LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 04-25-2003, 01:53 AM   #1
chuck77
Member
 
Registered: Nov 2001
Location: singapore
Posts: 120

Rep: Reputation: 15
/bin files corruption


Hi all. My redhat 7.1 /bin files has been corrupted... for certain files.

When i try replacement.. these are the error sign

bash-2.04# ./cp more /bin
./cp: cannot create regular file `/bin/more': Permission denied


What can i do ??? need expert advise....
 
Old 04-25-2003, 02:39 AM   #2
whansard
Senior Member
 
Registered: Dec 2002
Location: Mosquitoville
Distribution: RH 6.2, Gen2, Knoppix,arch, bodhi, studio, suse, mint
Posts: 3,304

Rep: Reputation: 65
you are root when you are trying to do this right?

boot with some linux cdrom, mount your hard drive
partition and copy the files back.

i've had a bunch of weird problems with my machine
this week. i tried compressing all the binaries with
upx. i thought it wouldn't compress stuff that would
mess up the system. the system wouldn't even boot
when i was done. a bunch of files wouldn't work
while compressed with upx. and a bunch of stuff
doesn't work now, even though i've uncompressed
everything. i had some files that didn't work, that
i wasn't allowed to copy over for some reason.
i booted another linux to do it.
 
Old 04-25-2003, 02:44 AM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
As root check the (read-write) mount flags on the partition and check with "lsattr" if the dir/binary isn't set immutable and/or undeletable.
 
Old 04-25-2003, 03:09 AM   #4
chuck77
Member
 
Registered: Nov 2001
Location: singapore
Posts: 120

Original Poster
Rep: Reputation: 15
this is the response...

bash-2.04# /usr/bin/lsattr /bin/more
bash: /usr/bin/lsattr: cannot execute binary file

what should i do next ?? pls advise. thanx..


Actually an Linux/OSF.A virus has caused this problem.
 
Old 04-25-2003, 03:21 AM   #5
Tinkster
Moderator
 
Registered: Apr 2002
Location: earth
Distribution: slackware by choice, others too :} ... android.
Posts: 23,067
Blog Entries: 11

Rep: Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928
You could try what I said yesterday, and what
has been suggested in this thread, too ....
Boot the machine with your installation CD,
mount the partition that has the /bin directory
and copy the files there manually...

Cheers,
Tink
 
Old 04-25-2003, 03:30 AM   #6
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Good you mentioned Linux/OSF.A upfront. Excellent.
Also good to mention it's part of another thread. Excellent...

Apparently when executing an infected binary it'll open a backdoor on TCP/3049 or higher (Sophos). Running an clean copy of netstat, lsof (-i) or chkrootkit should be able to prove that.
Since you managed to infect your box (as root, right) running untrusted binaries, and you don't know who accessed the system after the infection, I'd suggest you save your human readable data and reformat and reinstall. Don't save binaries and don't assume you'll get a trusted system back by just copying in clean binaries from cdr w/o the means to verify file integrity (using Aide, Samhain or tripwire incl. databases from floppy or cdr). Please read the 1st thread in the security forum, look for "Steps for Recovering from a UNIX or NT System Compromise", rebuild your box and read the stuff on hardening your boxen. Also there's a supposed cleaner at Packetstorm (search for clean-osf) but again: don't assume you'll get a trusted system back by just copying in clean binaries from cdr.

HTH
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Installing .bin-files, leave the file in /usr/local/bin/ ? lagu2653 Linux - Software 1 11-08-2005 08:30 PM
.sit files and .bin files in Linux pierre24 Linux - Newbie 2 02-02-2005 07:55 AM
Corruption of tar files from fat32 to ext3? BluePyre Linux - General 5 07-11-2004 10:40 AM
How can I install Bin Files? or tg files? GeKsKe-XP Linux - Software 3 03-23-2004 03:54 PM
cant install .bin files, tar.gz files or anyother format!!! madskillz Linux - Newbie 4 10-05-2003 10:28 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 06:16 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration