uranus.int.autonlab.org daily security run output
punosevac72 at gmail.com
punosevac72 at gmail.com
Sun Aug 23 03:41:57 EDT 2015
Checking setuid files and devices:
uranus.int.autonlab.org setuid diffs:
--- /var/log/setuid.today 2015-07-25 03:01:03.000000000 -0400
+++ /tmp/security.HrxyzGBT 2015-08-23 03:21:58.443525557 -0400
@@ -80,13 +80,13 @@
83216 -r-xr-sr-x 1 root smmsp 692136 Jul 25 00:36:52 2015 /usr/libexec/sendmail/sendmail
109 -r-sr-xr-x 1 root wheel 38568 May 14 12:51:54 2015 /usr/libexec/ssh-keysign
115 -r-sr-xr-x 1 root wheel 5592 May 14 12:51:19 2015 /usr/libexec/ulog-helper
-71587 -rwsr-xr-x 1 root wheel 11464 May 4 14:52:42 2015 /usr/local/bin/otp
+89602 -rwsr-xr-x 1 root wheel 11552 Aug 11 08:50:03 2015 /usr/local/bin/otp
32080 -rwsr-xr-x 1 root wheel 401136 May 5 04:31:14 2015 /usr/local/bin/screen
-71594 -rwsr-xr-x 1 root wheel 15880 May 4 14:52:43 2015 /usr/local/bin/su
+89609 -rwsr-xr-x 1 root wheel 15952 Aug 11 08:50:04 2015 /usr/local/bin/su
32151 -rwsr-xr-x 1 root wheel 103736 May 4 18:20:22 2015 /usr/local/bin/sudo
74818 -r-sr-xr-x 1 root wheel 32616 May 5 23:12:37 2015 /usr/local/bin/tcptraceroute
-77127 -r-xr-sr-x 1 root mail 61240 May 5 08:09:23 2015 /usr/local/libexec/dma
-77128 -r-sr-xr-x 1 root mail 7224 May 5 08:09:23 2015 /usr/local/libexec/dma-mbox-create
+38158 -r-xr-sr-x 1 root mail 61312 Aug 12 01:44:45 2015 /usr/local/libexec/dma
+38159 -r-sr-xr-x 1 root mail 7336 Aug 12 01:44:45 2015 /usr/local/libexec/dma-mbox-create
25043 -rwsr-x--x 1 root wheel 7304 May 4 14:44:01 2015 /usr/local/sbin/jailme
76301 -rwxr-sr-x 1 root kmem 127656 May 4 19:32:43 2015 /usr/local/sbin/lsof
550 -r-sr-sr-x 2 root authpf 23744 May 14 12:52:37 2015 /usr/sbin/authpf
Checking negative group permissions:
17380 -rw-r--r-x 2 1026 1026 301947657 Dec 12 03:26:09 2013 /backups/home/home/dsutherl/experiments/scene/old-ot-divs/feats_pca.h5
17380 -rw-r--r-x 2 1026 1026 301947657 Dec 12 03:26:09 2013 /backups/home/home/dsutherl/experiments/scene/old-ot-divs/feats_pca.mat
uranus.int.autonlab.org changes in mounted filesystems:
--- /var/log/mount.today 2015-08-22 04:07:47.000000000 -0400
+++ /tmp/security.RA94cF5K 2015-08-23 03:41:57.259443315 -0400
@@ -5,16 +5,6 @@
backups/data/zdata /backups/data/zdata zfs rw,noatime,nfsv4acls 0 0
backups/home /backups/home zfs rw,nfsv4acls 0 0
backups/home/home /backups/home/home zfs rw,noatime,nfsv4acls 0 0
-backups/home/home at auto-20150807.1600-2w /backups/home/home/.zfs/snapshot/auto-20150807.1600-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
-backups/home/home at auto-20150807.1700-2w /backups/home/home/.zfs/snapshot/auto-20150807.1700-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
-backups/home/home at auto-20150807.1800-2w /backups/home/home/.zfs/snapshot/auto-20150807.1800-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
-backups/home/home at auto-20150808.0900-2w /backups/home/home/.zfs/snapshot/auto-20150808.0900-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
-backups/home/home at auto-20150808.1000-2w /backups/home/home/.zfs/snapshot/auto-20150808.1000-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
-backups/home/home at auto-20150808.1100-2w /backups/home/home/.zfs/snapshot/auto-20150808.1100-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
-backups/home/home at auto-20150808.1200-2w /backups/home/home/.zfs/snapshot/auto-20150808.1200-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
-backups/home/home at auto-20150808.1300-2w /backups/home/home/.zfs/snapshot/auto-20150808.1300-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
-backups/home/home at auto-20150808.1400-2w /backups/home/home/.zfs/snapshot/auto-20150808.1400-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
-backups/home/home at auto-20150808.1500-2w /backups/home/home/.zfs/snapshot/auto-20150808.1500-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
backups/home/home at auto-20150808.1600-2w /backups/home/home/.zfs/snapshot/auto-20150808.1600-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
backups/home/home at auto-20150808.1700-2w /backups/home/home/.zfs/snapshot/auto-20150808.1700-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
backups/home/home at auto-20150808.1800-2w /backups/home/home/.zfs/snapshot/auto-20150808.1800-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
@@ -125,6 +115,16 @@
backups/home/home at auto-20150821.1300-2w /backups/home/home/.zfs/snapshot/auto-20150821.1300-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
backups/home/home at auto-20150821.1400-2w /backups/home/home/.zfs/snapshot/auto-20150821.1400-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
backups/home/home at auto-20150821.1500-2w /backups/home/home/.zfs/snapshot/auto-20150821.1500-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
+backups/home/home at auto-20150821.1600-2w /backups/home/home/.zfs/snapshot/auto-20150821.1600-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
+backups/home/home at auto-20150821.1700-2w /backups/home/home/.zfs/snapshot/auto-20150821.1700-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
+backups/home/home at auto-20150821.1800-2w /backups/home/home/.zfs/snapshot/auto-20150821.1800-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
+backups/home/home at auto-20150822.0900-2w /backups/home/home/.zfs/snapshot/auto-20150822.0900-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
+backups/home/home at auto-20150822.1000-2w /backups/home/home/.zfs/snapshot/auto-20150822.1000-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
+backups/home/home at auto-20150822.1100-2w /backups/home/home/.zfs/snapshot/auto-20150822.1100-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
+backups/home/home at auto-20150822.1200-2w /backups/home/home/.zfs/snapshot/auto-20150822.1200-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
+backups/home/home at auto-20150822.1300-2w /backups/home/home/.zfs/snapshot/auto-20150822.1300-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
+backups/home/home at auto-20150822.1400-2w /backups/home/home/.zfs/snapshot/auto-20150822.1400-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
+backups/home/home at auto-20150822.1500-2w /backups/home/home/.zfs/snapshot/auto-20150822.1500-2w zfs ro,nosuid,noatime,nfsv4acls 0 0
backups/project /backups/project zfs rw,nfsv4acls 0 0
backups/project/project /backups/project/project zfs rw,noatime,nfsv4acls 0 0
data0 /data0 zfs rw,nfsv4acls 0 0
Checking for uids of 0:
root 0
toor 0
Checking for passwordless accounts:
Checking login.conf permissions:
uranus.int.autonlab.org pf denied packets:
+++ /tmp/security.NCuWAqVw 2015-08-23 03:41:57.308443317 -0400
+block return in all [ Evaluations: 17023 Packets: 5971 Bytes: 3401588 States: 0 ]
+block return quick from <bruteforce> to any [ Evaluations: 17023 Packets: 0 Bytes: 0 States: 0 ]
+block return in quick on egress proto tcp from <sshguard> to any port = ssh label "ssh bruteforce" [ Evaluations: 17023 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick on ! lo0 inet from 127.0.0.0/8 to any [ Evaluations: 17023 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick from urpf-failed to any [ Evaluations: 15982 Packets: 0 Bytes: 0 States: 0 ]
+block return in on ! lo0 proto tcp from any to any port 6000:6010 [ Evaluations: 15982 Packets: 0 Bytes: 0 States: 0 ]
uranus.int.autonlab.org login failures:
Aug 22 23:01:42 uranus sshd[61187]: nss_ldap: failed to bind to LDAP server ldap://127.0.0.1: Can't contact LDAP server
Aug 22 23:01:42 uranus sshd[61187]: nss_ldap: failed to bind to LDAP server ldap://127.0.0.1: Can't contact LDAP server
Aug 22 23:01:46 uranus sshd[61187]: nss_ldap: failed to bind to LDAP server ldap://127.0.0.1: Can't contact LDAP server
Aug 22 23:01:54 uranus sshd[61187]: nss_ldap: failed to bind to LDAP server ldap://127.0.0.1: Can't contact LDAP server
Aug 22 23:02:10 uranus sshd[61187]: nss_ldap: failed to bind to LDAP server ldap://127.0.0.1: Can't contact LDAP server
Aug 22 23:02:42 uranus sshd[61187]: nss_ldap: failed to bind to LDAP server ldap://127.0.0.1: Can't contact LDAP server
uranus.int.autonlab.org refused connections:
Checking for packages with security vulnerabilities:
Database fetched: Sat Aug 22 04:07:48 EDT 2015
libxml2-2.9.2_2
libidn-1.29
php55-5.5.24
pcre-8.35_2
php55-gd-5.5.24
ruby-2.0.0.645,1
-- End of security output --
More information about the Autonlab-sysinfo
mailing list