bhyve.int.autonlab.org daily security run output
punosevac72 at gmail.com
punosevac72 at gmail.com
Fri Oct 16 03:04:59 EDT 2015
Checking setuid files and devices:
bhyve.int.autonlab.org setuid diffs:
--- /var/log/setuid.today 2015-10-15 03:02:49.000000000 -0400
+++ /tmp/security.TZUEfupU 2015-10-16 03:02:59.977565795 -0400
@@ -134,6 +134,51 @@
310 -r-sr-xr-x 1 root wheel 28424 Nov 11 16:03:41 2014 /iocage/jails/12ca1d93-36f1-11e5-8746-0cc47a68b3d8/root/usr/sbin/traceroute
136 -r-sr-xr-x 1 root wheel 23976 Nov 11 16:03:41 2014 /iocage/jails/12ca1d93-36f1-11e5-8746-0cc47a68b3d8/root/usr/sbin/traceroute6
328 -r-xr-sr-x 1 root kmem 11608 Nov 11 16:03:41 2014 /iocage/jails/12ca1d93-36f1-11e5-8746-0cc47a68b3d8/root/usr/sbin/trpt
+ 84632 -r-sr-xr-x 1 root wheel 19440 Oct 14 20:41:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/bin/rcp
+ 12807 -r-sr-xr-- 1 root operator 9984 Aug 12 11:27:14 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/sbin/mksnap_ffs
+ 12778 -r-sr-xr-x 1 root wheel 28080 Aug 12 11:27:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/sbin/ping
+ 12790 -r-sr-xr-x 1 root wheel 40648 Aug 12 11:27:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/sbin/ping6
+ 12781 -r-sr-xr-- 2 root operator 15712 Aug 12 11:27:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/sbin/poweroff
+ 12781 -r-sr-xr-- 2 root operator 15712 Aug 12 11:27:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/sbin/shutdown
+ 9697 -r-sr-xr-x 4 root wheel 28576 Aug 12 11:27:30 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/at
+ 9697 -r-sr-xr-x 4 root wheel 28576 Aug 12 11:27:30 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/atq
+ 9697 -r-sr-xr-x 4 root wheel 28576 Aug 12 11:27:30 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/atrm
+ 9697 -r-sr-xr-x 4 root wheel 28576 Aug 12 11:27:30 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/batch
+ 9942 -r-xr-sr-x 1 root kmem 13104 Aug 12 11:27:30 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/btsockstat
+ 84646 -r-sr-xr-x 6 root wheel 21768 Oct 14 20:41:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/chfn
+ 84646 -r-sr-xr-x 6 root wheel 21768 Oct 14 20:41:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/chpass
+ 84646 -r-sr-xr-x 6 root wheel 21768 Oct 14 20:41:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/chsh
+ 84648 -r-sr-xr-x 1 root wheel 32296 Oct 14 20:41:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/crontab
+ 9721 -r-sr-xr-x 1 root wheel 11496 Aug 12 11:27:33 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/lock
+ 84652 -r-sr-xr-x 1 root wheel 25256 Oct 14 20:41:16 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/login
+ 9899 -r-sr-sr-x 1 root daemon 33072 Aug 12 11:27:44 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/lpq
+ 9995 -r-sr-sr-x 1 root daemon 38576 Aug 12 11:27:44 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/lpr
+ 9929 -r-sr-sr-x 1 root daemon 32896 Aug 12 11:27:44 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/lprm
+ 84656 -r-xr-sr-x 1 root kmem 144600 Oct 14 20:41:16 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/netstat
+ 84658 -r-sr-xr-x 1 root wheel 6776 Oct 14 20:41:16 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/opieinfo
+ 84660 -r-sr-xr-x 1 root wheel 13400 Oct 14 20:41:16 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/opiepasswd
+ 84662 -r-sr-xr-x 2 root wheel 7928 Oct 14 20:41:16 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/passwd
+ 9873 -r-sr-xr-x 1 root wheel 15712 Aug 12 11:27:34 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/quota
+ 84664 -r-sr-xr-x 1 root wheel 15192 Oct 14 20:41:16 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/rlogin
+ 84666 -r-sr-xr-x 1 root wheel 11168 Oct 14 20:41:16 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/rsh
+ 84670 -r-sr-xr-x 1 root wheel 17200 Oct 14 20:41:16 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/su
+ 9751 -r-xr-sr-x 1 root tty 16144 Aug 12 11:27:37 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/wall
+ 9780 -r-xr-sr-x 1 root tty 12080 Aug 12 11:27:38 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/write
+ 84646 -r-sr-xr-x 6 root wheel 21768 Oct 14 20:41:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/ypchfn
+ 84646 -r-sr-xr-x 6 root wheel 21768 Oct 14 20:41:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/ypchpass
+ 84646 -r-sr-xr-x 6 root wheel 21768 Oct 14 20:41:15 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/ypchsh
+ 84662 -r-sr-xr-x 2 root wheel 7928 Oct 14 20:41:16 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/bin/yppasswd
+ 12169 -r-xr-sr-x 1 root smmsp 696888 Aug 12 11:27:47 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/libexec/sendmail/sendmail
+ 12015 -r-sr-xr-x 1 root wheel 39040 Aug 12 11:27:17 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/libexec/ssh-keysign
+ 12014 -r-sr-xr-x 1 root wheel 6072 Aug 12 11:27:02 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/libexec/ulog-helper
+ 856 -r-sr-sr-x 2 root authpf 24216 Aug 12 11:27:39 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/sbin/authpf
+ 856 -r-sr-sr-x 2 root authpf 24216 Aug 12 11:27:39 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/sbin/authpf-noip
+ 864 -r-xr-sr-x 1 root daemon 55936 Aug 12 11:27:44 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/sbin/lpc
+ 789 -r-sr-xr-- 1 root network 416120 Aug 12 11:27:46 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/sbin/ppp
+ 929 -r-sr-xr-x 1 root wheel 21040 Aug 12 11:27:47 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/sbin/timedc
+ 752 -r-sr-xr-x 1 root wheel 32696 Aug 12 11:27:47 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/sbin/traceroute
+ 819 -r-sr-xr-x 1 root wheel 23976 Aug 12 11:27:47 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/sbin/traceroute6
+ 992 -r-xr-sr-x 1 root kmem 11608 Aug 12 11:27:47 2015 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/usr/sbin/trpt
84632 -r-sr-xr-x 1 root wheel 19440 Oct 14 20:41:15 2015 /iocage/jails/cfe482bc-72d6-11e5-9d85-0cc47a68b3d8/root/bin/rcp
12807 -r-sr-xr-- 1 root operator 9984 Aug 12 11:27:14 2015 /iocage/jails/cfe482bc-72d6-11e5-9d85-0cc47a68b3d8/root/sbin/mksnap_ffs
12778 -r-sr-xr-x 1 root wheel 28080 Aug 12 11:27:15 2015 /iocage/jails/cfe482bc-72d6-11e5-9d85-0cc47a68b3d8/root/sbin/ping
Checking negative group permissions:
bhyve.int.autonlab.org changes in mounted filesystems:
--- /var/log/mount.today 2015-10-15 03:04:36.000000000 -0400
+++ /tmp/security.BK2sMFDn 2015-10-16 03:04:58.785556226 -0400
@@ -1,7 +1,9 @@
devfs /dev devfs rw,multilabel 0 0
devfs /iocage/jails/12ca1d93-36f1-11e5-8746-0cc47a68b3d8/root/dev devfs rw,multilabel 0 0
+devfs /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/dev devfs rw,multilabel 0 0
devfs /iocage/jails/cfe482bc-72d6-11e5-9d85-0cc47a68b3d8/root/dev devfs rw,multilabel 0 0
fdescfs /iocage/jails/12ca1d93-36f1-11e5-8746-0cc47a68b3d8/root/dev/fd fdescfs rw 0 0
+fdescfs /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root/dev/fd fdescfs rw 0 0
fdescfs /iocage/jails/cfe482bc-72d6-11e5-9d85-0cc47a68b3d8/root/dev/fd fdescfs rw 0 0
tank/ROOT/10.2-RELEASE-up-20150821_175236 / zfs rw,noatime,nfsv4acls 0 0
tank/iocage /iocage zfs rw,nfsv4acls 0 0
@@ -49,6 +51,8 @@
tank/iocage/jails /iocage/jails zfs rw,nfsv4acls 0 0
tank/iocage/jails/12ca1d93-36f1-11e5-8746-0cc47a68b3d8 /iocage/jails/12ca1d93-36f1-11e5-8746-0cc47a68b3d8 zfs rw,nfsv4acls 0 0
tank/iocage/jails/12ca1d93-36f1-11e5-8746-0cc47a68b3d8/root /iocage/jails/12ca1d93-36f1-11e5-8746-0cc47a68b3d8/root zfs rw,nfsv4acls 0 0
+tank/iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8 /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8 zfs rw,nfsv4acls 0 0
+tank/iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root /iocage/jails/20303f9d-73ba-11e5-9d85-0cc47a68b3d8/root zfs rw,nfsv4acls 0 0
tank/iocage/jails/cfe482bc-72d6-11e5-9d85-0cc47a68b3d8 /iocage/jails/cfe482bc-72d6-11e5-9d85-0cc47a68b3d8 zfs rw,nfsv4acls 0 0
tank/iocage/jails/cfe482bc-72d6-11e5-9d85-0cc47a68b3d8/root /iocage/jails/cfe482bc-72d6-11e5-9d85-0cc47a68b3d8/root zfs rw,nfsv4acls 0 0
tank/iocage/releases /iocage/releases zfs rw,nfsv4acls 0 0
Checking for uids of 0:
root 0
toor 0
Checking for passwordless accounts:
Checking login.conf permissions:
bhyve.int.autonlab.org pf denied packets:
+++ /tmp/security.GJHAnzOW 2015-10-16 03:04:58.926556385 -0400
+block return in all [ Evaluations: 9005 Packets: 4383 Bytes: 2499632 States: 0 ]
+block return quick from <bruteforce> to any [ Evaluations: 9005 Packets: 0 Bytes: 0 States: 0 ]
+block return in quick on egress proto tcp from <sshguard> to any port = ssh label "ssh bruteforce" [ Evaluations: 9005 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick on ! lo0 inet from 127.0.0.0/8 to any [ Evaluations: 9005 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick from urpf-failed to any [ Evaluations: 8232 Packets: 0 Bytes: 0 States: 0 ]
+block return in on ! lo0 proto tcp from any to any port 6000:6010 [ Evaluations: 8232 Packets: 0 Bytes: 0 States: 0 ]
bhyve.int.autonlab.org login failures:
bhyve.int.autonlab.org refused connections:
Checking for packages with security vulnerabilities:
Database fetched: Thu Oct 15 03:41:52 EDT 2015
php56-5.6.11
pcre-8.37_2
screen-4.3.1_1
go-1.4.2,1
-- End of security output --
More information about the Autonlab-sysinfo
mailing list