
Red Hat के Log4j डिटेक्टर स्क्रिप्ट को स्वचालित करने वाला Ansible प्लेबुक जो GPG सत्यापन के साथ CVE-2021-44228 (Log4Shell) कमजोरी के लिए Linux होस्ट्स को स्कैन करता है।
आधिकारिक Red Hat Log4j डिटेक्टर स्क्रिप्ट का उपयोग करके लक्ष्य Linux होस्ट्स को सत्यापित करने के लिए Ansible प्लेबुक (CVE-2021-44228)।
Red Hat संस्करण 1.3 डिटेक्टर 2022-01-10।
परिणाम detector_dir के अंतर्गत एक txt फ़ाइल में सहेजा जाता है (डिफ़ॉल्ट: /opt/cve-2021-44228/)।
कोड Ansible Galaxy भूमिका के रूप में भी उपलब्ध है lucab85.ansible_role_log4shell```bash ansible-galaxy install lucab85.ansible_role_log4shell
## Ansible Playbook कैसे चलाएं
डिफ़ॉल्ट वैरिएबल्स प्रभावित फ़ाइलों के लिए `/var/` पथ को स्कैन करते हैं।
आप अधिक विकल्पों के लिए `vars.yml` फ़ाइल को अनुकूलित कर सकते हैं।```bash
ansible-playbook log4j-cve-2021-44228.yml
कोई नहीं।
ansible 2.9+
डिफ़ॉल्ट मान:```yaml rh_bullettin: >- https://access.redhat.com/security/vulnerabilities/RHSB-2021-009 intro: | Ansible Playbook tested with detector version 1.3 released 2022-01-10. If a 404 error occur please adjust the URL with the latest version available for detector URL. Please refer to the Red Hat Security Bullettin for up-to-date information and adjust the playbook variables accordingly. {{ rh_bullettin }}. vulnerable: | System MIGHT be vulnerable to log4j (CVE-2021-44228) not_vulnerable: | System IS NOT vulnerable to log4j (CVE-2021-44228) report_txt: "/report/vuln_log4j2_path_*.txt" sh_detector: "cve-2021-44228--2022-01-10-1242.sh" sh_signature: "cve-2021-44228--2022-01-10-1242.sh.asc" detector_baseurl: "https://access.redhat.com/sites/default/files/" force_download: false detector_path: "/var/" detector_dir: "/opt/cve-2021-44228/" detector_run_dir: "tmp" detector_options: '-n -d --no-progress --scan {{ detector_path }}' gpg_keyid: "7514F77D8366B0D9" gpg_server: "pgp.mit.edu" gpg_public_key: 'gpg --keyserver {{ gpg_server }} --recv {{ gpg_keyid }}' clean_run_before: true delete_after: false verify_gpg: true
- `rh_bullettin`: RHSB का लिंक (डिफ़ॉल्ट: [https://access.redhat.com/security/vulnerabilities/RHSB-2021-009](https://access.redhat.com/security/vulnerabilities/RHSB-2021-009))
- `intro`: परिचय पाठ
- `vulnerable`: असुरक्षित पाठ (केवल डिबग स्तर 2 निष्पादन `-vv` पर दिखाई देता है)
- `not_vulnerable`: असुरक्षित नहीं पाठ (केवल डिबग स्तर 2 निष्पादन `-vv` पर दिखाई देता है)
- `report_txt`: मुद्रण के लिए रिपोर्ट पथ (डिफ़ॉल्ट: `/report/vuln_log4j2_path_*.txt`)
- `sh_detector`: डिटेक्टर बैश स्क्रिप्ट फ़ाइल का फ़ाइलनाम
- `sh_signature`: डिटेक्टर GPG हस्ताक्षर फ़ाइल का फ़ाइलनाम
- `detector_baseurl`: पिछली फ़ाइलों को डाउनलोड करने का आधार URL
- `force_download`: प्रत्येक रन पर कोड डाउनलोड करने के लिए बाध्य करें (डिफ़ॉल्ट: `false`)
- `detector_path`: निरीक्षण करने का पथ (डिफ़ॉल्ट `/var/`)
- `detector_dir`: डिटेक्टर का डाउनलोड पथ (डिफ़ॉल्ट `/opt/cve-2021-44228/`)
- `detector_run_dir`: रन से पहले बनाने वाली उपनिर्देशिका (डिफ़ॉल्ट `tmp`)
- `detector_options`: डिटेक्टर स्क्रिप्ट के लिए कमांड लाइन विकल्प (डिफ़ॉल्ट `-n -d --no-progress --scan {{ detector_path }}`)
- `gpg_keyid`: सत्यापन के लिए डाउनलोड करने वाली GPG सार्वजनिक कुंजी (डिफ़ॉल्ट Red Hat Product Security `7514F77D8366B0D9`)
- `gpg_server`: GPG कुंजी सर्वर (डिफ़ॉल्ट: `pgp.mit.edu`)
- `gpg_public_key`: gpg सत्यापन के लिए कमांड (डिफ़ॉल्ट: `gpg --keyserver {{ gpg_server }} --recv {{ gpg_keyid }}`)
- `clean_run_before`: निष्पादन से पहले रन निर्देशिका हटाएं और पुनः बनाएं - डिटेक्टर को एक खाली निर्देशिका की आवश्यकता है (डिफ़ॉल्ट `true`)
- `delete_after`: निष्पादन के बाद _detector_dir_ हटाएं (डिफ़ॉल्ट `false`)
- `verify_gpg`: GPG हस्ताक्षर डाउनलोड और सत्यापन करें (डिफ़ॉल्ट: `true`)
## डेमो निष्पादन
RHEL8 डेमो लक्ष्य होस्ट के विरुद्ध प्लेबुक के निष्पादन का पूर्ण आउटपुट:```bash
$ ansible-playbook -i test/inventory log4j-cve-2021-44228.yml -vv
ansible-playbook [core 2.12.1]
config file = None
configured module search path = ['/Users/lberton/.ansible/plugins/modules', '/usr/share/ansible/plugins/modules']
ansible python module location = /usr/local/Cellar/ansible/5.1.0/libexec/lib/python3.10/site-packages/ansible
ansible collection location = /Users/lberton/.ansible/collections:/usr/share/ansible/collections
executable location = /usr/local/bin/ansible-playbook
python version = 3.10.1 (main, Dec 6 2021, 23:20:29) [Clang 13.0.0 (clang-1300.0.29.3)]
jinja version = 3.0.3
libyaml = True
No config file found; using defaults
Skipping callback 'default', as we already have a stdout callback.
Skipping callback 'minimal', as we already have a stdout callback.
Skipping callback 'oneline', as we already have a stdout callback.
PLAYBOOK: log4j-cve-2021-44228.yml *********************************************************************************************************************************************************
2 plays in log4j-cve-2021-44228.yml
PLAY [download detector for Apache Log4j (CVE-2021-44228)] *********************************************************************************************************************************
META: ran handlers
TASK [include_vars] ************************************************************************************************************************************************************************
task path: /Users/lberton/prj/github/log4j-cve-2021-44228/log4j-cve-2021-44228.yml:29
ok: [localhost] => {"ansible_facts": {"clean_run_before": true, "delete_after": false, "detector_baseurl": "https://access.redhat.com/sites/default/files/", "detector_dir": "/opt/cve-2021-44228/", "detector_options": "-n -d --no-progress --scan {{ detector_path }}", "detector_path": "/var/", "detector_run_dir": "tmp", "force_download": false, "gpg_keyid": "7514F77D8366B0D9", "gpg_public_key": "gpg --keyserver {{ gpg_server }} --recv {{ gpg_keyid }}", "gpg_server": "pgp.mit.edu", "intro": "Ansible Playbook tested with detector version 1.3 released 2022-01-10.\nIf a 404 error occur please adjust the URL with the latest version available\nfor detector URL.\nPlease refer to the Red Hat Security Bullettin for up-to-date information and\nadjust the playbook variables accordingly.\n{{ rh_bullettin }}.\n", "not_vulnerable": "System IS NOT vulnerable to log4j (CVE-2021-44228)\n", "report_txt": "/report/vuln_log4j2_path_*.txt", "rh_bullettin": "https://access.redhat.com/security/vulnerabilities/RHSB-2021-009", "sh_detector": "cve-2021-44228--2022-01-10-1242.sh", "sh_signature": "cve-2021-44228--2022-01-10-1242.sh.asc", "verify_gpg": true, "vulnerable": "System MIGHT be vulnerable to log4j (CVE-2021-44228)\n"}, "ansible_included_var_files": ["/Users/lberton/prj/github/log4j-cve-2021-44228/vars.yml"], "changed": false}
TASK [print information] *******************************************************************************************************************************************************************
task path: /Users/lberton/prj/github/log4j-cve-2021-44228/log4j-cve-2021-44228.yml:31
ok: [localhost] => {
"msg": "Ansible Playbook tested with detector version 1.3 released 2022-01-10.\nIf a 404 error occur please adjust the URL with the latest version available\nfor detector URL.\nPlease refer to the Red Hat Security Bullettin for up-to-date information and\nadjust the playbook variables accordingly.\nhttps://access.redhat.com/security/vulnerabilities/RHSB-2021-009.\n"
}