warden.int.autonlab.org daily security run output

punosevac72 at gmail.com punosevac72 at gmail.com
Sat Jul 25 03:14:14 EDT 2015


Checking setuid files and devices:

warden.int.autonlab.org setuid diffs:
--- /var/log/setuid.today	2015-07-24 23:01:07.000000000 -0400
+++ /tmp/security.bBubIxyV	2015-07-25 03:07:40.262452810 -0400
@@ -77,7 +77,7 @@
   487 -r-sr-xr-x  1 root  wheel      28032 May 14 12:52:52 2015 /usr/jails/.warden-template-10.1-RELEASE-amd64/usr/sbin/traceroute
   576 -r-sr-xr-x  1 root  wheel      23592 May 14 12:52:52 2015 /usr/jails/.warden-template-10.1-RELEASE-amd64/usr/sbin/traceroute6
   558 -r-xr-sr-x  1 root  kmem       11144 May 14 12:52:52 2015 /usr/jails/.warden-template-10.1-RELEASE-amd64/usr/sbin/trpt
-  195 -r-xr-sr-x  1 root  smmsp     696232 May 14 12:52:51 2015 /usr/libexec/sendmail/sendmail
+79767 -r-xr-sr-x  1 root  smmsp     692136 Jul 25 00:28:34 2015 /usr/libexec/sendmail/sendmail
   109 -r-sr-xr-x  1 root  wheel      38568 May 14 12:51:54 2015 /usr/libexec/ssh-keysign
   115 -r-sr-xr-x  1 root  wheel       5592 May 14 12:51:19 2015 /usr/libexec/ulog-helper
 70123 -rwsr-xr-x  1 root  wheel      11464 May  4 14:52:42 2015 /usr/local/bin/otp
@@ -92,7 +92,7 @@
   550 -r-sr-sr-x  2 root  authpf     23744 May 14 12:52:37 2015 /usr/sbin/authpf
   550 -r-sr-sr-x  2 root  authpf     23744 May 14 12:52:37 2015 /usr/sbin/authpf-noip
   482 -r-xr-sr-x  1 root  daemon     54656 May 14 12:52:45 2015 /usr/sbin/lpc
-  574 -r-sr-xr--  1 root  network   415680 May 14 12:52:49 2015 /usr/sbin/ppp
+79861 -r-sr-xr--  1 root  network   415648 Jul 25 00:28:35 2015 /usr/sbin/ppp
   549 -r-sr-xr-x  1 root  wheel      20560 May 14 12:52:52 2015 /usr/sbin/timedc
   495 -r-sr-xr-x  1 root  wheel      28032 May 14 12:52:52 2015 /usr/sbin/traceroute
   584 -r-sr-xr-x  1 root  wheel      23592 May 14 12:52:52 2015 /usr/sbin/traceroute6

Checking negative group permissions:

warden.int.autonlab.org changes in mounted filesystems:
--- /var/log/mount.today	2015-07-02 23:01:19.064240549 -0400
+++ /tmp/security.pHa7iEcK	2015-07-25 03:14:13.237424468 -0400
@@ -1,5 +1,5 @@
 devfs			/dev			devfs	rw,multilabel 	0 0
-tank/ROOT/default	/			zfs	rw,noatime,nfsv4acls 	0 0
+tank/ROOT/10.1-RELEASE-p25-up-20150725_002836 /			zfs	rw,noatime,nfsv4acls 	0 0
 tank/root		/root			zfs	rw,nfsv4acls 	0 0
 tank/tmp		/tmp			zfs	rw,nfsv4acls 	0 0
 tank/usr/home		/usr/home		zfs	rw,nfsv4acls 	0 0

Checking for uids of 0:
root 0
toor 0

Checking for passwordless accounts:

Checking login.conf permissions:

warden.int.autonlab.org ipfw denied packets:

warden.int.autonlab.org pf denied packets:
+++ /tmp/security.Pve4BjTn	2015-07-25 03:14:13.636425155 -0400
+block return in all [ Evaluations: 7709 Packets: 4524 Bytes: 2577856 States: 0 ]
+block return quick from <bruteforce> to any [ Evaluations: 7709 Packets: 0 Bytes: 0 States: 0 ]
+block return in quick on egress proto tcp from <sshguard> to any port = ssh label "ssh bruteforce" [ Evaluations: 7709 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick on ! lo0 inet from 127.0.0.0/8 to any [ Evaluations: 7709 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick from urpf-failed to any [ Evaluations: 6740 Packets: 0 Bytes: 0 States: 0 ]
+block return in on ! lo0 proto tcp from any to any port 6000:6010 [ Evaluations: 6740 Packets: 0 Bytes: 0 States: 0 ]

warden.int.autonlab.org kernel log messages:
+++ /tmp/security.DUCXCUDk	2015-07-25 03:14:13.731425683 -0400
+FreeBSD 10.1-RELEASE-p25 #0: Wed Jul 22 14:54:58 UTC 2015
+    root at amd64-builder.pcbsd.org:/usr/obj/usr/src/sys/GENERIC amd64
+CPU: Intel(R) Atom(TM) CPU  C2758  @ 2.40GHz (2400.06-MHz K8-class CPU)
+module_register_init: MOD_LOAD (vesa, 0xffffffff80db0430, 0) error 19
+SMP: AP CPU #2 Launched!
+SMP: AP CPU #7 Launched!
+Timecounter "TSC-low" frequency 1200032364 Hz quality 1000
+ukbd0: <vendor 0x0557 product 0x2419, class 0/0, rev 1.10/1.00, addr 4> on usbus1
+kbd2 at ukbd0
+Trying to mount root from zfs:tank/ROOT/10.1-RELEASE-p25-up-20150725_002836 []...
+warning: KLD '/boot/kernel/libiconv.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/libmchain.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/msdosfs_iconv.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/sem.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/linsysfs.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/linux.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/fuse.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/ums.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/pflog.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/pf.ko' is newer than the linker.hints file
+warning: KLD '/boot/kernel/ipfw.ko' is newer than the linker.hints file

warden.int.autonlab.org login failures:

warden.int.autonlab.org refused connections:

Checking for packages with security vulnerabilities:
Database fetched: Thu Jul 23 23:01:37 EDT 2015
libxml2-2.9.2_2
php55-5.5.24
curl-7.42.1
pcre-8.35_2
libressl-2.1.6
php55-gd-5.5.24
ruby-2.0.0.645,1

-- End of security output --


More information about the Autonlab-sysinfo mailing list