no
|
||||
#Compression delayed
|
||||
#ClientAliveInterval 0
|
||||
#ClientAliveCountMax 3
|
||||
#UseDNS no
|
||||
#PidFile /var/run/sshd.pid
|
||||
#MaxStartups 10:30:100
|
||||
#PermitTunnel no
|
||||
#ChrootDirectory none
|
||||
#VersionAddendum none
|
||||
|
||||
# no default banner path
|
||||
Banner /root/scripts/monosphere_banner.txt
|
||||
|
||||
# Allow client to pass locale environment variables
|
||||
AcceptEnv LANG LC_*
|
||||
|
||||
# override default of no subsystems
|
||||
Subsystem sftp /usr/lib/ssh/sftp-server -f AUTHPRIV -l INFO
|
||||
|
||||
#---Bastion configurations ! CHANGE AT YOUR OWN RISK !---
|
||||
KexAlgorithms curve25519-sha256@libssh.org,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256
|
||||
Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr
|
||||
MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,umac-128@openssh.com
|
||||
PubkeyAcceptedKeyTypes sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com
|
||||
AllowStreamLocalForwarding no
|
||||
Match User *,!ubuntu
|
||||
ForceCommand /opt/public/scripts/server_menu.sh
|
||||
X11Forwarding no
|
||||
Loading…
x
Reference in New Issue
Block a user