uranus.int.autonlab.org daily security run output

punosevac72 at gmail.com punosevac72 at gmail.com
Fri Jul 31 03:18:01 EDT 2015


Checking setuid files and devices:

Checking negative group permissions:

uranus.int.autonlab.org changes in mounted filesystems:
--- /var/log/mount.today	2015-07-30 03:07:56.000000000 -0400
+++ /tmp/security.6nKUFTfp	2015-07-31 03:17:59.457495615 -0400
@@ -2,6 +2,7 @@
 archive/attic		/archive/attic		zfs	rw,nfsv4acls 	0 0
 backups			/backups		zfs	rw,nfsv4acls 	0 0
 backups/data		/backups/data		zfs	rw,nfsv4acls 	0 0
+backups/data/zdata	/backups/data/zdata	zfs	rw,noatime,nfsv4acls 	0 0
 backups/home		/backups/home		zfs	rw,nfsv4acls 	0 0
 backups/project		/backups/project	zfs	rw,nfsv4acls 	0 0
 backups/project/project	/backups/project/project zfs	rw,noatime,nfsv4acls 	0 0

Checking for uids of 0:
root 0
toor 0

Checking for passwordless accounts:

Checking login.conf permissions:

uranus.int.autonlab.org ipfw denied packets:

uranus.int.autonlab.org pf denied packets:
+++ /tmp/security.XWuTH3cb	2015-07-31 03:17:59.497495866 -0400
+block return in all [ Evaluations: 481673 Packets: 246533 Bytes: 140414922 States: 0 ]
+block return quick from <bruteforce> to any [ Evaluations: 481678 Packets: 0 Bytes: 0 States: 0 ]
+block return in quick on egress proto tcp from <sshguard> to any port = ssh label "ssh bruteforce" [ Evaluations: 481672 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick on ! lo0 inet from 127.0.0.0/8 to any [ Evaluations: 481674 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick from urpf-failed to any [ Evaluations: 441585 Packets: 0 Bytes: 0 States: 0 ]
+block return in on ! lo0 proto tcp from any to any port 6000:6010 [ Evaluations: 441593 Packets: 0 Bytes: 0 States: 0 ]

uranus.int.autonlab.org login failures:

uranus.int.autonlab.org refused connections:

Checking for packages with security vulnerabilities:
libxml2-2.9.2_2
php55-5.5.24
curl-7.42.1
pcre-8.35_2
libressl-2.1.6
php55-gd-5.5.24
ruby-2.0.0.645,1

-- End of security output --


More information about the Autonlab-sysinfo mailing list