CISOfy / lynis

Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
https://cisofy.com/lynis/
GNU General Public License v3.0
13.47k stars 1.49k forks source link

AUTH-9284 doesn't exist anymore #1563

Open thiagomarafeli opened 1 month ago

thiagomarafeli commented 1 month ago

Describe the bug When I ran the lynis script, one of the warnings was about Locked Accounts, but, when clicking the suggested link, leads to a page that doesn't exist

Version

Expected behavior A page showing the description of AUTH-9284

Output Shows a page saying that it looks like a new discovery

Additional context The access to the webpage was made 15min ago

mboelen commented 1 month ago

Thanks for reporting. Can you show me the details of the output (lynis show details AUTH-9284) that you are seeing? Based on that (but redacted), we can create a new article to add as one of the links.

thiagomarafeli commented 4 weeks ago

Thanks for reporting. Can you show me the details of the output (lynis show details AUTH-9284) that you are seeing? Based on that (but redacted), we can create a new article to add as one of the links.

This is the output of lynis show details AUTH-9284:

2024-10-16 20:54:06 Performing test ID AUTH-9284 (Check locked user accounts in /etc/passwd)
2024-10-16 20:54:06 Test: Checking locked accounts
2024-10-16 20:54:06 Result: found one or more locked accounts
2024-10-16 20:54:06 Locked account: ssm-user
2024-10-16 20:54:06 Locked account: ubuntu
2024-10-16 20:54:06 Suggestion: Look at the locked accounts and consider removing them [test:AUTH-9284] [details:-] [solution:-]
2024-10-16 20:54:06 ====

Also, when I ran the ./lynis audit system command, one of the things it returned was this:

  * Look at the locked accounts and consider removing them [AUTH-9284] 
    - Related resources
      * Website: https://cisofy.com/lynis/controls/AUTH-9284/