Re: Security Check Diffs Question
From: Pierre-Luc Lespérance (silence@oksala.org)
Date: 07/25/01
- Next message: Dean M. Phillips: "Re: Security Check Diffs Question"
- Previous message: Kris Kennaway: "Re: Security Check Diffs Question"
- In reply to: Jon Loeliger: "Security Check Diffs Question"
- Next in thread: Rob Simmons: "Re: Security Check Diffs Question"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Tue, 24 Jul 2001 19:16:16 -0400 From: Pierre-Luc Lespérance <silence@oksala.org> To: security@freebsd.org
Jon Loeliger wrote:
>
> Hi Folks,
>
> This morning, on a machine that's been up for 33 days,
> I suddenly saw these /etc/security diffs:
>
> <host> setuid diffs:
> 20,22c20,22
> < 8047 -r-sr-xr-x 6 root wheel 32184 Nov 20 06:01:52 2000 /usr/bin/chfn
> < 8047 -r-sr-xr-x 6 root wheel 32184 Nov 20 06:01:52 2000 /usr/bin/chpass
> < 8047 -r-sr-xr-x 6 root wheel 32184 Nov 20 06:01:52 2000 /usr/bin/chsh
> ---
> > 8047 -r-sr-xr-x 5 root wheel 32184 Nov 20 06:01:52 2000 /usr/bin/chfn
> > 8047 -r-sr-xr-x 5 root wheel 32184 Nov 20 06:01:52 2000 /usr/bin/chpass
> > 8047 -r-sr-xr-x 5 root wheel 32184 Nov 20 06:01:52 2000 /usr/bin/chsh
> 53,55c53,55
> < 8047 -r-sr-xr-x 6 root wheel 32184 Nov 20 06:01:52 2000 /usr/bin/ypchfn
> < 8047 -r-sr-xr-x 6 root wheel 32184 Nov 20 06:01:52 2000 /usr/bin/ypchpass
> < 8047 -r-sr-xr-x 6 root wheel 32184 Nov 20 06:01:52 2000 /usr/bin/ypchsh
> ---
> > 8270 -r-sr-xr-x 1 root wheel 32184 Nov 20 06:01:52 2000 /usr/bin/ypchfn
> > 8047 -r-sr-xr-x 5 root wheel 32184 Nov 20 06:01:52 2000 /usr/bin/ypchpass
> > 8047 -r-sr-xr-x 5 root wheel 32184 Nov 20 06:01:52 2000 /usr/bin/ypchsh
If your box is not really* important. You sould lets it like that
and wait for the return of the Evil telnetd cracker (if any) and mail
a little paper to is ISP.
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message
- Next message: Dean M. Phillips: "Re: Security Check Diffs Question"
- Previous message: Kris Kennaway: "Re: Security Check Diffs Question"
- In reply to: Jon Loeliger: "Security Check Diffs Question"
- Next in thread: Rob Simmons: "Re: Security Check Diffs Question"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|