bhyve.int.autonlab.org daily security run output

punosevac72 at gmail.com punosevac72 at gmail.com
Fri Oct 16 03:04:59 EDT 2015


Checking setuid files and devices:

bhyve.int.autonlab.org setuid diffs:
--- /var/log/setuid.today	2015-10-15 03:02:49.000000000 -0400
+++ /tmp/security.TZUEfupU	2015-10-16 03:02:59.977565795 -0400
@@ -134,6 +134,51 @@
    310 -r-sr-xr-x  1 root  wheel      28424 Nov 11 16:03:41 2014 /iocage/jails/12ca1d93-36f1-11e5-8746-0cc47a68b3d8/root/usr/sbin/traceroute
    136 -r-sr-xr-x  1 root  wheel      23976 Nov 11 16:03:41 2014 /iocage/jails/12ca1d93-36f1-11e5-8746-0cc47a68b3d8/root/usr/sbin/traceroute6
    328 -r-xr-sr-x  1 root  kmem       11608 Nov 11 16:03:41 2014 /iocage/jails/12ca1d93-36f1-11e5-8746-0cc47a68b3d8/root/usr/sbin/trpt
+ 84632 -r-sr-xr-x  1 root  wheel      19440 Oct 14 20:41:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/bin/rcp
+ 12807 -r-sr-xr--  1 root  operator    9984 Aug 12 11:27:14 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/sbin/mksnap_ffs
+ 12778 -r-sr-xr-x  1 root  wheel      28080 Aug 12 11:27:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/sbin/ping
+ 12790 -r-sr-xr-x  1 root  wheel      40648 Aug 12 11:27:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/sbin/ping6
+ 12781 -r-sr-xr--  2 root  operator   15712 Aug 12 11:27:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/sbin/poweroff
+ 12781 -r-sr-xr--  2 root  operator   15712 Aug 12 11:27:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/sbin/shutdown
+  9697 -r-sr-xr-x  4 root  wheel      28576 Aug 12 11:27:30 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/at
+  9697 -r-sr-xr-x  4 root  wheel      28576 Aug 12 11:27:30 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/atq
+  9697 -r-sr-xr-x  4 root  wheel      28576 Aug 12 11:27:30 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/atrm
+  9697 -r-sr-xr-x  4 root  wheel      28576 Aug 12 11:27:30 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/batch
+  9942 -r-xr-sr-x  1 root  kmem       13104 Aug 12 11:27:30 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/btsockstat
+ 84646 -r-sr-xr-x  6 root  wheel      21768 Oct 14 20:41:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/chfn
+ 84646 -r-sr-xr-x  6 root  wheel      21768 Oct 14 20:41:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/chpass
+ 84646 -r-sr-xr-x  6 root  wheel      21768 Oct 14 20:41:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/chsh
+ 84648 -r-sr-xr-x  1 root  wheel      32296 Oct 14 20:41:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/crontab
+  9721 -r-sr-xr-x  1 root  wheel      11496 Aug 12 11:27:33 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/lock
+ 84652 -r-sr-xr-x  1 root  wheel      25256 Oct 14 20:41:16 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/login
+  9899 -r-sr-sr-x  1 root  daemon     33072 Aug 12 11:27:44 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/lpq
+  9995 -r-sr-sr-x  1 root  daemon     38576 Aug 12 11:27:44 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/lpr
+  9929 -r-sr-sr-x  1 root  daemon     32896 Aug 12 11:27:44 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/lprm
+ 84656 -r-xr-sr-x  1 root  kmem      144600 Oct 14 20:41:16 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/netstat
+ 84658 -r-sr-xr-x  1 root  wheel       6776 Oct 14 20:41:16 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/opieinfo
+ 84660 -r-sr-xr-x  1 root  wheel      13400 Oct 14 20:41:16 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/opiepasswd
+ 84662 -r-sr-xr-x  2 root  wheel       7928 Oct 14 20:41:16 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/passwd
+  9873 -r-sr-xr-x  1 root  wheel      15712 Aug 12 11:27:34 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/quota
+ 84664 -r-sr-xr-x  1 root  wheel      15192 Oct 14 20:41:16 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/rlogin
+ 84666 -r-sr-xr-x  1 root  wheel      11168 Oct 14 20:41:16 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/rsh
+ 84670 -r-sr-xr-x  1 root  wheel      17200 Oct 14 20:41:16 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/su
+  9751 -r-xr-sr-x  1 root  tty        16144 Aug 12 11:27:37 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/wall
+  9780 -r-xr-sr-x  1 root  tty        12080 Aug 12 11:27:38 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/write
+ 84646 -r-sr-xr-x  6 root  wheel      21768 Oct 14 20:41:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/ypchfn
+ 84646 -r-sr-xr-x  6 root  wheel      21768 Oct 14 20:41:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/ypchpass
+ 84646 -r-sr-xr-x  6 root  wheel      21768 Oct 14 20:41:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/ypchsh
+ 84662 -r-sr-xr-x  2 root  wheel       7928 Oct 14 20:41:16 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/yppasswd
+ 12169 -r-xr-sr-x  1 root  smmsp     696888 Aug 12 11:27:47 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/libexec/sendmail/sendmail
+ 12015 -r-sr-xr-x  1 root  wheel      39040 Aug 12 11:27:17 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/libexec/ssh-keysign
+ 12014 -r-sr-xr-x  1 root  wheel       6072 Aug 12 11:27:02 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/libexec/ulog-helper
+   856 -r-sr-sr-x  2 root  authpf     24216 Aug 12 11:27:39 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/sbin/authpf
+   856 -r-sr-sr-x  2 root  authpf     24216 Aug 12 11:27:39 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/sbin/authpf-noip
+   864 -r-xr-sr-x  1 root  daemon     55936 Aug 12 11:27:44 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/sbin/lpc
+   789 -r-sr-xr--  1 root  network   416120 Aug 12 11:27:46 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/sbin/ppp
+   929 -r-sr-xr-x  1 root  wheel      21040 Aug 12 11:27:47 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/sbin/timedc
+   752 -r-sr-xr-x  1 root  wheel      32696 Aug 12 11:27:47 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/sbin/traceroute
+   819 -r-sr-xr-x  1 root  wheel      23976 Aug 12 11:27:47 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/sbin/traceroute6
+   992 -r-xr-sr-x  1 root  kmem       11608 Aug 12 11:27:47 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/sbin/trpt
  84632 -r-sr-xr-x  1 root  wheel      19440 Oct 14 20:41:15 2015 /iocage/jails/cfe482bc-72d6-11e5-9d85-0cc47a68b3d8/root/bin/rcp
  12807 -r-sr-xr--  1 root  operator    9984 Aug 12 11:27:14 2015 /iocage/jails/cfe482bc-72d6-11e5-9d85-0cc47a68b3d8/root/sbin/mksnap_ffs
  12778 -r-sr-xr-x  1 root  wheel      28080 Aug 12 11:27:15 2015 /iocage/jails/cfe482bc-72d6-11e5-9d85-0cc47a68b3d8/root/sbin/ping

Checking negative group permissions:

bhyve.int.autonlab.org changes in mounted filesystems:
--- /var/log/mount.today	2015-10-15 03:04:36.000000000 -0400
+++ /tmp/security.BK2sMFDn	2015-10-16 03:04:58.785556226 -0400
@@ -1,7 +1,9 @@
 devfs			/dev			devfs	rw,multilabel 	0 0
 devfs			/iocage/jails/12ca1d93-36f1-11e5-8746-0cc47a68b3d8/root/dev devfs	rw,multilabel 	0 0
+devfs			/iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/dev devfs	rw,multilabel 	0 0
 devfs			/iocage/jails/cfe482bc-72d6-11e5-9d85-0cc47a68b3d8/root/dev devfs	rw,multilabel 	0 0
 fdescfs			/iocage/jails/12ca1d93-36f1-11e5-8746-0cc47a68b3d8/root/dev/fd fdescfs	rw		0 0
+fdescfs			/iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/dev/fd fdescfs	rw		0 0
 fdescfs			/iocage/jails/cfe482bc-72d6-11e5-9d85-0cc47a68b3d8/root/dev/fd fdescfs	rw		0 0
 tank/ROOT/10.2-RELEASE-up-20150821_175236 /			zfs	rw,noatime,nfsv4acls 	0 0
 tank/iocage		/iocage			zfs	rw,nfsv4acls 	0 0
@@ -49,6 +51,8 @@
 tank/iocage/jails	/iocage/jails		zfs	rw,nfsv4acls 	0 0
 tank/iocage/jails/12ca1d93-36f1-11e5-8746-0cc47a68b3d8 /iocage/jails/12ca1d93-36f1-11e5-8746-0cc47a68b3d8 zfs	rw,nfsv4acls 	0 0
 tank/iocage/jails/12ca1d93-36f1-11e5-8746-0cc47a68b3d8/root /iocage/jails/12ca1d93-36f1-11e5-8746-0cc47a68b3d8/root zfs	rw,nfsv4acls 	0 0
+tank/iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8 zfs	rw,nfsv4acls 	0 0
+tank/iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root zfs	rw,nfsv4acls 	0 0
 tank/iocage/jails/cfe482bc-72d6-11e5-9d85-0cc47a68b3d8 /iocage/jails/cfe482bc-72d6-11e5-9d85-0cc47a68b3d8 zfs	rw,nfsv4acls 	0 0
 tank/iocage/jails/cfe482bc-72d6-11e5-9d85-0cc47a68b3d8/root /iocage/jails/cfe482bc-72d6-11e5-9d85-0cc47a68b3d8/root zfs	rw,nfsv4acls 	0 0
 tank/iocage/releases	/iocage/releases	zfs	rw,nfsv4acls 	0 0

Checking for uids of 0:
root 0
toor 0

Checking for passwordless accounts:

Checking login.conf permissions:

bhyve.int.autonlab.org pf denied packets:
+++ /tmp/security.GJHAnzOW	2015-10-16 03:04:58.926556385 -0400
+block return in all [ Evaluations: 9005 Packets: 4383 Bytes: 2499632 States: 0 ]
+block return quick from <bruteforce> to any [ Evaluations: 9005 Packets: 0 Bytes: 0 States: 0 ]
+block return in quick on egress proto tcp from <sshguard> to any port = ssh label "ssh bruteforce" [ Evaluations: 9005 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick on ! lo0 inet from 127.0.0.0/8 to any [ Evaluations: 9005 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick from urpf-failed to any [ Evaluations: 8232 Packets: 0 Bytes: 0 States: 0 ]
+block return in on ! lo0 proto tcp from any to any port 6000:6010 [ Evaluations: 8232 Packets: 0 Bytes: 0 States: 0 ]

bhyve.int.autonlab.org login failures:

bhyve.int.autonlab.org refused connections:

Checking for packages with security vulnerabilities:
Database fetched: Thu Oct 15 03:41:52 EDT 2015
php56-5.6.11
pcre-8.37_2
screen-4.3.1_1
go-1.4.2,1

-- End of security output --


More information about the Autonlab-sysinfo mailing list