I have build me an working rpm-packet. But I stuck at the point to activate the wazuh module for oscap.
Also I have build me some cis-rootkit files for sles11 and sles12.
But I got thousands of alterts with btrfs that the number of links are wrong....
Files hidden inside directory '/var/tmp'. Link count does not match number of files (3,1)
ls -la /var/tmp | grep ^d | wc -l
stat /var/tmp
sles12test:/var/tmp # ls -la /var/tmp | grep ^d | wc -l8
sles12test:/var/tmp # stat /var/tmp Datei: „/var/tmp“ Größe: 718 Blöcke: 0 EA Block: 4096 VerzeichnisGerät: 29h/41d Inode: 256 Verknüpfungen: 1Zugriff: (1777/drwxrwxrwt) Uid: ( 0/ root) Gid: ( 0/ root)Zugriff : 2016-09-05 10:18:51.899837496 +0200Modifiziert: 2016-09-05 10:04:31.097393192 +0200Geändert : 2016-09-05 10:04:31.097393192 +0200 Geburt : -
linux-9p27:/var/tmp # df -hTFilesystem Type Size Used Avail Use% Mounted ondevtmpfs devtmpfs 7.9G 0 7.9G 0% /devtmpfs tmpfs 7.9G 0 7.9G 0% /dev/shmtmpfs tmpfs 7.9G 1.7M 7.9G 1% /runtmpfs tmpfs 7.9G 0 7.9G 0% /sys/fs/cgroup/dev/mapper/system-root btrfs 24G 3.0G 21G 14% //dev/mapper/system-root btrfs 24G 3.0G 21G 14% /var/spool/dev/mapper/system-root btrfs 24G 3.0G 21G 14% /var/lib/mysql/dev/mapper/system-root btrfs 24G 3.0G 21G 14% /srv/dev/mapper/system-root btrfs 24G 3.0G 21G 14% /boot/grub2/i386-pc/dev/mapper/system-root btrfs 24G 3.0G 21G 14% /.snapshots/dev/mapper/system-root btrfs 24G 3.0G 21G 14% /var/lib/pgsql/dev/mapper/system-root btrfs 24G 3.0G 21G 14% /var/lib/mailman/dev/mapper/system-root btrfs 24G 3.0G 21G 14% /usr/local/dev/mapper/system-root btrfs 24G 3.0G 21G 14% /tmp/dev/mapper/system-root btrfs 24G 3.0G 21G 14% /opt/dev/mapper/system-root btrfs 24G 3.0G 21G 14% /var/log/dev/mapper/system-root btrfs 24G 3.0G 21G 14% /var/crash/dev/mapper/system-root btrfs 24G 3.0G 21G 14% /boot/grub2/x86_64-efi/dev/mapper/system-root btrfs 24G 3.0G 21G 14% /var/lib/mariadb/dev/mapper/system-root btrfs 24G 3.0G 21G 14% /var/opt/dev/mapper/system-root btrfs 24G 3.0G 21G 14% /var/lib/libvirt/images/dev/mapper/system-root btrfs 24G 3.0G 21G 14% /var/tmp/dev/mapper/system-root btrfs 24G 3.0G 21G 14% /var/lib/named/dev/mapper/system-home xfs 36G 33M 36G 1% /homelinux-9p27:~ # ls -la /var/tmp/total 0drwxrwxrwt 1 root root 164 Sep 5 18:43 .drwxr-xr-x 1 root root 96 Jul 28 20:28 ..drwx------ 1 root root 6 Sep 5 18:40 systemd-private-7d9f1af055764f40a45c6330621413ea-ntpd.service-VSw2vsdrwxr-xr-x 1 root root 54 Sep 5 18:44 tsdrwxr-xr-x 1 root root 0 Sep 5 18:43 tswrdrwxr-xr-x 1 root root 0 Sep 5 18:43 tswrwseflinux-9p27:~ # stat /var/tmp/ File: ‘/var/tmp/’ Size: 164 Blocks: 0 IO Block: 4096 directoryDevice: 38h/56d Inode: 256 Links: 1Access: (1777/drwxrwxrwt) Uid: ( 0/ root) Gid: ( 0/ root)Access: 2016-09-05 18:43:53.545161213 +0200Modify: 2016-09-05 18:43:51.026421122 +0200Change: 2016-09-05 18:43:51.026421122 +0200 Birth: -linux-9p27:~ # mkdir /var/tmp/testslinux-9p27:~ # stat /var/tmp/ File: ‘/var/tmp/’ Size: 174 Blocks: 0 IO Block: 4096 directoryDevice: 38h/56d Inode: 256 Links: 1Access: (1777/drwxrwxrwt) Uid: ( 0/ root) Gid: ( 0/ root)Access: 2016-09-05 18:43:53.545161213 +0200Modify: 2016-09-05 18:47:53.249252999 +0200Change: 2016-09-05 18:47:53.249252999 +0200 Birth: -
linux-9p27:~ # stat /home File: ‘/home’ Size: 6 Blocks: 0 IO Block: 4096 directoryDevice: fe02h/65026d Inode: 64 Links: 2Access: (0755/drwxr-xr-x) Uid: ( 0/ root) Gid: ( 0/ root)Access: 2016-07-28 20:29:39.532889000 +0200Modify: 2015-09-30 12:59:27.000000000 +0200Change: 2016-07-28 20:27:38.228889000 +0200 Birth: -linux-9p27:~ # ls -la /hometotal 0drwxr-xr-x 2 root root 6 Sep 30 2015 .drwxr-xr-x 1 root root 166 Jul 28 20:29 ..linux-9p27:~ # mkdir /home/testlinux-9p27:~ # stat /home File: ‘/home’ Size: 18 Blocks: 0 IO Block: 4096 directoryDevice: fe02h/65026d Inode: 64 Links: 3Access: (0755/drwxr-xr-x) Uid: ( 0/ root) Gid: ( 0/ root)Access: 2016-09-05 18:50:52.167748999 +0200Modify: 2016-09-05 18:50:59.124268999 +0200Change: 2016-09-05 18:50:59.124268999 +0200 Birth: -
<group name="rootcheck,">
<rule id="100002" level="0">
<if_sid>510</if_sid>
<match>Link count does not match number of files</match>
<description>Ignore Link count (rootcheck)</description>
</rule>
</group>
https://github.com/ossec/ossec-hids/pull/950
Let's see....