message alerte sécurité ? [Réglé]

Ami age Membre non connecté
-
- Voir le profil du membre Ami age
- Inscrit le : 18/08/2012
- Site internet
- Groupes :
-
Modérateur
ça vous inquiète ce genre de message qui apparait dans la boite à miniature, info système
"
MSEC has performed Diff Check on localhost on juil. 22 21:10:11. Changes in system security were detected and are available in /var/log/security.log."
_______________________________________________________________________

___________________________________ Un petit clic pour Mageia ? =>> CLIQUEZ I C I :
.



___________________________________ Un petit clic pour Mageia ? =>> CLIQUEZ I C I :
.

leuhmanu Membre non connecté
-
- Voir le profil du membre leuhmanu
- Inscrit le : 19/03/2011
- Groupes :
-
Équipe Mageia
-
Membre d'Honneur

Adrien.D Membre non connecté
-
- Voir le profil du membre Adrien.D
- Inscrit le : 30/05/2011
- Site internet
- Groupes :
Il y a des paramètres qui ne sont pas selon cet outil "sécurisé" mais si t'as une mauvaise permission, il râle.
CF 2ème screenhot de la doc : http://wiki.mandriva.com/fr/Msec
Tu vois la case en bas à gauche, tu peux la décocher pour ne plus voir les notifications sur ton bureau !
Config : PC Fixe : X470 GAMING PRO- AMD Ryzen 5 2600X - 16Go RAM - Radeon RX 560 (Pilote libre) - Gentoo Linux - GNOME Desktop - Kernel 5.10 LTS
Ancien Webmaster de MageiaLinuxOnline. Les remplaçants assurent !
Ancien Webmaster de MageiaLinuxOnline. Les remplaçants assurent !


skulls Membre non connecté
-
- Voir le profil du membre skulls
- Inscrit le : 19/03/2013

ça ressemble à ce genre de chose ton /var/log/security?

En général je jete un œil sur le net avec le service associé ou dans etc/services etc..
Édit, j'ai quand même rsyslog d'installer pour compléter parce que bon l'impression qu'il fait des alertes un peu dans le vent parfois; .

Édité par skulls Le 22/07/2013 à 22h17
Ma foi sur l'avenir, bien fou qui se fiera, tel qui rit vendredi dimanche pleurera

Ami age Membre non connecté
-
- Voir le profil du membre Ami age
- Inscrit le : 18/08/2012
- Site internet
- Groupes :
-
Modérateur
Caché :
juil. 20 18:50:11 localhost info: Total of open network ports: 8
juil. 20 18:50:11 localhost info: Total of configured firewall rules: 100
juil. 20 18:50:11 localhost info: Total local users: 24
juil. 20 18:50:11 localhost info: Total local group: 46
juil. 20 18:50:11 localhost diff: *** Diff Check, juil. 20 18:50:11 ***
juil. 20 18:50:11 localhost diff:
juil. 20 18:50:11 localhost diff: Security Warning: change in processes with open network ports found :
juil. 20 18:50:11 localhost diff: - Added processes with open network ports : udp 0 0 *:55140 *:* dhclient
juil. 20 18:50:11 localhost diff: - Added processes with open network ports : udp 0 0 *:59916 *:* avahi-daemon: r
juil. 20 18:50:11 localhost diff: - Added processes with open network ports : udp 0 0 *:48777 *:* dhclient
juil. 20 18:50:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:41699 *:* avahi-daemon: r
juil. 20 18:50:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:63713 *:* dhclient
juil. 20 18:50:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:34237 *:* dhclient
juil. 21 08:42:11 localhost info: Total of open network ports: 8
juil. 21 08:42:11 localhost info: Total of configured firewall rules: 100
juil. 21 08:42:11 localhost info: Total local users: 24
juil. 21 08:42:11 localhost info: Total local group: 46
juil. 21 08:42:11 localhost diff: *** Diff Check, juil. 21 08:42:11 ***
juil. 21 08:42:11 localhost diff:
juil. 21 08:42:11 localhost diff: Security Warning: change in processes with open network ports found :
juil. 21 08:42:11 localhost diff: - Added processes with open network ports : udp 0 0 *:49568 *:* avahi-daemon: r
juil. 21 08:42:11 localhost diff: - Added processes with open network ports : udp 0 0 *:50279 *:* dhclient
juil. 21 08:42:11 localhost diff: - Added processes with open network ports : udp 0 0 *:36416 *:* dhclient
juil. 21 08:42:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:55140 *:* dhclient
juil. 21 08:42:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:59916 *:* avahi-daemon: r
juil. 21 08:42:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:48777 *:* dhclient
juil. 21 09:03:02 localhost info: Total of Suid Root files: 30
juil. 21 09:03:02 localhost info: Total of Sgid files: 16
juil. 21 09:03:02 localhost info: Total of World Writable files: 123
juil. 21 09:03:02 localhost info: Total of Un-owned files: 0
juil. 21 09:03:02 localhost info: Total of Un-owned group files: 0
juil. 21 09:03:02 localhost info: Total of SUID files with controlled MD5 checksum: 30
juil. 21 09:03:02 localhost info: Total of installed packages: 2071
juil. 21 09:03:02 localhost info: Chkrootkit check: skipped (chkrootkit not found)
juil. 21 09:03:02 localhost diff: *** Diff Check, juil. 21 09:03:02 ***
juil. 21 09:03:02 localhost diff:
juil. 21 09:03:02 localhost diff: Security Warning: change in World Writable permissions on files found :
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-09Rk7o
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-183idP
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-Dh5a87
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-Du97nZ
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-FufqID
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-lK9X2X
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-MHKInP
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-OL8rj0
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-pAffMC
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-qTqMmP
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-QXMVDy
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-SI0ZNG
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-u2U8Gn
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-WEYitY
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-WFwzrk
juil. 22 21:10:11 localhost info: Total of open network ports: 8
juil. 22 21:10:11 localhost info: Total of configured firewall rules: 100
juil. 22 21:10:11 localhost info: Total local users: 25
juil. 22 21:10:11 localhost info: Total local group: 47
juil. 22 21:10:11 localhost diff: *** Diff Check, juil. 22 21:10:11 ***
juil. 22 21:10:11 localhost diff:
juil. 22 21:10:11 localhost diff: Security Warning: change in processes with open network ports found :
juil. 22 21:10:11 localhost diff: - Added processes with open network ports : udp 0 0 *:17153 *:* dhclient
juil. 22 21:10:11 localhost diff: - Added processes with open network ports : udp 0 0 *:55653 *:* avahi-daemon: r
juil. 22 21:10:11 localhost diff: - Added processes with open network ports : udp 0 0 *:45527 *:* dhclient
juil. 22 21:10:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:49568 *:* avahi-daemon: r
juil. 22 21:10:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:50279 *:* dhclient
juil. 22 21:10:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:36416 *:* dhclient
juil. 22 21:10:11 localhost diff:
juil. 22 21:10:11 localhost diff: Security Warning: change in local users found :
juil. 22 21:10:11 localhost diff: - Added local users : visiteur
juil. 22 21:10:11 localhost diff:
juil. 22 21:10:11 localhost diff: Security Warning: change in local groups found :
juil. 22 21:10:11 localhost diff: - Added local groups : visiteur
juil. 24 19:15:11 localhost info: Total of open network ports: 8
juil. 24 19:15:11 localhost info: Total of configured firewall rules: 100
juil. 24 19:15:11 localhost info: Total local users: 25
juil. 24 19:15:11 localhost info: Total local group: 47
juil. 24 19:15:11 localhost diff: *** Diff Check, juil. 24 19:15:11 ***
juil. 24 19:15:11 localhost diff:
juil. 24 19:15:11 localhost diff: Security Warning: change in processes with open network ports found :
juil. 24 19:15:11 localhost diff: - Added processes with open network ports : udp 0 0 *:45785 *:* avahi-daemon: r
juil. 24 19:15:11 localhost diff: - Added processes with open network ports : udp 0 0 *:30013 *:* dhclient
juil. 24 19:15:11 localhost diff: - Added processes with open network ports : udp 0 0 *:4611 *:* dhclient
juil. 24 19:15:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:17153 *:* dhclient
juil. 24 19:15:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:55653 *:* avahi-daemon: r
juil. 24 19:15:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:45527 *:* dhclient
juil. 20 18:50:11 localhost info: Total of configured firewall rules: 100
juil. 20 18:50:11 localhost info: Total local users: 24
juil. 20 18:50:11 localhost info: Total local group: 46
juil. 20 18:50:11 localhost diff: *** Diff Check, juil. 20 18:50:11 ***
juil. 20 18:50:11 localhost diff:
juil. 20 18:50:11 localhost diff: Security Warning: change in processes with open network ports found :
juil. 20 18:50:11 localhost diff: - Added processes with open network ports : udp 0 0 *:55140 *:* dhclient
juil. 20 18:50:11 localhost diff: - Added processes with open network ports : udp 0 0 *:59916 *:* avahi-daemon: r
juil. 20 18:50:11 localhost diff: - Added processes with open network ports : udp 0 0 *:48777 *:* dhclient
juil. 20 18:50:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:41699 *:* avahi-daemon: r
juil. 20 18:50:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:63713 *:* dhclient
juil. 20 18:50:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:34237 *:* dhclient
juil. 21 08:42:11 localhost info: Total of open network ports: 8
juil. 21 08:42:11 localhost info: Total of configured firewall rules: 100
juil. 21 08:42:11 localhost info: Total local users: 24
juil. 21 08:42:11 localhost info: Total local group: 46
juil. 21 08:42:11 localhost diff: *** Diff Check, juil. 21 08:42:11 ***
juil. 21 08:42:11 localhost diff:
juil. 21 08:42:11 localhost diff: Security Warning: change in processes with open network ports found :
juil. 21 08:42:11 localhost diff: - Added processes with open network ports : udp 0 0 *:49568 *:* avahi-daemon: r
juil. 21 08:42:11 localhost diff: - Added processes with open network ports : udp 0 0 *:50279 *:* dhclient
juil. 21 08:42:11 localhost diff: - Added processes with open network ports : udp 0 0 *:36416 *:* dhclient
juil. 21 08:42:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:55140 *:* dhclient
juil. 21 08:42:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:59916 *:* avahi-daemon: r
juil. 21 08:42:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:48777 *:* dhclient
juil. 21 09:03:02 localhost info: Total of Suid Root files: 30
juil. 21 09:03:02 localhost info: Total of Sgid files: 16
juil. 21 09:03:02 localhost info: Total of World Writable files: 123
juil. 21 09:03:02 localhost info: Total of Un-owned files: 0
juil. 21 09:03:02 localhost info: Total of Un-owned group files: 0
juil. 21 09:03:02 localhost info: Total of SUID files with controlled MD5 checksum: 30
juil. 21 09:03:02 localhost info: Total of installed packages: 2071
juil. 21 09:03:02 localhost info: Chkrootkit check: skipped (chkrootkit not found)
juil. 21 09:03:02 localhost diff: *** Diff Check, juil. 21 09:03:02 ***
juil. 21 09:03:02 localhost diff:
juil. 21 09:03:02 localhost diff: Security Warning: change in World Writable permissions on files found :
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-09Rk7o
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-183idP
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-Dh5a87
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-Du97nZ
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-FufqID
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-lK9X2X
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-MHKInP
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-OL8rj0
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-pAffMC
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-qTqMmP
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-QXMVDy
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-SI0ZNG
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-u2U8Gn
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-WEYitY
juil. 21 09:03:02 localhost diff: - Added World Writable permissions on files : /var/tmp/systemd-private-WFwzrk
juil. 22 21:10:11 localhost info: Total of open network ports: 8
juil. 22 21:10:11 localhost info: Total of configured firewall rules: 100
juil. 22 21:10:11 localhost info: Total local users: 25
juil. 22 21:10:11 localhost info: Total local group: 47
juil. 22 21:10:11 localhost diff: *** Diff Check, juil. 22 21:10:11 ***
juil. 22 21:10:11 localhost diff:
juil. 22 21:10:11 localhost diff: Security Warning: change in processes with open network ports found :
juil. 22 21:10:11 localhost diff: - Added processes with open network ports : udp 0 0 *:17153 *:* dhclient
juil. 22 21:10:11 localhost diff: - Added processes with open network ports : udp 0 0 *:55653 *:* avahi-daemon: r
juil. 22 21:10:11 localhost diff: - Added processes with open network ports : udp 0 0 *:45527 *:* dhclient
juil. 22 21:10:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:49568 *:* avahi-daemon: r
juil. 22 21:10:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:50279 *:* dhclient
juil. 22 21:10:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:36416 *:* dhclient
juil. 22 21:10:11 localhost diff:
juil. 22 21:10:11 localhost diff: Security Warning: change in local users found :
juil. 22 21:10:11 localhost diff: - Added local users : visiteur
juil. 22 21:10:11 localhost diff:
juil. 22 21:10:11 localhost diff: Security Warning: change in local groups found :
juil. 22 21:10:11 localhost diff: - Added local groups : visiteur
juil. 24 19:15:11 localhost info: Total of open network ports: 8
juil. 24 19:15:11 localhost info: Total of configured firewall rules: 100
juil. 24 19:15:11 localhost info: Total local users: 25
juil. 24 19:15:11 localhost info: Total local group: 47
juil. 24 19:15:11 localhost diff: *** Diff Check, juil. 24 19:15:11 ***
juil. 24 19:15:11 localhost diff:
juil. 24 19:15:11 localhost diff: Security Warning: change in processes with open network ports found :
juil. 24 19:15:11 localhost diff: - Added processes with open network ports : udp 0 0 *:45785 *:* avahi-daemon: r
juil. 24 19:15:11 localhost diff: - Added processes with open network ports : udp 0 0 *:30013 *:* dhclient
juil. 24 19:15:11 localhost diff: - Added processes with open network ports : udp 0 0 *:4611 *:* dhclient
juil. 24 19:15:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:17153 *:* dhclient
juil. 24 19:15:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:55653 *:* avahi-daemon: r
juil. 24 19:15:11 localhost diff: - Removed processes with open network ports : udp 0 0 *:45527 *:* dhclient

Édité par Ami age Le 24/07/2013 à 22h53
_______________________________________________________________________

___________________________________ Un petit clic pour Mageia ? =>> CLIQUEZ I C I :
.



___________________________________ Un petit clic pour Mageia ? =>> CLIQUEZ I C I :
.

Ami age Membre non connecté
-
- Voir le profil du membre Ami age
- Inscrit le : 18/08/2012
- Site internet
- Groupes :
-
Modérateur
_______________________________________________________________________

___________________________________ Un petit clic pour Mageia ? =>> CLIQUEZ I C I :
.



___________________________________ Un petit clic pour Mageia ? =>> CLIQUEZ I C I :
.

Visiteur
Visiteur
Ami age :
repérez vous quelque chose méritant une attention particulière dans l'extrait ci dessus ?.
bon suis pas un expert mais c'est clean ton log
puis ne t’inquiète pas trop avec le diff check, tu as une alerte quasi tout le temps, en fait pour faire simple le lundi il prend un photo de ton disque dur et au rescan suivant il indique tout les différences donc si tu as mise a jour, effacé ou modifié, ou si une appli a eu besoin d'une modification temporaire dans le temp etc etc tu auras une alerte par msec.
donc te stress pas trop , tu peux toujours regarder dans les logs voir si quelque chose te semble vraiment suspect mais tu te rendras vite compte que c'est des mise a jour, des fichiers modifiés temporaire, des fichiers que tu as supprimér ou modifié, par contre si tu vois par exemple que le kernel ou ses modules ou un fichier important a été modifier sans qu'a ta connaissance il y ait eu mise a jour ou autre modif voulu la il faut te pencher sur le truc
bref te stress pas linux c pas windaube
Édité par Visiteur Le 17/08/2013 à 16h22

Ami age Membre non connecté
-
- Voir le profil du membre Ami age
- Inscrit le : 18/08/2012
- Site internet
- Groupes :
-
Modérateur

_______________________________________________________________________

___________________________________ Un petit clic pour Mageia ? =>> CLIQUEZ I C I :
.



___________________________________ Un petit clic pour Mageia ? =>> CLIQUEZ I C I :
.

Rockett50 Membre non connecté
-
- Voir le profil du membre Rockett50
- Inscrit le : 30/05/2013
Répondre
Vous n'êtes pas autorisé à écrire dans cette catégorie