uranus.int.autonlab.org daily security run output

punosevac72 at gmail.com punosevac72 at gmail.com
Sat Jul 25 03:01:04 EDT 2015


Checking setuid files and devices:

uranus.int.autonlab.org setuid diffs:
--- /var/log/setuid.today	2015-07-17 23:01:00.000000000 -0400
+++ /tmp/security.GzdOl0jQ	2015-07-25 03:01:03.563292636 -0400
@@ -77,7 +77,7 @@
   487 -r-sr-xr-x  1 root  wheel      28032 May 14 12:52:52 2015 /usr/jails/.warden-template-10.1-RELEASE-amd64/usr/sbin/traceroute
   576 -r-sr-xr-x  1 root  wheel      23592 May 14 12:52:52 2015 /usr/jails/.warden-template-10.1-RELEASE-amd64/usr/sbin/traceroute6
   558 -r-xr-sr-x  1 root  kmem       11144 May 14 12:52:52 2015 /usr/jails/.warden-template-10.1-RELEASE-amd64/usr/sbin/trpt
-  195 -r-xr-sr-x  1 root  smmsp     696232 May 14 12:52:51 2015 /usr/libexec/sendmail/sendmail
+83216 -r-xr-sr-x  1 root  smmsp     692136 Jul 25 00:36:52 2015 /usr/libexec/sendmail/sendmail
   109 -r-sr-xr-x  1 root  wheel      38568 May 14 12:51:54 2015 /usr/libexec/ssh-keysign
   115 -r-sr-xr-x  1 root  wheel       5592 May 14 12:51:19 2015 /usr/libexec/ulog-helper
 71587 -rwsr-xr-x  1 root  wheel      11464 May  4 14:52:42 2015 /usr/local/bin/otp
@@ -92,7 +92,7 @@
   550 -r-sr-sr-x  2 root  authpf     23744 May 14 12:52:37 2015 /usr/sbin/authpf
   550 -r-sr-sr-x  2 root  authpf     23744 May 14 12:52:37 2015 /usr/sbin/authpf-noip
   482 -r-xr-sr-x  1 root  daemon     54656 May 14 12:52:45 2015 /usr/sbin/lpc
-  574 -r-sr-xr--  1 root  network   415680 May 14 12:52:49 2015 /usr/sbin/ppp
+83310 -r-sr-xr--  1 root  network   415648 Jul 25 00:36:53 2015 /usr/sbin/ppp
   549 -r-sr-xr-x  1 root  wheel      20560 May 14 12:52:52 2015 /usr/sbin/timedc
   495 -r-sr-xr-x  1 root  wheel      28032 May 14 12:52:52 2015 /usr/sbin/traceroute
   584 -r-sr-xr-x  1 root  wheel      23592 May 14 12:52:52 2015 /usr/sbin/traceroute6

Checking negative group permissions:

uranus.int.autonlab.org changes in mounted filesystems:
--- /var/log/mount.today	2015-07-02 23:01:02.846722833 -0400
+++ /tmp/security.v1J8K5R7	2015-07-25 03:01:04.102292854 -0400
@@ -1,5 +1,5 @@
 devfs			/dev			devfs	rw,multilabel 	0 0
-tank/ROOT/default	/			zfs	rw,noatime,nfsv4acls 	0 0
+tank/ROOT/10.1-RELEASE-p25-up-20150725_003653 /			zfs	rw,noatime,nfsv4acls 	0 0
 tank/root		/root			zfs	rw,nfsv4acls 	0 0
 tank/tmp		/tmp			zfs	rw,nfsv4acls 	0 0
 tank/usr/home		/usr/home		zfs	rw,nfsv4acls 	0 0

Checking for uids of 0:
root 0
toor 0

Checking for passwordless accounts:

Checking login.conf permissions:

uranus.int.autonlab.org ipfw denied packets:

uranus.int.autonlab.org pf denied packets:
+++ /tmp/security.Y8d5CFb4	2015-07-25 03:01:04.141293818 -0400
+block return in all [ Evaluations: 7774 Packets: 3948 Bytes: 2254328 States: 0 ]
+block return quick from <bruteforce> to any [ Evaluations: 7774 Packets: 0 Bytes: 0 States: 0 ]
+block return in quick on egress proto tcp from <sshguard> to any port = ssh label "ssh bruteforce" [ Evaluations: 7774 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick on ! lo0 inet from 127.0.0.0/8 to any [ Evaluations: 7774 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick from urpf-failed to any [ Evaluations: 7118 Packets: 0 Bytes: 0 States: 0 ]
+block return in on ! lo0 proto tcp from any to any port 6000:6010 [ Evaluations: 7118 Packets: 0 Bytes: 0 States: 0 ]

uranus.int.autonlab.org kernel log messages:
+++ /tmp/security.FteVKM7y	2015-07-25 03:01:04.158293994 -0400
+FreeBSD 10.1-RELEASE-p25 #0: Wed Jul 22 14:54:58 UTC 2015
+    root at amd64-builder.pcbsd.org:/usr/obj/usr/src/sys/GENERIC amd64
+CPU: Intel(R) Xeon(R) CPU E5-2620 v3 @ 2.40GHz (2400.05-MHz K8-class CPU)
+module_register_init: MOD_LOAD (vesa, 0xffffffff80db0430, 0) error 19
+ukbd0: <vendor 0x0557 product 0x2419, class 0/0, rev 1.10/1.00, addr 4> on usbus1
+kbd2 at ukbd0
+run_interrupt_driven_hooks: still waiting after 60 seconds for xpt_config
+da3 at mpr0 bus 0 scbus0 target 11 lun 0
+da0 at mpr0 bus 0 scbus0 target 8 lun 0
+da0: <ATA ST4000NM0024-1HT SN02> Fixed Direct Access SCSI-6 device 
+da0: Serial Number             Z4F03GGV
+da0: 150.000MB/s transfers
+da0: Command Queueing enabled
+da3: <ATA ST4000NM0024-1HT SN02> Fixed Direct Access SCSI-6 device 
+da3: Serial Number             Z4F03GFN
+da3: 150.000MB/s transfers
+da3: Command Queueing enabled
+da3: 3815447MB (7814037168 512 byte sectors: 255H 63S/T 486401C)
+da8 at mpr0 bus 0 scbus0 target 16 lun 0
+da8: <ATA ST4000NM0024-1HT SN02> Fixed Direct Access SCSI-6 device 
+da8: Serial Number             Z4F03GH6
+da8: 150.000MB/s transfers
+da8: Command Queueing enabled
+da8: 3815447MB (7814037168 512 byte sectors: 255H 63S/T 486401C)
+da1: <ATA ST4000NM0024-1HT SN02> Fixed Direct Access SCSI-6 device 
+da1: Serial Number             Z4F03GLQ
+da1: 150.000MB/s transfers
+da1: Command Queueing enabled
+da1: 3815447MB (7814037168 512 byte sectors: 255H 63S/T 486401C)
+da6 at mpr0 bus 0 scbus0 target 14 lun 0
+da9: 150.000MB/s transfers
+da9: Command Queueing enabled
+da9: 3815447MB (7814037168 512 byte sectors: 255H 63S/T 486401C)
+da6: <ATA ST4000NM0024-1HT SN02> Fixed Direct Access SCSI-6 device 
+da6: Serial Number             Z4F03FCL
+da6: 150.000MB/s transfers
+da6: Command Queueing enabled
+da6: 3815447MB (7814037168 512 byte sectors: 255H 63S/T 486401C)
+da11 at mpr0 bus 0 scbus0 target 19 lun 0
+da11: <ATA ST4000NM0024-1HT SN02> Fixed Direct Access SCSI-6 device 
+da11: Serial Number             Z4F03G8E
+da11: 150.000MB/s transfers
+da11: Command Queueing enabled
+da11: 3815447MB (7814037168 512 byte sectors: 255H 63S/T 486401C)
+da10 at mpr0 bus 0 scbus0 target 18 lun 0
+da10: <ATA ST4000NM0024-1HT SN02> Fixed Direct Access SCSI-6 device 
+da10: Serial Number             Z4F03GLZ
+da10: 150.000MB/s transfers
+da10: Command Queueing enabled
+da10: 3815447MB (7814037168 512 byte sectors: 255H 63S/T 486401C)
+da2: <ATA ST4000NM0024-1HT SN02> Fixed Direct Access SCSI-6 device 
+da14 at mpr0 bus 0 scbus0 target 41 lun 0
+da12 at mpr0 bus 0 scbus0 target 39 lun 0
+da16 at mpr0 bus 0 scbus0 target 43 lun 0
+da14: <ATA ST4000NM0024-1HT SN02> Fixed Direct Access SCSI-6 device 
+da14: Serial Number             Z4F03G76
+da12: Serial Number             Z4F03FQ7
+da12: 150.000MB/s transfers
+da12: Command Queueing enabled
+da12: 3815447MB (7814037168 512 byte sectors: 255H 63S/T 486401C)
+da22 at mpr0 bus 0 scbus0 target 49 lun 0
+da13 at mpr0 bus 0 scbus0 target 40 lun 0
+da14: 150.000MB/s transfers
+da14: Command Queueing enabled
+da14: 3815447MB (7814037168 512 byte sectors: 255H 63S/T 486401C)
+da19 at mpr0 bus 0 scbus0 target 46 lun 0
+da16: Serial Number             Z4F03FP4
+da13: <ATA ST4000NM0024-1HT SN02> Fixed Direct Access SCSI-6 device 
+da13: Serial Number             Z4F03F3Z
+da13: 150.000MB/s transfers
+da13: Command Queueing enabled
+da13: 3815447MB (7814037168 512 byte sectors: 255H 63S/T 486401C)
+da16: 150.000MB/s transfers
+da16: Command Queueing enabled
+da16: 3815447MB (7814037168 512 byte sectors: 255H 63S/T 486401C)
+da17 at mpr0 bus 0 scbus0 target 44 lun 0
+da17: <ATA ST4000NM0024-1HT SN02> Fixed Direct Access SCSI-6 device 
+da17: Serial Number             Z4F030AL
+da17: 150.000MB/s transfers
+da17: Command Queueing enabled
+da17: 3815447MB (7814037168 512 byte sectors: 255H 63S/T 486401C)
+da32 at mpr0 bus 0 scbus0 target 59 lun 0
+da32: <ATA ST4000NM0024-1HT SN02> Fixed Direct Access SCSI-6 device 
+da18 at mpr0 bus 0 scbus0 target 45 lun 0
+da18: <ATA ST4000NM0024-1HT SN02> Fixed Direct Access SCSI-6 device 
+da18: Serial Number             Z4F03FYB
+da30 at mpr0 bus 0 scbus0 target 57 lun 0
+da21 at mpr0 bus 0 scbus0 target 48 lun 0
+da21: <ATA ST4000NM0024-1HT SN02> Fixed Direct Access SCSI-6 device 
+da21: Serial Number             Z4F03FYW
+da21: 150.000MB/s transfers
+da21: Command Queueing enabled
+da21: 3815447MB (7814037168 512 byte sectors: 255H 63S/T 486401C)
+da26 at mpr0 bus 0 scbus0 target 53 lun 0
+da34: <ATA ST4000NM0024-1HT SN02> Fixed Direct Access SCSI-6 device 
+da34: Serial Number             Z4F03G5X
+da18: 150.000MB/s transfers
+da18: Command Queueing enabled
+da18: 3815447MB (7814037168 512 byte sectors: 255H 63S/T 486401C)
+da28 at mpr0 bus 0 scbus0 target 55 lun 0
+da28: <ATA ST4000NM0024-1HT SN02> Fixed Direct Access SCSI-6 device 
+da28: Serial Number             Z4F02YYN
+da28: 150.000MB/s transfers
+da28: Command Queueing enabled
+da28: 3815447MB (7814037168 512 byte sectors: 255H 63S/T 486401C)
+da23 at mpr0 bus 0 scbus0 target 50 lun 0
+da23: <ATA ST4000NM0024-1HT SN02> Fixed Direct Access SCSI-6 device 
+da23: Serial Number             Z4F03G6N
+da23: 150.000MB/s transfers
+da23: Command Queueing enabled
+da23: 3815447MB (7814037168 512 byte sectors: 255H 63S/T 486401C)
+da33 at mpr0 bus 0 scbus0 target 60 lun 0
+da30: <ATA ST4000NM0024-1HT SN02> Fixed Direct Access SCSI-6 device 
+da30: Serial Number             Z4F03EXF
+da30: 150.000MB/s transfers
+da30: Command Queueing enabled
+da30: 3815447MB (7814037168 512 byte sectors: 255H 63S/T 486401C)
+da34: 150.000MB/s transfers
+da34: Command Queueing enabled
+da34: 3815447MB (7814037168 512 byte sectors: 255H 63S/T 486401C)
+da35 at mpr0 bus 0 scbus0 target 62 lun 0
+da35: <ATA ST4000NM0024-1HT SN02> Fixed Direct Access SCSI-6 device 
+da35: Serial Number             Z4F03GB9
+da35: 150.000MB/s transfers
+da35: Command Queueing enabled
+da35: 3815447MB (7814037168 512 byte sectors: 255H 63S/T 486401C)
+ada0 at ahcich4 bus 0 scbus6 target 0 lun 0
+SMP: AP CPU #3 Launched!
+SMP: AP CPU #20 Launched!
+SMP: AP CPU #4 Launched!
+SMP: AP CPU #22 Launched!
+SMP: AP CPU #8 Launched!
+SMP: AP CPU #17 Launched!
+SMP: AP CPU #9 Launched!
+SMP: AP CPU #16 Launched!
+SMP: AP CPU #11 Launched!
+SMP: AP CPU #7 Launched!
+SMP: AP CPU #15 Launched!
+SMP: AP CPU #5 Launched!
+SMP: AP CPU #18 Launched!
+SMP: AP CPU #19 Launched!
+Timecounter "TSC-low" frequency 1200026457 Hz quality 1000
+Trying to mount root from zfs:tank/ROOT/10.1-RELEASE-p25-up-20150725_003653 []...
+warning: KLD '/boot/kernel/libiconv.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/libmchain.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/msdosfs_iconv.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/sem.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/linsysfs.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/linux.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/fuse.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/ums.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/pflog.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/pf.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/ipfw.ko' is newer than the linker.hints file

uranus.int.autonlab.org login failures:

uranus.int.autonlab.org refused connections:

Checking for packages with security vulnerabilities:
Database fetched: Fri Jul 24 23:01:21 EDT 2015
libxml2-2.9.2_2
php55-5.5.24
curl-7.42.1
pcre-8.35_2
libressl-2.1.6
php55-gd-5.5.24
ruby-2.0.0.645,1

-- End of security output --


More information about the Autonlab-sysinfo mailing list