Linux Security Auditing Tool (LSAT) is a post install security auditing tool. It is modular in design, so new features can be added quickly. It checks many system configurations and local network settings on the system for common security/config errors and for packages that are not needed. It has been tested on Linux (Gentoo, Red Hat, Debian, etc.) and Solaris (SunOS 2.x).

2008-05-04 23:11

This release adds an extra limits check on resource limits, a Redhat/Fedora specific check in checkcfg, and checking for strict mode in SSH config. It fixes a few small output errors.
2007-05-21 04:51

The dependency on the popt library has been removed. This release adds extra passwd and group checks under Linux, a check for failed logins under Linux/Solaris, a check for kernel modules under Solaris, network interface stats, and routing checks. It fixes a problem in checknetforward giving false positives, and an issue where verbose output was not very consistent. The kernel module check under Linux has been modified.
2007-04-28 21:30

Headers were missing from a number of modules, and
checkrc was not working under Linux kernel 2.6 and
gentoo. A possible symlink attack in various
modules and notes in modules writing instructions
were fixed. The checkinit module returning false
positive under gentoo was fixed. checknet was
changed to reflect a network promiscuity change
under the Linux 2.6 kernel. The behavior of
checkopenfiles was changed, as it would not catch
some open files. More checking was added to the
checkdotfiles module. Various typos and formatting
errors were fixed.
2006-09-16 22:53

Explicit CentOS, CaOS, and Fedora Core checks were
added. Changes were made in the umask module. More
sys exclusions were added for find in md5. The
openfiles module was sped up. Checks for listening
applications were added. Small problems in the
checkx module were resolved.
2005-10-09 09:03

An error in checkwww under Slackware and an error
in checkhostfiles under Solaris were fixed. Typos
in checkinittab.c were fixed. General code cleanup
was done.
