Title: New Scanner: Implement a SSH Server Scanner · Issue #54 · secureCodeBox/secureCodeBox · GitHub
Open Graph Title: New Scanner: Implement a SSH Server Scanner · Issue #54 · secureCodeBox/secureCodeBox
X Title: New Scanner: Implement a SSH Server Scanner · Issue #54 · secureCodeBox/secureCodeBox
Description: Is your feature request related to a problem? Please describe. As an user i want to use test my ssh-server (or already found ssh port) based on best practices and given security policies with the secureCodeBox. Some Best Practices on the...
Open Graph Description: Is your feature request related to a problem? Please describe. As an user i want to use test my ssh-server (or already found ssh port) based on best practices and given security policies with the s...
X Description: Is your feature request related to a problem? Please describe. As an user i want to use test my ssh-server (or already found ssh port) based on best practices and given security policies with the s...
Opengraph URL: https://github.com/secureCodeBox/secureCodeBox/issues/54
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"New Scanner: Implement a SSH Server Scanner","articleBody":"**Is your feature request related to a problem? Please describe.**\r\nAs an user i want to use test my ssh-server (or already found ssh port) based on best practices and given security policies with the secureCodeBox. \r\n\r\nSome Best Practices on the topic **ssh hardening** can be found here:\r\n- https://linux-audit.com/audit-and-harden-your-ssh-configuration/\r\n- https://infosec.mozilla.org/guidelines/openssh\r\n\r\n**Describe the solution you'd like**\r\nThere are already some ssh security scanners like:\r\n- https://github.com/arthepsy/ssh-audit\r\n- https://github.com/mozilla/ssh_scan\r\n\r\nEspecially the **mozilla ssh_scan** seems to be a good candidate to implement.\r\nIt's well documented and has a active community. It supports _JSON output_ and the possibility to add my own _ssh check policy_. \r\n- See here for [example video](https://asciinema.org/a/7pliiw5zqhj7eqvz7q437u6vx)\r\n- See here for [example output](https://github.com/mozilla/ssh_scan/blob/master/examples/192.168.1.1.json)\r\n- See here for [example policies](https://github.com/mozilla/ssh_scan/blob/master/config/policies)\r\n\r\n**Additional context**\r\nA new ssh scanner could be combined with the existing port scanner (nmap) to check found ssh ports.\r\n\r\n## Steps to implement a new scanner\r\nA general guide how to implement a new scanner is documented [here]( https://github.com/secureCodeBox/secureCodeBox/blob/master/docs/developer-guide/README.md#developing-own-processes)\r\n\r\n### Must have\r\n- [x] Create a [new public secureCodeBox repository](https://github.com/organizations/secureCodeBox/repositories/new) for the scanner implementation\r\n- [x] Implement a new scanner microservice an reuse some of the existing stuff, if possible\r\n- [ ] Check if there is a [healthcheck](https://github.com/secureCodeBox/secureCodeBox/blob/master/docs/developer-guide/README.md#healthchecks-for-scanner-microservices) for the microservice implemented\r\n- [x] Implement a [new basic security process](https://github.com/secureCodeBox/secureCodeBox/blob/master/docs/developer-guide/README.md#developing-a-process-model) for the scanner\r\n- [x] Update the [docker-compose](https://github.com/secureCodeBox/secureCodeBox/blob/master/docker-compose.yml) files and integrate your new scanner there\r\n- [ ] Update the [user guide](https://github.com/secureCodeBox/secureCodeBox/tree/master/docs/user-guide) and [developer guide](https://github.com/secureCodeBox/secureCodeBox/tree/master/docs/developer-guide)\r\n- [x] Implement a integration test for the scanner [here](https://github.com/secureCodeBox/secureCodeBox/tree/master/test)\r\n\r\n### Should have\r\n- [ ] Update the [CLI examples](https://github.com/secureCodeBox/secureCodeBox/tree/master/cli)\r\n- [ ] Update the [Jenkins Pipeline](https://github.com/secureCodeBox/integration-pipeline-jenkins-examples) examples\r\n- [x] Update the [OpenShift Container Setup](https://github.com/secureCodeBox/ansible-role-securecodebox-openshift)\r\n","author":{"url":"https://github.com/rfelber","@type":"Person","name":"rfelber"},"datePublished":"2018-10-16T12:07:27.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":1},"url":"https://github.com/54/secureCodeBox/issues/54"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:23e7fa85-19e9-eba4-846e-be154db6499b |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | 9F42:18E94D:808C502:A62ECC5:6976EAA6 |
| html-safe-nonce | c6e9577c4d2c6c9ceb280edf7fc0f1d30bc51a098d9ea9d18483121cd200a0a0 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiI5RjQyOjE4RTk0RDo4MDhDNTAyOkE2MkVDQzU6Njk3NkVBQTYiLCJ2aXNpdG9yX2lkIjoiNDYxODk0MjAxNTI1NjA2MjYzMCIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9 |
| visitor-hmac | ef5c54013eb3b02e51249a003ec31c4308843f8f060cfd61a983cf5b2732b8c4 |
| hovercard-subject-tag | issue:370579528 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/secureCodeBox/secureCodeBox/54/issue_layout |
| twitter:image | https://opengraph.githubassets.com/1c250da9576aec14d35bdd22aef075826eeade9649fcc4d44b4794b4d99ff17e/secureCodeBox/secureCodeBox/issues/54 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/1c250da9576aec14d35bdd22aef075826eeade9649fcc4d44b4794b4d99ff17e/secureCodeBox/secureCodeBox/issues/54 |
| og:image:alt | Is your feature request related to a problem? Please describe. As an user i want to use test my ssh-server (or already found ssh port) based on best practices and given security policies with the s... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | rfelber |
| hostname | github.com |
| expected-hostname | github.com |
| None | 01d198479908d09a841b2febe8eb105a81af2af7d81830960fe0971e1f4adc09 |
| turbo-cache-control | no-preview |
| go-import | github.com/secureCodeBox/secureCodeBox git https://github.com/secureCodeBox/secureCodeBox.git |
| octolytics-dimension-user_id | 34573705 |
| octolytics-dimension-user_login | secureCodeBox |
| octolytics-dimension-repository_id | 80711933 |
| octolytics-dimension-repository_nwo | secureCodeBox/secureCodeBox |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 80711933 |
| octolytics-dimension-repository_network_root_nwo | secureCodeBox/secureCodeBox |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | f752335dbbea672610081196a1998e39aec5e14b |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width