neill-backup.int.autonlab.org daily security run output

punosevac72 at gmail.com punosevac72 at gmail.com
Wed Oct 14 04:25:39 EDT 2015


Checking setuid files and devices:

neill-backup.int.autonlab.org setuid diffs:
--- /var/log/setuid.today	2015-08-22 03:20:43.000000000 -0400
+++ /tmp/security.lU5e52t7	2015-10-14 03:40:30.000000000 -0400
@@ -38,8 +38,8 @@
 86536329 -r-sr-xr-x  1 root  wheel      32632 Oct  3 13:18:25 2014 /usr/local/bin/tcptraceroute
 85894152 -r-xr-sr-x  1 root  mail       61664 Jul  2 07:52:28 2015 /usr/local/libexec/dma
 85894153 -r-sr-xr-x  1 root  mail        7672 Jul  2 07:52:28 2015 /usr/local/libexec/dma-mbox-create
-85974411 -rwsr-x--x  1 root  wheel       7312 Nov  6 03:21:54 2014 /usr/local/sbin/jailme
-85974428 -rwxr-sr-x  1 root  kmem      126136 Oct 23 05:08:33 2014 /usr/local/sbin/lsof
+85974497 -rwsr-x--x  1 root  wheel       7800 Oct  2 23:31:48 2015 /usr/local/sbin/jailme
+85974493 -rwxr-sr-x  1 root  kmem      129464 Oct  2 23:30:38 2015 /usr/local/sbin/lsof
 85633173 -r-sr-sr-x  2 root  authpf     24216 Nov 11 16:03:36 2014 /usr/sbin/authpf
 85633173 -r-sr-sr-x  2 root  authpf     24216 Nov 11 16:03:36 2014 /usr/sbin/authpf-noip
 85633282 -r-xr-sr-x  1 root  daemon     55936 Nov 11 16:03:39 2014 /usr/sbin/lpc

Checking negative group permissions:

Checking for uids of 0:
root 0
toor 0

Checking for passwordless accounts:

Checking login.conf permissions:

neill-backup.int.autonlab.org pf denied packets:
+++ /tmp/security.AqCAHA2G	2015-10-14 04:25:39.000000000 -0400
+block return in all [ Evaluations: 37522 Packets: 25035 Bytes: 14281980 States: 0 ]
+block return quick from <bruteforce> to any [ Evaluations: 37522 Packets: 0 Bytes: 0 States: 0 ]
+block return in quick on egress proto tcp from <sshguard> to any port = ssh label "ssh bruteforce" [ Evaluations: 37522 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick on ! lo0 inet from 127.0.0.0/8 to any [ Evaluations: 37522 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick from urpf-failed to any [ Evaluations: 34995 Packets: 0 Bytes: 0 States: 0 ]
+block return in on ! lo0 proto tcp from any to any port 6000:6010 [ Evaluations: 34995 Packets: 0 Bytes: 0 States: 0 ]

neill-backup.int.autonlab.org kernel log messages:
+++ /tmp/security.JYAIrNlq	2015-10-14 04:25:39.000000000 -0400
+twa0: INFO: (0x04: 0x0055): Battery charging started: 
+twa0: INFO: (0x04: 0x0056): Battery charging completed: 
+twa0: INFO: (0x04: 0x0053): Battery capacity test is overdue: 

neill-backup.int.autonlab.org login failures:

neill-backup.int.autonlab.org refused connections:

Checking for packages with security vulnerabilities:
Database fetched: Mon Oct 12 06:15:19 EDT 2015

-- End of security output --


More information about the Autonlab-sysinfo mailing list