bhyve.int.autonlab.org daily security run output

punosevac72 at gmail.com punosevac72 at gmail.com
Sat Jul 25 03:02:13 EDT 2015


Checking setuid files and devices:

bhyve.int.autonlab.org setuid diffs:
--- /var/log/setuid.today	2015-07-24 23:01:11.000000000 -0400
+++ /tmp/security.aR9fWBnP	2015-07-25 03:01:38.155257316 -0400
@@ -77,7 +77,7 @@
   487 -r-sr-xr-x  1 root  wheel      28032 May 14 12:52:52 2015 /usr/jails/.warden-template-10.1-RELEASE-amd64/usr/sbin/traceroute
   576 -r-sr-xr-x  1 root  wheel      23592 May 14 12:52:52 2015 /usr/jails/.warden-template-10.1-RELEASE-amd64/usr/sbin/traceroute6
   558 -r-xr-sr-x  1 root  kmem       11144 May 14 12:52:52 2015 /usr/jails/.warden-template-10.1-RELEASE-amd64/usr/sbin/trpt
-  195 -r-xr-sr-x  1 root  smmsp     696232 May 14 12:52:51 2015 /usr/libexec/sendmail/sendmail
+79772 -r-xr-sr-x  1 root  smmsp     692136 Jul 25 00:27:28 2015 /usr/libexec/sendmail/sendmail
   109 -r-sr-xr-x  1 root  wheel      38568 May 14 12:51:54 2015 /usr/libexec/ssh-keysign
   115 -r-sr-xr-x  1 root  wheel       5592 May 14 12:51:19 2015 /usr/libexec/ulog-helper
 70138 -rwsr-xr-x  1 root  wheel      11464 May  4 14:52:42 2015 /usr/local/bin/otp
@@ -92,7 +92,7 @@
   550 -r-sr-sr-x  2 root  authpf     23744 May 14 12:52:37 2015 /usr/sbin/authpf
   550 -r-sr-sr-x  2 root  authpf     23744 May 14 12:52:37 2015 /usr/sbin/authpf-noip
   482 -r-xr-sr-x  1 root  daemon     54656 May 14 12:52:45 2015 /usr/sbin/lpc
-  574 -r-sr-xr--  1 root  network   415680 May 14 12:52:49 2015 /usr/sbin/ppp
+79866 -r-sr-xr--  1 root  network   415648 Jul 25 00:27:28 2015 /usr/sbin/ppp
   549 -r-sr-xr-x  1 root  wheel      20560 May 14 12:52:52 2015 /usr/sbin/timedc
   495 -r-sr-xr-x  1 root  wheel      28032 May 14 12:52:52 2015 /usr/sbin/traceroute
   584 -r-sr-xr-x  1 root  wheel      23592 May 14 12:52:52 2015 /usr/sbin/traceroute6

Checking negative group permissions:

bhyve.int.autonlab.org changes in mounted filesystems:
--- /var/log/mount.today	2015-07-02 23:01:21.638612433 -0400
+++ /tmp/security.5AiWq4UN	2015-07-25 03:02:13.355255105 -0400
@@ -1,5 +1,5 @@
 devfs			/dev			devfs	rw,multilabel 	0 0
-tank1/ROOT/default	/			zfs	rw,noatime,nfsv4acls 	0 0
+tank1/ROOT/10.1-RELEASE-p25-up-20150725_002729 /			zfs	rw,noatime,nfsv4acls 	0 0
 tank1/root		/root			zfs	rw,nfsv4acls 	0 0
 tank1/tmp		/tmp			zfs	rw,nfsv4acls 	0 0
 tank1/usr/home		/usr/home		zfs	rw,nfsv4acls 	0 0

Checking for uids of 0:
root 0
toor 0

Checking for passwordless accounts:

Checking login.conf permissions:

bhyve.int.autonlab.org ipfw denied packets:

bhyve.int.autonlab.org pf denied packets:
+++ /tmp/security.hPGfPHN1	2015-07-25 03:02:13.488256705 -0400
+block return in all [ Evaluations: 7306 Packets: 4261 Bytes: 2428060 States: 0 ]
+block return quick from <bruteforce> to any [ Evaluations: 7306 Packets: 0 Bytes: 0 States: 0 ]
+block return in quick on egress proto tcp from <sshguard> to any port = ssh label "ssh bruteforce" [ Evaluations: 7306 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick on ! lo0 inet from 127.0.0.0/8 to any [ Evaluations: 7306 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick from urpf-failed to any [ Evaluations: 6408 Packets: 0 Bytes: 0 States: 0 ]
+block return in on ! lo0 proto tcp from any to any port 6000:6010 [ Evaluations: 6408 Packets: 0 Bytes: 0 States: 0 ]

bhyve.int.autonlab.org kernel log messages:
+++ /tmp/security.Ow8vYo7E	2015-07-25 03:02:13.523255998 -0400
+FreeBSD 10.1-RELEASE-p25 #0: Wed Jul 22 14:54:58 UTC 2015
+    root at amd64-builder.pcbsd.org:/usr/obj/usr/src/sys/GENERIC amd64
+module_register_init: MOD_LOAD (vesa, 0xffffffff80db0430, 0) error 19
+SMP: AP CPU #3 Launched!
+SMP: AP CPU #5 Launched!
+SMP: AP CPU #7 Launched!
+Timecounter "TSC-low" frequency 1200028332 Hz quality 1000
+Root mount waiting for: usbus1
+ukbd0: <vendor 0x0557 product 0x2419, class 0/0, rev 1.10/1.00, addr 4> on usbus1
+kbd2 at ukbd0
+Trying to mount root from zfs:tank1/ROOT/10.1-RELEASE-p25-up-20150725_002729 []...
+warning: KLD '/boot/kernel/libiconv.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/libmchain.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/msdosfs_iconv.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/sem.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/linsysfs.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/linux.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/fuse.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/ums.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/pflog.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/pf.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/ipfw.ko' is newer than the linker.hints file

bhyve.int.autonlab.org login failures:

bhyve.int.autonlab.org refused connections:

Checking for packages with security vulnerabilities:
Database fetched: Sat Jul 25 00:15:15 EDT 2015
libxml2-2.9.2_2
php55-5.5.24
curl-7.42.1
pcre-8.35_2
libressl-2.1.6
php55-gd-5.5.24
ruby-2.0.0.645,1

-- End of security output --


More information about the Autonlab-sysinfo mailing list