uranus.int.autonlab.org daily security run output

punosevac72 at gmail.com punosevac72 at gmail.com
Wed Aug 19 03:41:41 EDT 2015


Checking setuid files and devices:

Checking negative group permissions:
17380 -rw-r--r-x  2 1026  1026  301947657 Dec 12 03:26:09 2013 /backups/home/home/dsutherl/experiments/scene/old-ot-divs/feats_pca.h5
17380 -rw-r--r-x  2 1026  1026  301947657 Dec 12 03:26:09 2013 /backups/home/home/dsutherl/experiments/scene/old-ot-divs/feats_pca.mat

uranus.int.autonlab.org changes in mounted filesystems:
--- /var/log/mount.today	2015-08-18 03:41:48.000000000 -0400
+++ /tmp/security.au0RjJmT	2015-08-19 03:41:41.132263192 -0400
@@ -5,16 +5,6 @@
 backups/data/zdata	/backups/data/zdata	zfs	rw,noatime,nfsv4acls 	0 0
 backups/home		/backups/home		zfs	rw,nfsv4acls 	0 0
 backups/home/home	/backups/home/home	zfs	rw,noatime,nfsv4acls 	0 0
-backups/home/home at auto-20150803.1600-2w /backups/home/home/.zfs/snapshot/auto-20150803.1600-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
-backups/home/home at auto-20150803.1700-2w /backups/home/home/.zfs/snapshot/auto-20150803.1700-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
-backups/home/home at auto-20150803.1800-2w /backups/home/home/.zfs/snapshot/auto-20150803.1800-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
-backups/home/home at auto-20150804.0900-2w /backups/home/home/.zfs/snapshot/auto-20150804.0900-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
-backups/home/home at auto-20150804.1000-2w /backups/home/home/.zfs/snapshot/auto-20150804.1000-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
-backups/home/home at auto-20150804.1100-2w /backups/home/home/.zfs/snapshot/auto-20150804.1100-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
-backups/home/home at auto-20150804.1200-2w /backups/home/home/.zfs/snapshot/auto-20150804.1200-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
-backups/home/home at auto-20150804.1300-2w /backups/home/home/.zfs/snapshot/auto-20150804.1300-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
-backups/home/home at auto-20150804.1400-2w /backups/home/home/.zfs/snapshot/auto-20150804.1400-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
-backups/home/home at auto-20150804.1500-2w /backups/home/home/.zfs/snapshot/auto-20150804.1500-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
 backups/home/home at auto-20150804.1600-2w /backups/home/home/.zfs/snapshot/auto-20150804.1600-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
 backups/home/home at auto-20150804.1700-2w /backups/home/home/.zfs/snapshot/auto-20150804.1700-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
 backups/home/home at auto-20150804.1800-2w /backups/home/home/.zfs/snapshot/auto-20150804.1800-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
@@ -125,6 +115,16 @@
 backups/home/home at auto-20150817.1300-2w /backups/home/home/.zfs/snapshot/auto-20150817.1300-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
 backups/home/home at auto-20150817.1400-2w /backups/home/home/.zfs/snapshot/auto-20150817.1400-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
 backups/home/home at auto-20150817.1500-2w /backups/home/home/.zfs/snapshot/auto-20150817.1500-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
+backups/home/home at auto-20150817.1600-2w /backups/home/home/.zfs/snapshot/auto-20150817.1600-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
+backups/home/home at auto-20150817.1700-2w /backups/home/home/.zfs/snapshot/auto-20150817.1700-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
+backups/home/home at auto-20150817.1800-2w /backups/home/home/.zfs/snapshot/auto-20150817.1800-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
+backups/home/home at auto-20150818.0900-2w /backups/home/home/.zfs/snapshot/auto-20150818.0900-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
+backups/home/home at auto-20150818.1000-2w /backups/home/home/.zfs/snapshot/auto-20150818.1000-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
+backups/home/home at auto-20150818.1100-2w /backups/home/home/.zfs/snapshot/auto-20150818.1100-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
+backups/home/home at auto-20150818.1200-2w /backups/home/home/.zfs/snapshot/auto-20150818.1200-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
+backups/home/home at auto-20150818.1300-2w /backups/home/home/.zfs/snapshot/auto-20150818.1300-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
+backups/home/home at auto-20150818.1400-2w /backups/home/home/.zfs/snapshot/auto-20150818.1400-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
+backups/home/home at auto-20150818.1500-2w /backups/home/home/.zfs/snapshot/auto-20150818.1500-2w zfs	ro,nosuid,noatime,nfsv4acls 	0 0
 backups/project		/backups/project	zfs	rw,nfsv4acls 	0 0
 backups/project/project	/backups/project/project zfs	rw,noatime,nfsv4acls 	0 0
 data0			/data0			zfs	rw,nfsv4acls 	0 0

Checking for uids of 0:
root 0
toor 0

Checking for passwordless accounts:

Checking login.conf permissions:

uranus.int.autonlab.org pf denied packets:
+++ /tmp/security.3T1gSDm3	2015-08-19 03:41:41.173262541 -0400
+block return in all [ Evaluations: 2622336 Packets: 1012523 Bytes: 577397098 States: 0 ]
+block return quick from <bruteforce> to any [ Evaluations: 2622341 Packets: 0 Bytes: 0 States: 0 ]
+block return in quick on egress proto tcp from <sshguard> to any port = ssh label "ssh bruteforce" [ Evaluations: 2622336 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick on ! lo0 inet from 127.0.0.0/8 to any [ Evaluations: 2622338 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick from urpf-failed to any [ Evaluations: 2455085 Packets: 0 Bytes: 0 States: 0 ]
+block return in on ! lo0 proto tcp from any to any port 6000:6010 [ Evaluations: 2455094 Packets: 0 Bytes: 0 States: 0 ]

uranus.int.autonlab.org login failures:

uranus.int.autonlab.org refused connections:

Checking for packages with security vulnerabilities:
Database fetched: Tue Aug 18 03:41:52 EDT 2015
libxml2-2.9.2_2
libidn-1.29
php55-5.5.24
curl-7.42.1
pcre-8.35_2
net-snmp-5.7.3_7
libressl-2.1.6
php55-gd-5.5.24
ruby-2.0.0.645,1

-- End of security output --


More information about the Autonlab-sysinfo mailing list