From 050a565440f07c790fb7d1641cc3e76bc7ecb53e Mon Sep 17 00:00:00 2001 From: Joseph de CLERCK Date: Mon, 20 Dec 2021 14:38:24 -0500 Subject: [PATCH] fix checks with comma issues --- checks/check122 | 4 ++-- checks/check_extra7149 | 2 +- checks/check_extra7152 | 2 +- checks/check_extra7153 | 2 +- checks/check_extra7156 | 4 ++-- checks/check_extra727 | 2 +- checks/check_extra731 | 2 +- 7 files changed, 9 insertions(+), 9 deletions(-) diff --git a/checks/check122 b/checks/check122 index 81ea3e61d2..db1c68c66c 100644 --- a/checks/check122 +++ b/checks/check122 @@ -42,9 +42,9 @@ check122(){ textFail "$REGION: Policy $policy allows \"*:*\"" "$REGION" "$policy" done else - textPass "$REGION: No custom policy found that allow full \"*:*\" administrative privileges" "$REGION" "$policy" + textPass "$REGION: No custom policy found that allow full \"*:*\" administrative privileges" "$REGION" fi else - textPass "$REGION: No custom policies found" "$REGION" "$policy" + textPass "$REGION: No custom policies found" "$REGION" fi } diff --git a/checks/check_extra7149 b/checks/check_extra7149 index 259947d886..2aa0a7b098 100644 --- a/checks/check_extra7149 +++ b/checks/check_extra7149 @@ -31,7 +31,7 @@ extra7149() { for redshiftcluster in $LIST_OF_REDSHIFT_CLUSTERS; do REDSHIFT_SNAPSHOT_ENABLED=$($AWSCLI redshift describe-cluster-snapshots $PROFILE_OPT --region $regx --cluster-identifier $redshiftcluster --snapshot-type automated) if [[ $REDSHIFT_SNAPSHOT_ENABLED ]]; then - textPass "$regx: Redshift cluster $redshiftcluster has automated snapshots $REDSHIFT_SNAPSHOT_ENABLED" "$regx" "$redshiftcluster" + textPass "$regx: Redshift cluster $redshiftcluster has automated snapshots." "$regx" "$redshiftcluster" else textFail "$regx: Redshift cluster $redshiftcluster has automated snapshots disabled!" "$regx" "$redshiftcluster" fi diff --git a/checks/check_extra7152 b/checks/check_extra7152 index e205de318a..4ad7d3b84c 100644 --- a/checks/check_extra7152 +++ b/checks/check_extra7152 @@ -30,7 +30,7 @@ CHECK_SEVERITY_extra7152="Medium" CHECK_ASFF_RESOURCE_TYPE_extra7152="AwsRoute53Domain" CHECK_ALTERNATE_check7152="extra7152" CHECK_SERVICENAME_extra7152="route53" -CHECK_RISK_extra7152='Without privacy protection enabled, ones personal information is published to the public WHOIS database' +CHECK_RISK_extra7152='Without privacy protection enabled; ones personal information is published to the public WHOIS database' CHECK_REMEDIATION_extra7152='Ensure default Privacy is enabled' CHECK_DOC_extra7152='https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/domain-privacy-protection.html' CHECK_CAF_EPIC_extra7152='Data Protection' diff --git a/checks/check_extra7153 b/checks/check_extra7153 index eee485c55e..356afe9cff 100644 --- a/checks/check_extra7153 +++ b/checks/check_extra7153 @@ -27,7 +27,7 @@ CHECK_SEVERITY_extra7153="Medium" CHECK_ASFF_RESOURCE_TYPE_extra7153="AwsRoute53Domain" CHECK_ALTERNATE_check7153="extra7153" CHECK_SERVICENAME_extra7153="route53" -CHECK_RISK_extra7153='Without transfer lock enabled, a domain name could be incorrectly moved to a new registrar' +CHECK_RISK_extra7153='Without transfer lock enabled; a domain name could be incorrectly moved to a new registrar' CHECK_REMEDIATION_extra7153='Ensure transfer lock is enabled' CHECK_DOC_extra7153='https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/domain-lock.html' CHECK_CAF_EPIC_extra7153='Data Protection' diff --git a/checks/check_extra7156 b/checks/check_extra7156 index 529c061662..2cf31e72c7 100644 --- a/checks/check_extra7156 +++ b/checks/check_extra7156 @@ -37,9 +37,9 @@ extra7156(){ for stagename in $CHECK_STAGES_NAME;do CHECK_STAGE_METHOD_LOGGING=$($AWSCLI apigatewayv2 get-stages $PROFILE_OPT --region $regx --api-id $apigwid --query "Items[?StageName == \`$stagename\` ].AccessLogSettings.DestinationArn" --output text) if [[ $CHECK_STAGE_METHOD_LOGGING ]];then - textPass "$regx: API Gateway V2 $API_GW_NAME ID: $apigwid, stage: $stagename, has access logging enabled to $CHECK_STAGE_METHOD_LOGGING" "$regx" "$API_GW_NAME" + textPass "$regx: API Gateway V2 $API_GW_NAME ID: $apigwid with stage: $stagename has access logging enabled to $CHECK_STAGE_METHOD_LOGGING" "$regx" "$API_GW_NAME" else - textFail "$regx: API Gateway V2 $API_GW_NAME ID: $apigwid, stage: $stagename, has access logging disabled" "$regx" "$API_GW_NAME" + textFail "$regx: API Gateway V2 $API_GW_NAME ID: $apigwid with stage: $stagename has access logging disabled" "$regx" "$API_GW_NAME" fi done else diff --git a/checks/check_extra727 b/checks/check_extra727 index 86f5dfbd50..ce4f29972a 100644 --- a/checks/check_extra727 +++ b/checks/check_extra727 @@ -39,7 +39,7 @@ extra727(){ if [[ $SQS_POLICY_ALLOW_ALL_WITHOUT_CONDITION ]]; then SQS_POLICY_ALLOW_ALL_WITHOUT_CONDITION_DETAILS=$(echo $SQS_POLICY_ALLOW_ALL_WITHOUT_CONDITION \ | jq '"[Principal: " + (.Principal|tostring) + " Action: " + (.Action|tostring) + "]"' ) - textFail "$regx: SQS $queue queue policy with public access: $SQS_POLICY_ALLOW_ALL_WITHOUT_CONDITION_DETAILS" "$regx" "$queue" + textFail "$regx: SQS $queue queue policy with public access" "$regx" "$queue" else textInfo "$regx: SQS $queue queue policy with public access but has a Condition" "$regx" "$queue" fi diff --git a/checks/check_extra731 b/checks/check_extra731 index a22d8492f4..7bb9930073 100644 --- a/checks/check_extra731 +++ b/checks/check_extra731 @@ -39,7 +39,7 @@ extra731(){ if [[ $SNS_POLICY_ALLOW_ALL_WITHOUT_CONDITION ]]; then SNS_POLICY_ALLOW_ALL_WITHOUT_CONDITION_DETAILS=$(echo $SNS_POLICY_ALLOW_ALL_WITHOUT_CONDITION \ | jq '"[Principal: " + (.Principal|tostring) + " Action: " + (.Action|tostring) + "]"' ) - textFail "$regx: SNS topic $SHORT_TOPIC's policy with public access: $SNS_POLICY_ALLOW_ALL_WITHOUT_CONDITION_DETAILS" "$regx" "$SHORT_TOPIC" + textFail "$regx: SNS topic $SHORT_TOPIC's policy with public access" "$regx" "$SHORT_TOPIC" else textPass "$regx: SNS topic $SHORT_TOPIC's policy with public access but has a Condition" "$regx" "$SHORT_TOPIC" fi