LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-27-2011, 10:36 AM   #1
mrealty
LQ Newbie
 
Registered: Apr 2009
Posts: 6

Rep: Reputation: 0
yum installing packages all by itself - normal or security issue?


Occasionally, I will get the following in my logwatch file (this is from yesterday, and I did not login yesterday):

--------------------- yum Begin ------------------------


Packages Installed:
sendmail-cf - 8.14.2-1.fc8.i386

---------------------- yum End -------------------------


I am the only one with an account on this LAMP server, so I would be the only one to install packages or perform any sort of update. Does anyone have any idea if it's possible that this package is updating itself? It seems suspect because if my server has been hacked, chances are it's some spammer looking to use my server to forward mail.

I have not logged into the server for several days, so I know I couldn't have even accidentally updated sendmail. Could someone give me some help as to how to figure out if I have been hacked? I've done the obvious - checked previous login attempt logs - nothing is there.

[root@myserver ~]# uname -or
2.6.25.14-69.fc8 GNU/Linux

Thanks in advance for any help.
 
Old 11-27-2011, 10:40 AM   #2
TobiSGD
Moderator
 
Registered: Dec 2009
Location: Germany
Distribution: Whatever fits the task best
Posts: 17,148
Blog Entries: 2

Rep: Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886
It is very unlikely that a Fedora 8 system will update itself, just because Fedora 8 is way out of date and not been supported for a long time. There simply are no updates to apply to the system. I would strongly recommend to install a supported version of any distro, Fedora 8 has well known security issues that will never be fixed.
 
Old 11-27-2011, 05:40 PM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by TobiSGD View Post
I would strongly recommend to install a supported version of any distro, Fedora 8 has well known security issues that will never be fixed.
I'm always interested in dissecting a (perceived) compromised system however in this case I agree. The OP might learn where things went belly up but in the end that will be an exercise in futility as there's no compelling reason a Fedora 8 system should be re-installed (let alone be restored) and be allowed on the 'net again. The suggestion is to only backup files the OP can verify origin and modifications of.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
yum update issue - broken packages?? nivantha Linux - Software 2 10-19-2010 11:48 AM
FEDORA 10 - yum repo config issue - cannot see extra packages manuleka Linux - Newbie 17 02-23-2009 07:29 AM
Security Issue or normal??? tekmorph Linux - Security 6 09-09-2004 11:35 PM
installing packages using yum in fedora sven_p Linux - Software 1 03-16-2004 06:27 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:39 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration