warden.int.autonlab.org daily security run output
punosevac72 at gmail.com
punosevac72 at gmail.com
Wed Sep 9 03:55:13 EDT 2015
Checking setuid files and devices:
warden.int.autonlab.org setuid diffs:
--- /var/log/setuid.today 2015-09-04 03:03:37.000000000 -0400
+++ /tmp/security.TS1vLVko 2015-09-09 03:03:59.387615831 -0400
@@ -224,6 +224,51 @@
752 -r-sr-xr-x 1 root wheel 32696 Aug 12 11:27:47 2015 /iocage/jails/59aeade8-51d9-11e5-8dee-0cc47a68c908/root/usr/sbin/traceroute
819 -r-sr-xr-x 1 root wheel 23976 Aug 12 11:27:47 2015 /iocage/jails/59aeade8-51d9-11e5-8dee-0cc47a68c908/root/usr/sbin/traceroute6
992 -r-xr-sr-x 1 root kmem 11608 Aug 12 11:27:47 2015 /iocage/jails/59aeade8-51d9-11e5-8dee-0cc47a68c908/root/usr/sbin/trpt
+ 84504 -r-sr-xr-x 1 root wheel 19440 Aug 24 12:24:30 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/bin/rcp
+ 12807 -r-sr-xr-- 1 root operator 9984 Aug 12 11:27:14 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/sbin/mksnap_ffs
+ 12778 -r-sr-xr-x 1 root wheel 28080 Aug 12 11:27:15 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/sbin/ping
+ 12790 -r-sr-xr-x 1 root wheel 40648 Aug 12 11:27:15 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/sbin/ping6
+ 12781 -r-sr-xr-- 2 root operator 15712 Aug 12 11:27:15 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/sbin/poweroff
+ 12781 -r-sr-xr-- 2 root operator 15712 Aug 12 11:27:15 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/sbin/shutdown
+ 9697 -r-sr-xr-x 4 root wheel 28576 Aug 12 11:27:30 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/at
+ 9697 -r-sr-xr-x 4 root wheel 28576 Aug 12 11:27:30 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/atq
+ 9697 -r-sr-xr-x 4 root wheel 28576 Aug 12 11:27:30 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/atrm
+ 9697 -r-sr-xr-x 4 root wheel 28576 Aug 12 11:27:30 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/batch
+ 9942 -r-xr-sr-x 1 root kmem 13104 Aug 12 11:27:30 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/btsockstat
+ 84508 -r-sr-xr-x 6 root wheel 21768 Aug 24 12:24:30 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/chfn
+ 84508 -r-sr-xr-x 6 root wheel 21768 Aug 24 12:24:30 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/chpass
+ 84508 -r-sr-xr-x 6 root wheel 21768 Aug 24 12:24:30 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/chsh
+ 84510 -r-sr-xr-x 1 root wheel 32296 Aug 24 12:24:30 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/crontab
+ 9721 -r-sr-xr-x 1 root wheel 11496 Aug 12 11:27:33 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/lock
+ 84512 -r-sr-xr-x 1 root wheel 25256 Aug 24 12:24:30 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/login
+ 9899 -r-sr-sr-x 1 root daemon 33072 Aug 12 11:27:44 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/lpq
+ 9995 -r-sr-sr-x 1 root daemon 38576 Aug 12 11:27:44 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/lpr
+ 9929 -r-sr-sr-x 1 root daemon 32896 Aug 12 11:27:44 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/lprm
+ 9710 -r-xr-sr-x 1 root kmem 146552 Aug 12 11:27:34 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/netstat
+ 84514 -r-sr-xr-x 1 root wheel 6776 Aug 24 12:24:30 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/opieinfo
+ 84516 -r-sr-xr-x 1 root wheel 13400 Aug 24 12:24:30 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/opiepasswd
+ 84518 -r-sr-xr-x 2 root wheel 7928 Aug 24 12:24:30 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/passwd
+ 9873 -r-sr-xr-x 1 root wheel 15712 Aug 12 11:27:34 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/quota
+ 84520 -r-sr-xr-x 1 root wheel 15192 Aug 24 12:24:30 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/rlogin
+ 84522 -r-sr-xr-x 1 root wheel 11168 Aug 24 12:24:30 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/rsh
+ 84524 -r-sr-xr-x 1 root wheel 17200 Aug 24 12:24:30 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/su
+ 9751 -r-xr-sr-x 1 root tty 16144 Aug 12 11:27:37 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/wall
+ 9780 -r-xr-sr-x 1 root tty 12080 Aug 12 11:27:38 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/write
+ 84508 -r-sr-xr-x 6 root wheel 21768 Aug 24 12:24:30 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/ypchfn
+ 84508 -r-sr-xr-x 6 root wheel 21768 Aug 24 12:24:30 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/ypchpass
+ 84508 -r-sr-xr-x 6 root wheel 21768 Aug 24 12:24:30 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/ypchsh
+ 84518 -r-sr-xr-x 2 root wheel 7928 Aug 24 12:24:30 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/bin/yppasswd
+ 12169 -r-xr-sr-x 1 root smmsp 696888 Aug 12 11:27:47 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/libexec/sendmail/sendmail
+ 12015 -r-sr-xr-x 1 root wheel 39040 Aug 12 11:27:17 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/libexec/ssh-keysign
+ 12014 -r-sr-xr-x 1 root wheel 6072 Aug 12 11:27:02 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/libexec/ulog-helper
+ 856 -r-sr-sr-x 2 root authpf 24216 Aug 12 11:27:39 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/sbin/authpf
+ 856 -r-sr-sr-x 2 root authpf 24216 Aug 12 11:27:39 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/sbin/authpf-noip
+ 864 -r-xr-sr-x 1 root daemon 55936 Aug 12 11:27:44 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/sbin/lpc
+ 789 -r-sr-xr-- 1 root network 416120 Aug 12 11:27:46 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/sbin/ppp
+ 929 -r-sr-xr-x 1 root wheel 21040 Aug 12 11:27:47 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/sbin/timedc
+ 752 -r-sr-xr-x 1 root wheel 32696 Aug 12 11:27:47 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/sbin/traceroute
+ 819 -r-sr-xr-x 1 root wheel 23976 Aug 12 11:27:47 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/sbin/traceroute6
+ 992 -r-xr-sr-x 1 root kmem 11608 Aug 12 11:27:47 2015 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/usr/sbin/trpt
12034 -r-sr-xr-x 1 root wheel 19968 Nov 11 16:03:13 2014 /iocage/releases/10.1-RELEASE/root/bin/rcp
12556 -r-sr-xr-- 1 root operator 9984 Nov 11 16:03:20 2014 /iocage/releases/10.1-RELEASE/root/sbin/mksnap_ffs
12481 -r-sr-xr-x 1 root wheel 28080 Nov 11 16:03:20 2014 /iocage/releases/10.1-RELEASE/root/sbin/ping
Checking negative group permissions:
warden.int.autonlab.org changes in mounted filesystems:
--- /var/log/mount.today 2015-09-04 03:06:16.000000000 -0400
+++ /tmp/security.pT7stl2x 2015-09-09 03:07:00.238603651 -0400
@@ -1,10 +1,10 @@
devfs /dev devfs rw,multilabel 0 0
devfs /iocage/jails/1a5b55dc-52c6-11e5-a6b8-0cc47a68c908/root/dev devfs rw,multilabel 0 0
devfs /iocage/jails/4dbed757-4a7e-11e5-ba53-0cc47a68c908/root/dev devfs rw,multilabel 0 0
-devfs /iocage/jails/59aeade8-51d9-11e5-8dee-0cc47a68c908/root/dev devfs rw,multilabel 0 0
+devfs /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/dev devfs rw,multilabel 0 0
fdescfs /iocage/jails/1a5b55dc-52c6-11e5-a6b8-0cc47a68c908/root/dev/fd fdescfs rw 0 0
fdescfs /iocage/jails/4dbed757-4a7e-11e5-ba53-0cc47a68c908/root/dev/fd fdescfs rw 0 0
-fdescfs /iocage/jails/59aeade8-51d9-11e5-8dee-0cc47a68c908/root/dev/fd fdescfs rw 0 0
+fdescfs /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root/dev/fd fdescfs rw 0 0
tank1/ROOT/10.2-RELEASE-up-20150821_175054 / zfs rw,noatime,nfsv4acls 0 0
tank1/iocage /iocage zfs rw,nfsv4acls 0 0
tank1/iocage/.defaults /iocage/.defaults zfs rw,nfsv4acls 0 0
@@ -55,6 +55,8 @@
tank1/iocage/jails/4dbed757-4a7e-11e5-ba53-0cc47a68c908/root /iocage/jails/4dbed757-4a7e-11e5-ba53-0cc47a68c908/root zfs rw,nfsv4acls 0 0
tank1/iocage/jails/59aeade8-51d9-11e5-8dee-0cc47a68c908 /iocage/jails/59aeade8-51d9-11e5-8dee-0cc47a68c908 zfs rw,nfsv4acls 0 0
tank1/iocage/jails/59aeade8-51d9-11e5-8dee-0cc47a68c908/root /iocage/jails/59aeade8-51d9-11e5-8dee-0cc47a68c908/root zfs rw,nfsv4acls 0 0
+tank1/iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908 /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908 zfs rw,nfsv4acls 0 0
+tank1/iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root /iocage/jails/71f072b6-56a1-11e5-a6b8-0cc47a68c908/root zfs rw,nfsv4acls 0 0
tank1/iocage/releases /iocage/releases zfs rw,nfsv4acls 0 0
tank1/iocage/releases/10.1-RELEASE /iocage/releases/10.1-RELEASE zfs rw,nfsv4acls 0 0
tank1/iocage/releases/10.1-RELEASE/root /iocage/releases/10.1-RELEASE/root zfs rw,nfsv4acls 0 0
Checking for uids of 0:
root 0
toor 0
Checking for passwordless accounts:
Checking login.conf permissions:
warden.int.autonlab.org pf denied packets:
+++ /tmp/security.q49wyAXe 2015-09-09 03:07:00.346601704 -0400
+block return in all [ Evaluations: 479794 Packets: 132 Bytes: 9966 States: 0 ]
+block return quick from <bruteforce> to any [ Evaluations: 479795 Packets: 0 Bytes: 0 States: 0 ]
+block return in quick on egress proto tcp from <sshguard> to any port = ssh label "ssh bruteforce" [ Evaluations: 479794 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick on ! lo0 inet from 127.0.0.0/8 to any [ Evaluations: 479796 Packets: 0 Bytes: 0 States: 0 ]
+block drop in quick from urpf-failed to any [ Evaluations: 440789 Packets: 229780 Bytes: 131090252 States: 0 ]
+block return in on ! lo0 proto tcp from any to any port 6000:6010 [ Evaluations: 211010 Packets: 0 Bytes: 0 States: 0 ]
warden.int.autonlab.org login failures:
warden.int.autonlab.org refused connections:
Checking for packages with security vulnerabilities:
php56-5.6.11
pcre-8.37_2
screen-4.3.1_1
ruby-2.0.0.645,1
go-1.4.2,1
-- End of security output --
More information about the Autonlab-sysinfo
mailing list