bhyve.int.autonlab.org daily security run output
punosevac72 at gmail.com
punosevac72 at gmail.com
Sat Jul 25 03:02:13 EDT 2015
Checking setuid files and devices:
bhyve.int.autonlab.org setuid diffs:
--- /var/log/setuid.today 2015-07-24 23:01:11.000000000 -0400
+++ /tmp/security.aR9fWBnP 2015-07-25 03:01:38.155257316 -0400
@@ -77,7 +77,7 @@
487 -r-sr-xr-x 1 root wheel 28032 May 14 12:52:52 2015 /usr/jails/.warden-template-10.1-RELEASE-amd64/usr/sbin/traceroute
576 -r-sr-xr-x 1 root wheel 23592 May 14 12:52:52 2015 /usr/jails/.warden-template-10.1-RELEASE-amd64/usr/sbin/traceroute6
558 -r-xr-sr-x 1 root kmem 11144 May 14 12:52:52 2015 /usr/jails/.warden-template-10.1-RELEASE-amd64/usr/sbin/trpt
- 195 -r-xr-sr-x 1 root smmsp 696232 May 14 12:52:51 2015 /usr/libexec/sendmail/sendmail
+79772 -r-xr-sr-x 1 root smmsp 692136 Jul 25 00:27:28 2015 /usr/libexec/sendmail/sendmail
109 -r-sr-xr-x 1 root wheel 38568 May 14 12:51:54 2015 /usr/libexec/ssh-keysign
115 -r-sr-xr-x 1 root wheel 5592 May 14 12:51:19 2015 /usr/libexec/ulog-helper
70138 -rwsr-xr-x 1 root wheel 11464 May 4 14:52:42 2015 /usr/local/bin/otp
@@ -92,7 +92,7 @@
550 -r-sr-sr-x 2 root authpf 23744 May 14 12:52:37 2015 /usr/sbin/authpf
550 -r-sr-sr-x 2 root authpf 23744 May 14 12:52:37 2015 /usr/sbin/authpf-noip
482 -r-xr-sr-x 1 root daemon 54656 May 14 12:52:45 2015 /usr/sbin/lpc
- 574 -r-sr-xr-- 1 root network 415680 May 14 12:52:49 2015 /usr/sbin/ppp
+79866 -r-sr-xr-- 1 root network 415648 Jul 25 00:27:28 2015 /usr/sbin/ppp
549 -r-sr-xr-x 1 root wheel 20560 May 14 12:52:52 2015 /usr/sbin/timedc
495 -r-sr-xr-x 1 root wheel 28032 May 14 12:52:52 2015 /usr/sbin/traceroute
584 -r-sr-xr-x 1 root wheel 23592 May 14 12:52:52 2015 /usr/sbin/traceroute6
Checking negative group permissions:
bhyve.int.autonlab.org changes in mounted filesystems:
--- /var/log/mount.today 2015-07-02 23:01:21.638612433 -0400
+++ /tmp/security.5AiWq4UN 2015-07-25 03:02:13.355255105 -0400
@@ -1,5 +1,5 @@
devfs /dev devfs rw,multilabel 0 0
-tank1/ROOT/default / zfs rw,noatime,nfsv4acls 0 0
+tank1/ROOT/10.1-RELEASE-p25-up-20150725_002729 / zfs rw,noatime,nfsv4acls 0 0
tank1/root /root zfs rw,nfsv4acls 0 0
tank1/tmp /tmp zfs rw,nfsv4acls 0 0
tank1/usr/home /usr/home zfs rw,nfsv4acls 0 0
Checking for uids of 0:
root 0
toor 0
Checking for passwordless accounts:
Checking login.conf permissions:
bhyve.int.autonlab.org ipfw denied packets:
bhyve.int.autonlab.org pf denied packets:
+++ /tmp/security.hPGfPHN1 2015-07-25 03:02:13.488256705 -0400
+block return in all [ Evaluations: 7306 Packets: 4261 Bytes: 2428060 States: 0 ]
+block return quick from <bruteforce> to any [ Evaluations: 7306 Packets: 0 Bytes: 0 States: 0 ]
+block return in quick on egress proto tcp from <sshguard> to any port = ssh label "ssh bruteforce" [ Evaluations: 7306 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick on ! lo0 inet from 127.0.0.0/8 to any [ Evaluations: 7306 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick from urpf-failed to any [ Evaluations: 6408 Packets: 0 Bytes: 0 States: 0 ]
+block return in on ! lo0 proto tcp from any to any port 6000:6010 [ Evaluations: 6408 Packets: 0 Bytes: 0 States: 0 ]
bhyve.int.autonlab.org kernel log messages:
+++ /tmp/security.Ow8vYo7E 2015-07-25 03:02:13.523255998 -0400
+FreeBSD 10.1-RELEASE-p25 #0: Wed Jul 22 14:54:58 UTC 2015
+ root at amd64-builder.pcbsd.org:/usr/obj/usr/src/sys/GENERIC amd64
+module_register_init: MOD_LOAD (vesa, 0xffffffff80db0430, 0) error 19
+SMP: AP CPU #3 Launched!
+SMP: AP CPU #5 Launched!
+SMP: AP CPU #7 Launched!
+Timecounter "TSC-low" frequency 1200028332 Hz quality 1000
+Root mount waiting for: usbus1
+ukbd0: <vendor 0x0557 product 0x2419, class 0/0, rev 1.10/1.00, addr 4> on usbus1
+kbd2 at ukbd0
+Trying to mount root from zfs:tank1/ROOT/10.1-RELEASE-p25-up-20150725_002729 []...
+warning: KLD '/boot/kernel/libiconv.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/libmchain.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/msdosfs_iconv.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/sem.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/linsysfs.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/linux.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/fuse.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/ums.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/pflog.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/pf.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/ipfw.ko' is newer than the linker.hints file
bhyve.int.autonlab.org login failures:
bhyve.int.autonlab.org refused connections:
Checking for packages with security vulnerabilities:
Database fetched: Sat Jul 25 00:15:15 EDT 2015
libxml2-2.9.2_2
php55-5.5.24
curl-7.42.1
pcre-8.35_2
libressl-2.1.6
php55-gd-5.5.24
ruby-2.0.0.645,1
-- End of security output --
More information about the Autonlab-sysinfo
mailing list