Gentoo Archives: gentoo-user

From: James <wireless@×××××××××××.com>
To: gentoo-user@l.g.o
Subject: [gentoo-user] Re: hardened: setuid
Date: Thu, 13 Jul 2006 01:25:49
Message-Id: loom.20060713T030018-215@post.gmane.org
In Reply to: Re: [gentoo-user] hardened: setuid by Donnie Berkholz
1 Donnie Berkholz <dberkholz <at> gentoo.org> writes:
2
3
4 > > /usr/athena/bin/su
5 > > /usr/athena/bin/otp
6 > > /usr/athena/bin/rcp
7 > > /usr/athena/bin/rsh
8 > > /usr/athena/bin/rlogin
9
10 > > upon greater inspection this is most troubling:
11
12 > > -rws--x--x 1 root root 108416 May 4 19:52 /usr/athena/bin/su
13 > > -rws--x--x 1 root root 105640 May 4 19:52 /usr/athena/bin/otp
14 > > -rws--x--x 1 root root 95840 May 4 19:52 /usr/athena/bin/rlogin
15
16 > > Are these part of a normal gentoo system running hardened, or is it
17 > > time to re-install this machine?
18
19 > Have you tried checking which (if any) packages own these files? Have
20 > you built anything yourself outside of portage that could have installed
21 > them?
22
23 Well I used --tree and it revealed nothing.
24
25 No this system does not have any cvs or portage overlay packages....
26
27
28 James
29
30
31
32
33
34 --
35 gentoo-user@g.o mailing list

Replies

Subject Author
Re: [gentoo-user] Re: hardened: setuid Donnie Berkholz <dberkholz@g.o>