Author Topic: Daily MSEC security warnings  (Read 1039 times)

Offline Neo

  • PCLinuxOS Tester
  • Sr. Member
  • *******
  • Posts: 487
  • I Spurius Furius Iustus
Daily MSEC security warnings
« on: February 24, 2012, 09:21:15 PM »
Hi All,
I have recently been getting MSEC "security warning" messages popping up in the bottom right hand corner of my desktop.  Always two at a time.
I have no idea why this would be happening.
I have not made any changes to my system other than to keep it updated via Synaptic.

I don't even know what MSEC is.

I searched but I haven't seen anyone else post with the same problem recently (most of the threads are from 2010 or 2011).

Any help that you may provide will be greatly appreciated.

Offline ternor

  • Hero Member
  • *****
  • Posts: 1801
Re: Daily MSEC security warnings
« Reply #1 on: February 24, 2012, 09:58:03 PM »
The same thing happened to me.  I forget which update caused it.  Go to the PCL Control Centre, the security section and deselect the setting in msec.

Offline Phil

  • Hero Member
  • *****
  • Posts: 743
Re: Daily MSEC security warnings
« Reply #2 on: February 25, 2012, 01:35:44 AM »
MSEC puzzled me. Paid attention and made some changes as recommended. One item still puzzles me though.

http://wiki.mandriva.com/en/Msec

To run it and change settings in terminal msecgui

To read the output as root in a terminal:

# cat /var/mail/root | less

Once I have read and ruminated on what is says:

# cat /dev/null > /var/mail/root


This puzzles me, assume it is ok:

Total of users whose home directories have unsafe permissions : 1

Security Warning: these home directory should not be owned by someone else or writable :
user=uuidd(493) : home directory is group writable.

uuidd:x:493:489:system user for util-linux-ng:/var/lib/libuuid:/bin/false






Offline Georgetoon

  • Hero Member
  • *****
  • Posts: 3202
  • Don't rush the bacon.:)
    • Georgetoon Cartoons!
Re: Daily MSEC security warnings
« Reply #3 on: March 23, 2012, 08:22:12 AM »
Noticed thsi message just today.  thanks for clarifying. I think I'l jut keep it in place for now.  Seems to be doing some good, I would guess.  I just need to understand the messages and find where I can read them once more.  they don't stay on screen for too long.
Toonfully,

Mark
-----------
Lenovo 14" ThinkPad Edge (0578F5U) with Core i3 Processor(i3-370M) 2.40 GHz 4GB RAM
Acer Aspire 9300 Laptop
Desktop Icy Dock system with AMD PHENOM X4 QUADCORE 9650 2.3GHZ 4MB L1 , ‎NVidia GEFORCE 9400GT 1GB 2X DVI PCIE graphics card, 22" Chimei monitor.

Offline 7272andy

  • PCLinuxOS Tester
  • Hero Member
  • *******
  • Posts: 1628
  • UK MLU
Re: Daily MSEC security warnings
« Reply #4 on: March 23, 2012, 08:41:40 AM »
You should find them in /var/log/msec.log
you need to open the file as root.

Regards


Bare Metal 1         Bare Metal 2
Intel Celeron 420M   Intel i5 540M
2GB Ram              4GB Ram
Intel 943GM          Radeon HD 5650 PCI Express
RT2573               RT2790
32bit KDE            32&64bit KDE

Offline ternor

  • Hero Member
  • *****
  • Posts: 1801
Re: Daily MSEC security warnings
« Reply #5 on: March 23, 2012, 08:21:34 PM »
On my system, msec also seems to write to a file called 'dead.letter' in the root (/) folder.

Offline T6

  • Super Villain
  • ******
  • Posts: 19077
  • xmas is comming!
Re: Daily MSEC security warnings
« Reply #6 on: March 23, 2012, 08:30:05 PM »
msec creates deadletter?

this forum definitively answers alot of questions!
"If you wish to make an apple pie from scratch, you must first invent the universe."

Carl Sagan

Offline YouCanToo

  • PCLinuxOS Tester
  • Hero Member
  • *******
  • Posts: 5337
  • Location: Lebanon, OR., USA
    • Spreading the word.......
Re: Daily MSEC security warnings
« Reply #7 on: March 23, 2012, 09:22:17 PM »
On my system, msec also seems to write to a file called 'dead.letter' in the root (/) folder.

I do not believe that it is msec that is actually doing that. It is usually created by
/bin/mail or other program that composes email (MUA?) when
the user aborts the composition. I suspect that it is the actual system mail program that is writing the dead.letter file and it is being triggered by the msec program.




Be sure to visit the NEW Knowledge Base


Linux is user-friendly- it's just picky who its friends are!

Offline djohnston

  • PCLinuxOS Tester
  • Hero Member
  • *******
  • Posts: 6227
  • I don't do Windows
Re: Daily MSEC security warnings
« Reply #8 on: March 24, 2012, 12:45:54 AM »
On my system, msec also seems to write to a file called 'dead.letter' in the root (/) folder.


I do not believe that it is msec that is actually doing that. It is usually created by
/bin/mail or other program that composes email (MUA?) when
the user aborts the composition. I suspect that it is the actual system mail program that is writing the dead.letter file and it is being triggered by the msec program.

I'm not sure, but I believe this behavior began with a recent update. If msec has no valid email address to send the output to, it is added to the /dead.letter file. You can set your msec preferences in a gui by running /usr/sbin/msecgui as root.



Enter an email address in the System administrator email address box and the reports will be emailed to you. You can also turn the email function off, as well as the on screen display. You can even disable the MSEC security checks. I don't believe it would be wise to disable the checks. There are quite a few options available by clicking the tabs. Be careful what you change.
Bare metal                           VBox
AMD Athlon 7750 Dual-Core    Single core
4GiB RAM                              1GiB RAM
nVidia GeForce FX 5200          64MB video
LXDE 32bit                            KDE 64bit

Registered Linux User #416378

Offline ternor

  • Hero Member
  • *****
  • Posts: 1801
Re: Daily MSEC security warnings
« Reply #9 on: March 24, 2012, 04:45:23 AM »
You can also set msec preferences in PCLinuxOS Control Centre.  I don't know what happens to the emails addressed to 'root'.  I've never seen one, unless, as you say, they are added to the dead letter file.

Offline Georgetoon

  • Hero Member
  • *****
  • Posts: 3202
  • Don't rush the bacon.:)
    • Georgetoon Cartoons!
Re: Daily MSEC security warnings
« Reply #10 on: March 24, 2012, 10:31:57 AM »
On my system, msec also seems to write to a file called 'dead.letter' in the root (/) folder.

Thank you.:)
Toonfully,

Mark
-----------
Lenovo 14" ThinkPad Edge (0578F5U) with Core i3 Processor(i3-370M) 2.40 GHz 4GB RAM
Acer Aspire 9300 Laptop
Desktop Icy Dock system with AMD PHENOM X4 QUADCORE 9650 2.3GHZ 4MB L1 , ‎NVidia GEFORCE 9400GT 1GB 2X DVI PCIE graphics card, 22" Chimei monitor.

Offline Tony

  • Hero Member
  • *****
  • Posts: 1744
  • Reason_able ;)
Re: Daily MSEC security warnings
« Reply #11 on: March 24, 2012, 11:54:09 AM »
djohnston:
Quote
Enter an email address in the System administrator email address box and the reports will be emailed to you. You can also turn the email function off, as well as the on screen display. You can even disable the MSEC security checks. I don't believe it would be wise to disable the checks. There are quite a few options available by clicking the tabs. Be careful what you change.
I'm experiencing the same MSEC check, because 'Enable MSEC tool' is selected.
A message pops up out of the Notifications area on right hand of the panel. Two of them, a few seconds apart, daily.
I'd like to know what it says,... are you saying djohnston that I have to put in an Email address to get a full log message ? I don't have the Email option checked.
Is there not a log created somewhere ?

I just leave all that Security section alone, as I wouldn't know what it means, I'd just be guessing.

As someone mentioned earlier I just access this area through the PCLinuxOS Control Centre.

It is kind of annoying, but interesting to know what the notification says, if that could be explained ?
Thanks  :)

EDIT:
Just reread and saw 7272andy said to:
Quote
You should find them in /var/log/msec.log
you need to open the file as root.
Shall check ...
« Last Edit: March 24, 2012, 12:02:39 PM by Abraxas »
*PCLOS 3.2.18-pclos2 - MiniMe 2013.x - KDE 4.10.1 - Intel(R) Pentium(R) 4 CPU 3.00GHz - 1GiB DIMM DDR 533 MHz RAM  = SHABANG ! ;) *Software Updates

Offline djohnston

  • PCLinuxOS Tester
  • Hero Member
  • *******
  • Posts: 6227
  • I don't do Windows
Re: Daily MSEC security warnings
« Reply #12 on: March 24, 2012, 04:53:50 PM »

EDIT:
Just reread and saw 7272andy said to:
Quote
You should find them in /var/log/msec.log
you need to open the file as root.
Shall check ...


It writes to a few different logs. In addition, check:

/var/log/security/mail.today
/var/log/user.log
Bare metal                           VBox
AMD Athlon 7750 Dual-Core    Single core
4GiB RAM                              1GiB RAM
nVidia GeForce FX 5200          64MB video
LXDE 32bit                            KDE 64bit

Registered Linux User #416378

Offline Tony

  • Hero Member
  • *****
  • Posts: 1744
  • Reason_able ;)
Re: Daily MSEC security warnings
« Reply #13 on: March 25, 2012, 11:02:33 AM »
Quote
It writes to a few different logs. In addition, check:

/var/log/security/mail.today
/var/log/user.log
Thanks djohnston  :)
*PCLOS 3.2.18-pclos2 - MiniMe 2013.x - KDE 4.10.1 - Intel(R) Pentium(R) 4 CPU 3.00GHz - 1GiB DIMM DDR 533 MHz RAM  = SHABANG ! ;) *Software Updates