uranus.int.autonlab.org daily security run output
punosevac72 at gmail.com
punosevac72 at gmail.com
Fri Aug 21 03:41:37 EDT 2015
Checking setuid files and devices:
Checking negative group permissions:
17380 -rw-r--r-x 2 1026 1026 301947657 Dec 12 03:26:09 2013 /backups/home/home/dsutherl/experiments/scene/old-ot-divs/feats_pca.h5
17380 -rw-r--r-x 2 1026 1026 301947657 Dec 12 03:26:09 2013 /backups/home/home/dsutherl/experiments/scene/old-ot-divs/feats_pca.mat
uranus.int.autonlab.org changes in mounted filesystems:
--- /var/log/mount.today 2015-08-20 03:42:02.000000000 -0400
+++ /tmp/security.wmJH0OEq 2015-08-21 03:41:37.054354297 -0400
@@ -5,16 +5,6 @@
backups/data/zdata /backups/data/zdata zfs rw,noatime,nfsv4acls 0 0
backups/home /backups/home zfs rw,nfsv4acls 0 0
backups/home/home /backups/home/home zfs rw,noatime,nfsv4acls 0 0
-backups/home/home at auto-20150805.1600-2w /backups/home/home/.zfs/snapshot/auto-20150805.1600-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
-backups/home/home at auto-20150805.1700-2w /backups/home/home/.zfs/snapshot/auto-20150805.1700-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
-backups/home/home at auto-20150805.1800-2w /backups/home/home/.zfs/snapshot/auto-20150805.1800-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
-backups/home/home at auto-20150806.0900-2w /backups/home/home/.zfs/snapshot/auto-20150806.0900-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
-backups/home/home at auto-20150806.1000-2w /backups/home/home/.zfs/snapshot/auto-20150806.1000-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
-backups/home/home at auto-20150806.1100-2w /backups/home/home/.zfs/snapshot/auto-20150806.1100-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
-backups/home/home at auto-20150806.1200-2w /backups/home/home/.zfs/snapshot/auto-20150806.1200-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
-backups/home/home at auto-20150806.1300-2w /backups/home/home/.zfs/snapshot/auto-20150806.1300-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
-backups/home/home at auto-20150806.1400-2w /backups/home/home/.zfs/snapshot/auto-20150806.1400-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
-backups/home/home at auto-20150806.1500-2w /backups/home/home/.zfs/snapshot/auto-20150806.1500-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
backups/home/home at auto-20150806.1600-2w /backups/home/home/.zfs/snapshot/auto-20150806.1600-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
backups/home/home at auto-20150806.1700-2w /backups/home/home/.zfs/snapshot/auto-20150806.1700-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
backups/home/home at auto-20150806.1800-2w /backups/home/home/.zfs/snapshot/auto-20150806.1800-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
@@ -125,6 +115,16 @@
backups/home/home at auto-20150819.1300-2w /backups/home/home/.zfs/snapshot/auto-20150819.1300-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
backups/home/home at auto-20150819.1400-2w /backups/home/home/.zfs/snapshot/auto-20150819.1400-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
backups/home/home at auto-20150819.1500-2w /backups/home/home/.zfs/snapshot/auto-20150819.1500-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
+backups/home/home at auto-20150819.1600-2w /backups/home/home/.zfs/snapshot/auto-20150819.1600-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
+backups/home/home at auto-20150819.1700-2w /backups/home/home/.zfs/snapshot/auto-20150819.1700-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
+backups/home/home at auto-20150819.1800-2w /backups/home/home/.zfs/snapshot/auto-20150819.1800-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
+backups/home/home at auto-20150820.0900-2w /backups/home/home/.zfs/snapshot/auto-20150820.0900-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
+backups/home/home at auto-20150820.1000-2w /backups/home/home/.zfs/snapshot/auto-20150820.1000-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
+backups/home/home at auto-20150820.1100-2w /backups/home/home/.zfs/snapshot/auto-20150820.1100-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
+backups/home/home at auto-20150820.1200-2w /backups/home/home/.zfs/snapshot/auto-20150820.1200-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
+backups/home/home at auto-20150820.1300-2w /backups/home/home/.zfs/snapshot/auto-20150820.1300-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
+backups/home/home at auto-20150820.1400-2w /backups/home/home/.zfs/snapshot/auto-20150820.1400-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
+backups/home/home at auto-20150820.1500-2w /backups/home/home/.zfs/snapshot/auto-20150820.1500-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
backups/project /backups/project zfs rw,nfsv4acls 0 0
backups/project/project /backups/project/project zfs rw,noatime,nfsv4acls 0 0
data0 /data0 zfs rw,nfsv4acls 0 0
Checking for uids of 0:
root 0
toor 0
Checking for passwordless accounts:
Checking login.conf permissions:
uranus.int.autonlab.org pf denied packets:
+++ /tmp/security.axJtYP3U 2015-08-21 03:41:37.094354405 -0400
+block return in all [ Evaluations: 2850373 Packets: 1092999 Bytes: 623309474 States: 0 ]
+block return quick from <bruteforce> to any [ Evaluations: 2850378 Packets: 0 Bytes: 0 States: 0 ]
+block return in quick on egress proto tcp from <sshguard> to any port = ssh label "ssh bruteforce" [ Evaluations: 2850373 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick on ! lo0 inet from 127.0.0.0/8 to any [ Evaluations: 2850375 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick from urpf-failed to any [ Evaluations: 2667808 Packets: 0 Bytes: 0 States: 0 ]
+block return in on ! lo0 proto tcp from any to any port 6000:6010 [ Evaluations: 2667817 Packets: 0 Bytes: 0 States: 0 ]
uranus.int.autonlab.org kernel log messages:
+++ /tmp/security.maXP5SC3 2015-08-21 03:41:37.110353803 -0400
uranus.int.autonlab.org login failures:
Aug 20 15:39:12 uranus sshd[24611]: Invalid user suppe from 192.168.6.11
Aug 20 15:39:12 uranus sshd[24611]: input_userauth_request: invalid user suppe [preauth]
Aug 20 15:39:12 uranus sshd[24611]: Postponed keyboard-interactive for invalid user suppe from 192.168.6.11 port 44667 ssh2 [preauth]
Aug 20 15:39:16 uranus sshd[24611]: error: PAM: authentication error for illegal user suppe from ari.int.autonlab.org
Aug 20 15:39:16 uranus sshd[24611]: Failed keyboard-interactive/pam for invalid user suppe from 192.168.6.11 port 44667 ssh2
Aug 20 15:39:16 uranus sshd[24611]: Postponed keyboard-interactive for invalid user suppe from 192.168.6.11 port 44667 ssh2 [preauth]
Aug 20 15:39:23 uranus sshd[24611]: error: PAM: authentication error for illegal user suppe from ari.int.autonlab.org
Aug 20 15:39:23 uranus sshd[24611]: Failed keyboard-interactive/pam for invalid user suppe from 192.168.6.11 port 44667 ssh2
Aug 20 15:39:23 uranus sshd[24611]: Postponed keyboard-interactive for invalid user suppe from 192.168.6.11 port 44667 ssh2 [preauth]
Aug 20 15:39:24 uranus sshd[24611]: error: PAM: authentication error for illegal user suppe from ari.int.autonlab.org
Aug 20 15:39:24 uranus sshd[24611]: Failed keyboard-interactive/pam for invalid user suppe from 192.168.6.11 port 44667 ssh2
uranus.int.autonlab.org refused connections:
Checking for packages with security vulnerabilities:
Database fetched: Thu Aug 20 03:42:03 EDT 2015
libxml2-2.9.2_2
libidn-1.29
php55-5.5.24
curl-7.42.1
pcre-8.35_2
net-snmp-5.7.3_7
libressl-2.1.6
php55-gd-5.5.24
ruby-2.0.0.645,1
-- End of security output --
More information about the Autonlab-sysinfo
mailing list