/usr/bin/login patch question
From: SecLists (lists@secure.stargate.net)Date: 12/27/01
- Previous message: Mike D. Kail: "Re: Sun Solaris login bug patches out"
- Next in thread: Casper ***: "Re: /usr/bin/login patch question"
- Reply: Casper ***: "Re: /usr/bin/login patch question"
- Reply: Peter L. Ashford: "Re: /usr/bin/login patch question"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 27 Dec 2001 13:16:18 -0500 (EST) From: SecLists <lists@secure.stargate.net> To: focus-sun@securityfocus.com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
All:
We installed the /usr/bin/login patch yesterday on a Solaris 7 box. This
box is also running Tripwire... Well, this morning Tripwire tells me the
following has changed on the system:
changed: drwxrwxr-x root 1024 Aug 24 18:35:51 2000 /usr
changed: -r-sr-sr-x root 29144 Dec 13 15:07:22 2001 /usr/bin/login
The /usr directory changed from 0755 to 0775, dated Aug 24, 2000, and of
course the /usr/bin/login changed December 13th.
Now I can understand that since the patches for this were released on or
around the 13th, that the login mtime may simply be a result of the patch
keeping its own timestamp for that binary... ultimately, the mtime should
be Dec 26th, but I am willing to accept the 13th because that is when the
patch may have been made.... but the thing I am confused on is the /usr
permission changes and the timestamp being Aug 24th...
Tripwire runs everyday so I know that the perms changing on /usr had to
happen yesterday... yes, the Tripwire DB is on secure media and the check
runs automatically, and is only updated when I do it manually... so it was
modified yesterday but the mtime is showing Aug of last year...
I am assuming that this is a result of the patch we installed but I want
to make sure and so I know to expect this type of behavior on other
boxes...
Thanks,
Shawn Duffy
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (OpenBSD)
Comment: For info see http://www.gnupg.org
iD8DBQE8K2V43Qw8DHute6kRAlL2AJ46G2qmd6/2LNjojNdTwz1CQqSTRACdGCvd
teR7mgVmKVKV/VQzCNcGr+s=
=XEKQ
-----END PGP SIGNATURE-----
- Previous message: Mike D. Kail: "Re: Sun Solaris login bug patches out"
- Next in thread: Casper ***: "Re: /usr/bin/login patch question"
- Reply: Casper ***: "Re: /usr/bin/login patch question"
- Reply: Peter L. Ashford: "Re: /usr/bin/login patch question"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]