warden.int.autonlab.org daily security run output
punosevac72 at gmail.com
punosevac72 at gmail.com
Sat Jul 25 03:14:14 EDT 2015
Checking setuid files and devices:
warden.int.autonlab.org setuid diffs:
--- /var/log/setuid.today 2015-07-24 23:01:07.000000000 -0400
+++ /tmp/security.bBubIxyV 2015-07-25 03:07:40.262452810 -0400
@@ -77,7 +77,7 @@
487 -r-sr-xr-x 1 root wheel 28032 May 14 12:52:52 2015 /usr/jails/.warden-template-10.1-RELEASE-amd64/usr/sbin/traceroute
576 -r-sr-xr-x 1 root wheel 23592 May 14 12:52:52 2015 /usr/jails/.warden-template-10.1-RELEASE-amd64/usr/sbin/traceroute6
558 -r-xr-sr-x 1 root kmem 11144 May 14 12:52:52 2015 /usr/jails/.warden-template-10.1-RELEASE-amd64/usr/sbin/trpt
- 195 -r-xr-sr-x 1 root smmsp 696232 May 14 12:52:51 2015 /usr/libexec/sendmail/sendmail
+79767 -r-xr-sr-x 1 root smmsp 692136 Jul 25 00:28:34 2015 /usr/libexec/sendmail/sendmail
109 -r-sr-xr-x 1 root wheel 38568 May 14 12:51:54 2015 /usr/libexec/ssh-keysign
115 -r-sr-xr-x 1 root wheel 5592 May 14 12:51:19 2015 /usr/libexec/ulog-helper
70123 -rwsr-xr-x 1 root wheel 11464 May 4 14:52:42 2015 /usr/local/bin/otp
@@ -92,7 +92,7 @@
550 -r-sr-sr-x 2 root authpf 23744 May 14 12:52:37 2015 /usr/sbin/authpf
550 -r-sr-sr-x 2 root authpf 23744 May 14 12:52:37 2015 /usr/sbin/authpf-noip
482 -r-xr-sr-x 1 root daemon 54656 May 14 12:52:45 2015 /usr/sbin/lpc
- 574 -r-sr-xr-- 1 root network 415680 May 14 12:52:49 2015 /usr/sbin/ppp
+79861 -r-sr-xr-- 1 root network 415648 Jul 25 00:28:35 2015 /usr/sbin/ppp
549 -r-sr-xr-x 1 root wheel 20560 May 14 12:52:52 2015 /usr/sbin/timedc
495 -r-sr-xr-x 1 root wheel 28032 May 14 12:52:52 2015 /usr/sbin/traceroute
584 -r-sr-xr-x 1 root wheel 23592 May 14 12:52:52 2015 /usr/sbin/traceroute6
Checking negative group permissions:
warden.int.autonlab.org changes in mounted filesystems:
--- /var/log/mount.today 2015-07-02 23:01:19.064240549 -0400
+++ /tmp/security.pHa7iEcK 2015-07-25 03:14:13.237424468 -0400
@@ -1,5 +1,5 @@
devfs /dev devfs rw,multilabel 0 0
-tank/ROOT/default / zfs rw,noatime,nfsv4acls 0 0
+tank/ROOT/10.1-RELEASE-p25-up-20150725_002836 / zfs rw,noatime,nfsv4acls 0 0
tank/root /root zfs rw,nfsv4acls 0 0
tank/tmp /tmp zfs rw,nfsv4acls 0 0
tank/usr/home /usr/home zfs rw,nfsv4acls 0 0
Checking for uids of 0:
root 0
toor 0
Checking for passwordless accounts:
Checking login.conf permissions:
warden.int.autonlab.org ipfw denied packets:
warden.int.autonlab.org pf denied packets:
+++ /tmp/security.Pve4BjTn 2015-07-25 03:14:13.636425155 -0400
+block return in all [ Evaluations: 7709 Packets: 4524 Bytes: 2577856 States: 0 ]
+block return quick from <bruteforce> to any [ Evaluations: 7709 Packets: 0 Bytes: 0 States: 0 ]
+block return in quick on egress proto tcp from <sshguard> to any port = ssh label "ssh bruteforce" [ Evaluations: 7709 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick on ! lo0 inet from 127.0.0.0/8 to any [ Evaluations: 7709 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick from urpf-failed to any [ Evaluations: 6740 Packets: 0 Bytes: 0 States: 0 ]
+block return in on ! lo0 proto tcp from any to any port 6000:6010 [ Evaluations: 6740 Packets: 0 Bytes: 0 States: 0 ]
warden.int.autonlab.org kernel log messages:
+++ /tmp/security.DUCXCUDk 2015-07-25 03:14:13.731425683 -0400
+FreeBSD 10.1-RELEASE-p25 #0: Wed Jul 22 14:54:58 UTC 2015
+ root at amd64-builder.pcbsd.org:/usr/obj/usr/src/sys/GENERIC amd64
+CPU: Intel(R) Atom(TM) CPU C2758 @ 2.40GHz (2400.06-MHz K8-class CPU)
+module_register_init: MOD_LOAD (vesa, 0xffffffff80db0430, 0) error 19
+SMP: AP CPU #2 Launched!
+SMP: AP CPU #7 Launched!
+Timecounter "TSC-low" frequency 1200032364 Hz quality 1000
+ukbd0: <vendor 0x0557 product 0x2419, class 0/0, rev 1.10/1.00, addr 4> on usbus1
+kbd2 at ukbd0
+Trying to mount root from zfs:tank/ROOT/10.1-RELEASE-p25-up-20150725_002836 []...
+warning: KLD '/boot/kernel/libiconv.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/libmchain.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/msdosfs_iconv.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/sem.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/linsysfs.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/linux.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/fuse.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/ums.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/pflog.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/pf.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/ipfw.ko' is newer than the linker.hints file
warden.int.autonlab.org login failures:
warden.int.autonlab.org refused connections:
Checking for packages with security vulnerabilities:
Database fetched: Thu Jul 23 23:01:37 EDT 2015
libxml2-2.9.2_2
php55-5.5.24
curl-7.42.1
pcre-8.35_2
libressl-2.1.6
php55-gd-5.5.24
ruby-2.0.0.645,1
-- End of security output --
More information about the Autonlab-sysinfo
mailing list