1 |
James wrote: |
2 |
> Hello |
3 |
> |
4 |
> I was performing a routine security audit using: |
5 |
> |
6 |
> find / -user root -perm -4000 -print |
7 |
> |
8 |
> which found these peculiar files: |
9 |
> |
10 |
> /usr/athena/bin/su |
11 |
> /usr/athena/bin/otp |
12 |
> /usr/athena/bin/rcp |
13 |
> /usr/athena/bin/rsh |
14 |
> /usr/athena/bin/rlogin |
15 |
> |
16 |
> |
17 |
> upon greater inspection this is most troubling: |
18 |
> |
19 |
> -rws--x--x 1 root root 108416 May 4 19:52 /usr/athena/bin/su |
20 |
> -rws--x--x 1 root root 105640 May 4 19:52 /usr/athena/bin/otp |
21 |
> -rws--x--x 1 root root 95840 May 4 19:52 /usr/athena/bin/rlogin |
22 |
> |
23 |
> |
24 |
> Are these part of a normal gentoo system running hardened, or is it |
25 |
> time to re-install this machine? |
26 |
|
27 |
Have you tried checking which (if any) packages own these files? Have |
28 |
you built anything yourself outside of portage that could have installed |
29 |
them? |
30 |
|
31 |
Thanks, |
32 |
Donnie |