|
Server : Apache/2.2.22 (Unix) mod_ssl/2.2.22 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 System : Linux server.jackjohnson.com 2.6.32-279.5.2.el6.x86_64 #1 SMP Fri Aug 24 01:07:11 UTC 2012 x86_64 User : jackjohn ( 502) PHP Version : 5.3.17 Disable Function : NONE Directory : /home/jackjohn/mail/jackjohnson.com/jackjohnson/cur/ |
Upload File : |
Return-Path: <root@jackjohnson.nethosting.com> Received: from jackjohnson.nethosting.com (localhost [127.0.0.1]) by jackjohnson.nethosting.com (8.13.6.20060614/8.13.6) with ESMTP id l7G93WlY032385 for <root@jackjohnson.nethosting.com>; Thu, 16 Aug 2007 03:03:32 -0600 (MDT) Received: (from root@localhost) by jackjohnson.nethosting.com (8.13.6.20060614/8.13.6/Submit) id l7G93WCB032352 for root; Thu, 16 Aug 2007 03:03:32 -0600 (MDT) Date: Thu, 16 Aug 2007 03:03:32 -0600 (MDT) From: Charlie Root <root@jackjohnson.nethosting.com> Message-Id: <200708160903.l7G93WCB032352@jackjohnson.nethosting.com> To: root@jackjohnson.nethosting.com Subject: jackjohnson.nethosting.com security run output Checking setuid files and devices: find: fts_read: No such file or directory jackjohnson.nethosting.com setuid diffs: --- /var/log/setuid.today Thu Aug 2 03:06:53 2007 +++ /tmp/security.R2yoLZaH Thu Aug 16 03:03:31 2007 @@ -3,9 +3,9 @@ 124664406 -rwxr-sr-x 1 root mail 7668 Jul 2 09:23:09 2007 /backup/usr/local/bin/muttng_dotlock 124664700 -rwsr-sr-x 1 root mail 74140 Nov 17 18:17:16 2005 /backup/usr/local/bin/procmail 124664757 -rws--x--x 1 root wheel 949226 Nov 14 15:32:22 2005 /backup/usr/local/bin/sperl5.8.7 -124664762 ---s--x--x 2 root wheel 95216 Apr 16 08:55:06 2007 /backup/usr/local/bin/sudo -124664762 ---s--x--x 2 root wheel 95216 Apr 16 08:55:06 2007 /backup/usr/local/bin/sudoedit -124665026 -rws--x--x 1 root wheel 267620 May 22 11:48:16 2007 /backup/usr/local/bin/xterm +124664690 ---s--x--x 2 root wheel 103960 Jul 23 08:58:06 2007 /backup/usr/local/bin/sudo +124664690 ---s--x--x 2 root wheel 103960 Jul 23 08:58:06 2007 /backup/usr/local/bin/sudoedit +124664996 -rws--x--x 1 root wheel 270468 Jul 23 15:25:40 2007 /backup/usr/local/bin/xterm 124242811 -r-sr-xr-x 1 root wheel 18332 Nov 3 01:10:07 2005 /bin/rcp 124373523 -r-sr-xr-x 1 root wheel 22528 Nov 18 08:57:07 2005 /sbin/ping 124373524 -r-sr-xr-x 1 root wheel 30696 Sep 20 14:15:21 2006 /sbin/ping6 @@ -44,7 +44,7 @@ 124619140 -r-sr-xr-x 1 root wheel 3400 Nov 3 01:10:04 2005 /skel/usr/libexec/pt_chown 124619145 -r-xr-sr-x 1 root smmsp 657043 Jun 19 16:21:33 2006 /skel/usr/libexec/sendmail/sendmail 124619146 -r-xr-sr-x 1 root smmsp 588052 Nov 10 11:40:11 2005 /skel/usr/libexec/sendmail/sendmail-8.13.4 -124619147 -rws--x--x 1 root wheel 141692 Mar 26 09:27:57 2007 /skel/usr/libexec/ssh-keysign +124619156 -rws--x--x 1 root wheel 141692 Jul 18 15:45:05 2007 /skel/usr/libexec/ssh-keysign 124630292 -rws--x--x 1 root wheel 10920 Jul 31 16:55:46 2006 /skel/usr/local/apache/bin/suexec 124641831 -rwsr-xr-x 1 root wheel 19380 Feb 28 13:55:07 2007 /skel/usr/local/apache2/bin/suexec 124664331 -r-sr-xr-x 1 man wheel 33152 Mar 12 11:24:42 2007 /skel/usr/local/bin/jman @@ -52,9 +52,9 @@ 124664406 -rwxr-sr-x 1 root mail 7668 Jul 2 09:23:09 2007 /skel/usr/local/bin/muttng_dotlock 124664700 -rwsr-sr-x 1 root mail 74140 Nov 17 18:17:16 2005 /skel/usr/local/bin/procmail 124664757 -rws--x--x 1 root wheel 949226 Nov 14 15:32:22 2005 /skel/usr/local/bin/sperl5.8.7 -124664762 ---s--x--x 2 root wheel 95216 Apr 16 08:55:06 2007 /skel/usr/local/bin/sudo -124664762 ---s--x--x 2 root wheel 95216 Apr 16 08:55:06 2007 /skel/usr/local/bin/sudoedit -124665026 -rws--x--x 1 root wheel 267620 May 22 11:48:16 2007 /skel/usr/local/bin/xterm +124664690 ---s--x--x 2 root wheel 103960 Jul 23 08:58:06 2007 /skel/usr/local/bin/sudo +124664690 ---s--x--x 2 root wheel 103960 Jul 23 08:58:06 2007 /skel/usr/local/bin/sudoedit +124664996 -rws--x--x 1 root wheel 270468 Jul 23 15:25:40 2007 /skel/usr/local/bin/xterm 124698111 -rwsr-xr-x 1 root bin 11451 Jun 27 14:18:28 2003 /skel/usr/local/frontpage/version5.0/apache-fp/_vti_bin/fpexe 125023737 -r-s--x--x 1 root wheel 7744 Jun 27 16:08:23 2007 /skel/usr/local/sbin/sinfo 125401144 -r-xr-sr-x 1 root daemon 43112 Nov 3 01:11:47 2005 /skel/usr/sbin/lpc @@ -67,6 +67,6 @@ 124664406 -rwxr-sr-x 1 root mail 7668 Jul 2 09:23:09 2007 /usr/X11R6/bin/muttng_dotlock 124664700 -rwsr-sr-x 1 root mail 74140 Nov 17 18:17:16 2005 /usr/X11R6/bin/procmail 124664757 -rws--x--x 1 root wheel 949226 Nov 14 15:32:22 2005 /usr/X11R6/bin/sperl5.8.7 -124664762 ---s--x--x 2 root wheel 95216 Apr 16 08:55:06 2007 /usr/X11R6/bin/sudo -124664762 ---s--x--x 2 root wheel 95216 Apr 16 08:55:06 2007 /usr/X11R6/bin/sudoedit -124665026 -rws--x--x 1 root wheel 267620 May 22 11:48:16 2007 /usr/X11R6/bin/xterm +124664690 ---s--x--x 2 root wheel 103960 Jul 23 08:58:06 2007 /usr/X11R6/bin/sudo +124664690 ---s--x--x 2 root wheel 103960 Jul 23 08:58:06 2007 /usr/X11R6/bin/sudoedit +124664996 -rws--x--x 1 root wheel 270468 Jul 23 15:25:40 2007 /usr/X11R6/bin/xterm Checking for uids of 0: root 0 toor 0 Checking for passwordless accounts: jackjohnson.nethosting.com login failures: Aug 15 07:39:40 jackjohnson sshd[49882]: Failed password for invalid user lpd from 72.55.164.172 port 53631 ssh2 Aug 15 07:39:41 jackjohnson sshd[49897]: Failed password for invalid user lpa from 72.55.164.172 port 53802 ssh2 Aug 15 07:39:42 jackjohnson sshd[49902]: Failed password for invalid user admin from 72.55.164.172 port 53924 ssh2 Aug 15 07:39:43 jackjohnson sshd[49910]: Failed password for invalid user admin from 72.55.164.172 port 54036 ssh2 Aug 15 07:39:44 jackjohnson sshd[49919]: Failed password for invalid user admin from 72.55.164.172 port 54161 ssh2 jackjohnson.nethosting.com refused connections: -- End of security output --