scVENUS / PeekabooAV-Installer

This repository provides scripts and configuration files to install, update and test a Peekaboo installation
GNU General Public License v3.0
7 stars 9 forks source link

Secure Peekaboo/Cuckoo directory #16

Closed michaelweiser closed 5 years ago

michaelweiser commented 5 years ago

Our storage directory /var/lib/peekaboo contains highly sensitive data but is currently world-readable. Particularly .cuckoo/conf/cuckoo.conf contains the database password and must not be readable by anyone other than the Peekaboo (or Cuckoo) runtime user. But also in-flight or archives malware samples as well as analyses reports should be kept private to peekaboo.