From 16154784446e52dc2e49f796b32f81d24e233ae0 Mon Sep 17 00:00:00 2001 From: Toni de la Fuente Date: Wed, 25 Mar 2020 09:40:03 +0100 Subject: [PATCH] Fixed query on extra779 --- checks/check_extra779 | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/checks/check_extra779 b/checks/check_extra779 index 9163cd73..4b8de72d 100644 --- a/checks/check_extra779 +++ b/checks/check_extra779 @@ -23,7 +23,7 @@ extra779(){ for regx in $REGIONS; do # crate a list of SG open to the world with port 9200 or 9300 or 5601 SG_LIST=$($AWSCLI ec2 describe-security-groups $PROFILE_OPT --region $regx --output text \ - --query 'SecurityGroups[?length(IpPermissions[?((FromPort==null && ToPort==null) || (FromPort<=`9200` && ToPort>=`9200`) || (FromPort<=`9300` && ToPort>=`9300`)) || (FromPort<=`5601` && ToPort>=`5601 `) && (contains(IpRanges[].CidrIp, `0.0.0.0/0`) || contains(Ipv6Ranges[].CidrIpv6, `::/0`))]) > `0`].{GroupId:GroupId}') + --query 'SecurityGroups[?length(IpPermissions[?((FromPort==null && ToPort==null) || (FromPort<=`9200` && ToPort>=`9200`) || (FromPort<=`9300` && ToPort>=`9300`) || (FromPort<=`5601` && ToPort>=`5601 `)) && (contains(IpRanges[].CidrIp, `0.0.0.0/0`) || contains(Ipv6Ranges[].CidrIpv6, `::/0`))]) > `0`].{GroupId:GroupId}') # in case of open security groups goes through each one if [[ $SG_LIST ]];then for sg in $SG_LIST;do