neill-backup.int.autonlab.org daily security run output
punosevac72 at gmail.com
punosevac72 at gmail.com
Sat Aug 22 03:41:41 EDT 2015
Checking setuid files and devices:
neill-backup.int.autonlab.org setuid diffs:
--- /var/log/setuid.today 2015-07-18 03:33:32.000000000 -0400
+++ /tmp/security.HHMZ1bIu 2015-08-22 03:20:43.000000000 -0400
@@ -32,7 +32,7 @@
85644450 -r-sr-xr-x 6 root wheel 22640 Nov 11 16:03:31 2014 /usr/bin/ypchpass
85644450 -r-sr-xr-x 6 root wheel 22640 Nov 11 16:03:31 2014 /usr/bin/ypchsh
85644443 -r-sr-xr-x 2 root wheel 8392 Nov 11 16:03:34 2014 /usr/bin/yppasswd
-85733647 -r-xr-sr-x 1 root smmsp 692520 Jan 27 19:12:33 2015 /usr/libexec/sendmail/sendmail
+85733651 -r-xr-sr-x 1 root smmsp 692520 Aug 21 17:51:08 2015 /usr/libexec/sendmail/sendmail
85644406 -r-sr-xr-x 1 root wheel 39040 Nov 11 16:03:22 2014 /usr/libexec/ssh-keysign
85644410 -r-sr-xr-x 1 root wheel 6072 Nov 11 16:03:12 2014 /usr/libexec/ulog-helper
86536329 -r-sr-xr-x 1 root wheel 32632 Oct 3 13:18:25 2014 /usr/local/bin/tcptraceroute
Checking negative group permissions:
Checking for uids of 0:
root 0
toor 0
Checking for passwordless accounts:
Checking login.conf permissions:
neill-backup.int.autonlab.org pf denied packets:
+++ /tmp/security.L32a17KO 2015-08-22 03:41:40.000000000 -0400
+block return in all [ Evaluations: 10012892 Packets: 6608072 Bytes: 3764538018 States: 0 ]
+block return quick from <bruteforce> to any [ Evaluations: 10012898 Packets: 0 Bytes: 0 States: 0 ]
+block return in quick on egress proto tcp from <sshguard> to any port = ssh label "ssh bruteforce" [ Evaluations: 10012899 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick on ! lo0 inet from 127.0.0.0/8 to any [ Evaluations: 10012899 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick from urpf-failed to any [ Evaluations: 9358887 Packets: 0 Bytes: 0 States: 0 ]
+block return in on ! lo0 proto tcp from any to any port 6000:6010 [ Evaluations: 9358887 Packets: 0 Bytes: 0 States: 0 ]
neill-backup.int.autonlab.org login failures:
neill-backup.int.autonlab.org refused connections:
Checking for packages with security vulnerabilities:
Database fetched: Fri Aug 21 04:32:07 EDT 2015
libxml2-2.9.2_2
libidn-1.29
png-1.5.19
curl-7.38.0_2
freetype2-2.5.3_2
pcre-8.35_1
net-snmp-5.7.2_16
jasper-1.900.1_14
libevent2-2.0.21_3
-- End of security output --
More information about the Autonlab-sysinfo
mailing list