Comments (8)
ok, I got it now! Thanks for the detailed explanation @jamestford. I didn't think on that use case like yours and makes a lot of sense to add "--output" to all prowler commands to force the output I want and prevent taking default values that may incur in wrong results. Does it make sense?
from prowler.
Okay, looks like this is an issue when using table output rather than json output based on the way the query action returns results. If you use json the policy will be scored correctly.
from prowler.
Hi @jamestford, thanks for your feedback. I have just tested it again and it works fine. What do you mean with table vs json? If you look at the code from here https://github.com/Alfresco/prowler/blob/master/prowler#L534 prowler checks just the output of each particular value in lowercase (true or false) unless you change the default output format it should work.
from prowler.
When running aws from the command line you can tell it to output to json format or in table format. I had it set for table since it is more human readable (details here: http://docs.aws.amazon.com/cli/latest/userguide/controlling-output.html). But I noticed prowler would fail using the table format using the --query option, but when switching to json the --query option worked property (i.e., --query 'PasswordPolicy.RequireSymbols' ). When I get back to my test machine I can provide some screenshots. Thanks for the response!
from prowler.
I got your point, but you don't need to change anything on the command line to get prowler proper results. Prowler does queries and filter results in different formats depending on each test. Or am I missing something?
from prowler.
from prowler.
from prowler.
Fixed with PR #67
from prowler.
Related Issues (20)
- Allow secrets to be output when explicitly asked for using a flag HOT 3
- [Bug]: prowler azure is not scanning virtual machines in azure HOT 2
- [Bug]: iam_user_console_access_unused.py checks for last password usage HOT 3
- [Bug]: Prowler killed by OOM killer when run in AWS CloudShell HOT 6
- [Feature Request] - Round Robin the base urls in the event of unavailability for indexers HOT 1
- [Bug]: Cross account sqs flagged as public/critical HOT 3
- [Bug]: Exception merging from "*" and specific account HOT 3
- [Bug]: False positive on check - "Check if SQS queues have policy set as Public" HOT 2
- Improve publicly accessible checks to include targets of ELBs HOT 7
- [Bug]: Website Down? HOT 1
- [Bug]: False positve on ec2_securitygroup_not_used with Batch Compute HOT 6
- Support py3.12 HOT 1
- [Bug]: cloudwatch_log_group_retention_policy_specific_days_enabled alert on AWS managed log group HOT 4
- Possibility to custom output file using quick inventory HOT 1
- [Bug]: Output issue HOT 9
- [Bug]: False positive on s3_bucket_policy_public_write_access HOT 1
- [Bug]: allow list reporting wrong findings HOT 3
- [Question]: AWS account security questions have been deprecated HOT 3
- [Question]: Remove S3 KMS check, since its enabed by default, and cant be disabled HOT 2
- [Bug]: The assumed role ARN contains a value for resource type different than role, please input a valid ARN HOT 13
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from prowler.