Re: Group permissions changed

From: Jan Slupski (jslupski_at_juljas.net)
Date: 09/30/05


Date: Fri, 30 Sep 2005 01:41:43 +0200 (CEST)
To: focus-linux@securityfocus.com

On Thu, 29 Sep 2005, joop gerritse wrote:

> On Wednesday 28 September 2005 20:33, sf_submit@yahoo.com wrote:
>> I posted this before on the security basics, but haven't recieved a
>> response, and it worries me a bit, so I'm sending this to a few other
>> groups in hopes that someone will have an idea about it.
>>
>> ---
>>
>> Fairly recently I noticed my ftp client wouldn't list files in certain
>> directories on my server anymore - so I ssh'd in (it's dedicated), and did
>> a ls -aFl on the files, hoping to see what the problem was - here are a few
>> of the results:
>>
>> -rw-r--r-- 1 larry 503 371 2005-02-25 08:36 head.php
>> -rw-r--r-- 1 larry 48 873 2005-09-09 03:23 foot.php
>>
>> I never set the group ids to 503 or 48, so I checked just to make sure -
>> and no groups with those ids even exist. Is there an exploit/tool that
>> causes this, and should I be worried?
>
> I seem to remember that tar preserves group numbers when unpacking an archive,
> but I cannot check it right now.

It does if you are member of that group, or unpacking as root.

But 'larry' cannot be a member of nonexisting group.
And if the archive was unpacked by root, why the owner would be right
(I assume 'larry' is expected owner of the file) if the group numbers
were random?

Jan

    _ _ _ _ _____________________________________________
    | |_| |\ | S L U P S K I jslupski@juljas.net
  |_| | | | \| http://juljas.net/



Relevant Pages

  • Re: WELCOME HOME GGC
    ... I pray that his bone marrow is free and clear also ... small and BIG worries when BIG ... OH and ERmalee SOMEONE unpacked for you! ... Yes, someone did my unpacking, because my back is so very bad that I could never have done it. ...
    (rec.travel.cruises)
  • Re: Testing some Pond Ice
    ... as "Lawn Chair Larry" did nearly 30 years ago. ... Ice will soon be ... the least of your worries. ...
    (rec.arts.sf.fandom)
  • Re: s
    ... JimK wrote: ... No worries, Larry. ... DEAD FREAKS UNITE ...
    (rec.music.gdead)
  • Re: Trying for fresh start
    ... Clear for me, Larry. ... No worries about germs living in that shit. ...
    (rec.motorcycles.harley)
  • Re: Mclarens Simulator
    ... Larry wrote: ... just worries about Ferrari's current performance, ... Ferrari. ... To rate Hamilton higher than MS after a couple of successfull races is ...
    (rec.autos.simulators)