[95416] in RedHat Linux List
RE: do I have a visitor?
daemon@ATHENA.MIT.EDU (Charles Galpin)
Sun Oct 18 11:00:32 1998
Date: Sun, 18 Oct 1998 10:56:52 -0400
From: Charles Galpin <cgalpin@lighthouse-software.com>
To: Gordon Messmer <redhat-list@redhat.com>
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com
Thanks for replying Gordon.
===== Original Message from Gordon Messmer <redhat-list@redhat.com> at
10/18/98 2:59 am
>Charles Galpin wrote:
>> and messages has
>> Oct 13 09:16:52 pooh /sbin/mingetty[1785]: tty1: invalid character ^I in
>> login name
>
>tty1 is a local console. This is not a network terminal :)
>
doh! thanks
>> Oct 13 09:20:20 pooh PAM_pwdb[23033]: bad username [
>> ]
>> Oct 13 09:20:20 pooh login[23033]: FAILED LOGIN 1 FROM (null) FOR
>> , User not known to the
>> underlying authentication module
>> Oct 13 09:20:20 pooh login[23033]: FAILED LOGIN SESSION FROM (null) FOR ,
>> Error in service module
>>
>> I looked this guy up - he has a redhat box on the net right now - with the
>> default apache page.
did anyone look at the bounced message I posted? Anyone know if the message
originated from my machine?
>>
>> Something like this happened recently. I know I've been stupid not to follow
>> up on this. Last time I asked there were primarily two confilicting
>> opinions. One was that it was an application using a wrong glibc -I have
>> only compiled two apps on my system - a majordomo wrapper and imap.
>>
>> Any comments appreciated
>
>What version of the IMAP server are you running. A member of the list
>was hacked recently, we believe through a beta version of IMAP.
imap-4.1.final-1
# ldd /usr/sbin/imapd
libcrypt.so.1 => /lib/libcrypt.so.1 (0x40004000)
libc.so.6 => /lib/libc.so.6 (0x40031000)
/lib/ld-linux.so.2 => /lib/ld-linux.so.2 (0x00000000)
do these dependecies look correct? I still don't know the difference between
glibc and ??
>Try
>"rpm -Va >> rpm.test" Look at the contents of rpm.test afterwards and
>make sure your binaries are all intact.
I've done this before, but nothing looked too out of place. But to be sure,
here a few things of interest
I get the following in /dev. I looked up what the G, M, U stand or, but have
no idea what's correct or not. Why some of the ttys have a different user of
group I don't know. Could this be the result of being hacked? can someone
tell me what to change them to? I've annotated the rpm output with the
filesystem permissions
......G. /dev/ptyp0 ( crw-rw-rw- 1 root root 2, 0 Oct 16
21:14 /dev/ptyp0 )
......G. /dev/ptyp1
......G. /dev/ptyp2
......G. /dev/ptyp3
......G. /dev/ptyp4
......G. /dev/ptyp5
......G. /dev/ptyp6
......G. /dev/ptyp7
......G. /dev/ptyp8
......G. /dev/ptyp9
......G. /dev/ptypa
......G. /dev/ptypb
......G. /dev/ptypc
......G. /dev/ptypd
......G. /dev/ptype
......G. /dev/tty0
......G. /dev/tty1
......G. /dev/tty2
......G. /dev/tty3
......G. /dev/tty4
......G. /dev/tty5
......G. /dev/tty6
......G. /dev/tty7
......G. /dev/tty8
.M....G. /dev/ttyp0 ( crw------- 1 root root 3, 0 Oct 16
21:14 /dev/ttyp0 )
......G. /dev/ttyp1 ( crw-rw-rw- 1 root root 3, 1 Oct 16
21:14 /dev/ttyp1 )
.M....G. /dev/ttyp2
.M...U.. /dev/ttyp3 ( crw--w---- 1 cgalpin tty 3, 3 Oct 18
10:46 /dev/ttyp3 )
.M....G. /dev/ttyp4
.M...U.. /dev/ttyp5
.M...U.. /dev/ttyp6
.M...U.. /dev/ttyp7
.M....G. /dev/ttyp8
.M...U.. /dev/ttyp9
.M....G. /dev/ttypa
.M...U.. /dev/ttypb
.M....G. /dev/ttypc
.M...U.. /dev/ttypd
.M....G. /dev/ttype
of course imapd has changed sice I recompiled,
S.5....T /usr/sbin/imapd ( -rwxr-xr-x 1 root root 488212 Sep
10 22:20 /usr/sbin/imapd )
the only other program I have compiled on my system is the majordomo
wrapper:
# ls -l /usr/local/majordomo-1.94.4/wrapper
-rwsr-xr-x 1 root daemon 6755 Sep 24 21:44
/usr/local/majordomo-1.94.4/wrapper
>Then reload sendmail and all
>it's configurations files, or load qmail (my personal recommendation).
>
>MSG
>
thanks
--
Charles Galpin <cgalpin@lighthouse-software.com>
--
PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
http://www.redhat.com http://archive.redhat.com
To unsubscribe: mail redhat-list-request@redhat.com with
"unsubscribe" as the Subject.