forked from aquasecurity/cloudsploit
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathopenMySQL.js
More file actions
88 lines (70 loc) · 3.5 KB
/
Copy pathopenMySQL.js
File metadata and controls
88 lines (70 loc) · 3.5 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
var async = require('async');
var helpers = require('../../../helpers/oracle/');
module.exports = {
title: 'Open MySQL',
category: 'Networking',
description: 'Determine if TCP port 4333 or 3306 for MySQL is open to the public',
more_info: 'While some ports such as HTTP and HTTPS are required to be open to the ' +
'public to function properly, more sensitive services such as MySQL should be ' +
'restricted to known IP addresses.',
recommended_action: 'Restrict TCP ports 4333 and 3306 to known IP addresses',
link: 'https://docs.cloud.oracle.com/iaas/Content/Network/Concepts/securitylists.htm',
apis: ['vcn:list', 'securityList:list','networkSecurityGroup:list','securityRule:list'],
run: function(cache, settings, callback) {
var results = [];
var source = {};
var regions = helpers.regions(settings.govcloud);
var isSecurityRule = false;
async.each(regions.securityList, function(region, rcb){
if (helpers.checkRegionSubscription(cache, source, results, region)) {
var ruleEmpty = false;
var listEmpty = false;
var ports = {
'tcp': [4333, 3306]
};
var service = 'MySQL';
var getSecurityLists = helpers.addSource(cache, source,
['securityList', 'list', region]);
if (getSecurityLists && getSecurityLists.err) {
helpers.addResult(results, 3,
'Unable to query for security lists: ' +
helpers.addError(getSecurityLists), region);
} else if (getSecurityLists &&
(!getSecurityLists.data || !getSecurityLists.data.length)) {
listEmpty = true;
} else if (getSecurityLists) {
helpers.findOpenPorts(getSecurityLists.data, ports,
service, region, results, isSecurityRule);
}
var getSecurityRules = helpers.addSource(cache, source,
['securityRule', 'list', region]);
if (getSecurityRules && getSecurityRules.err) {
helpers.addResult(results, 3,
'Unable to query for security rules: ' +
helpers.addError(getSecurityRules), region);
} else if (getSecurityRules &&
(!getSecurityRules.data || !getSecurityRules.data.length)) {
ruleEmpty = true;
} else if (getSecurityRules) {
var getSecurityGroups = helpers.addSource(cache, source,
['networkSecurityGroup', 'list', region]);
isSecurityRule = true;
helpers.findOpenPorts(getSecurityRules.data, ports,
service, region, results, isSecurityRule, getSecurityGroups);
}
if (ruleEmpty && listEmpty) {
helpers.addResult(results, 0,
'No security rules or lists found', region);
} else if (ruleEmpty) {
helpers.addResult(results, 0, 'No security rules found', region);
} else if (listEmpty) {
helpers.addResult(results, 0, 'No security lists found', region);
}
}
rcb();
}, function(){
// Global checking goes here
callback(null, results, source);
});
}
};