Quote:
Originally Posted by pan64
what is /opt/varonis/vrns_mond (is this a shell, binary, ??) You can check it with the command file.
you can try to strace it too.
|
Code:
[root@server varonis]# file vrns_mond ; stat vrns_mond
vrns_mond: setuid ELF 64-bit LSB executable, AMD x86-64, version 1 (SYSV), for GNU/Linux 2.6.9, dynamically linked (uses shared libs), stripped
File: `vrns_mond'
Size: 32896 Blocks: 80 IO Block: 4096 regular file
Device: fd05h/64773d Inode: 1048599 Links: 1
Access: (4750/-rwsr-x---) Uid: ( 0/ root) Gid: ( 603/ varonis)
Access: 2016-03-22 13:53:38.000000000 -0500
Modify: 2012-10-31 11:34:27.000000000 -0500
Change: 2016-03-22 02:43:08.000000000 -0500
[root@server varonis]# uname -a
Linux server 2.6.18-408.el5 #1 SMP Fri Dec 11 14:03:08 EST 2015 x86_64 x86_64 x86_64 GNU/Linux
[root@server varonis]# strace -o /tmp/varonis_strace_logs/vrns_mond.txt ./vrns_mond
Driver loaded.
I sent the strace output to a file under /tmp, however I'm not totally familiar with the output and I don't see any type of errors that standing right out.