LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-21-2010, 04:40 AM   #1
High-gain
Member
 
Registered: Dec 2004
Location: London,UK
Distribution: Mandriva 2007
Posts: 156

Rep: Reputation: 15
Back Door Notice - Pam_time_stamp


Hi there - just had the following pop up on
daily cron messages - I am using Mandriva 2009 spring

#Security Warning: the md5 checksum for one of your SUID files has changed,
#maybe an intruder modified one of these suid binary in order to put in a backdoor...
#- Checksum changed file :
#/home/jerry/tmp/daily.6/localhost/sbin/pam_timestamp_check


I have recently added the audio software 'Lame', so wonder
if this would be the cause of this message.

How do I deal with this please? Can I just delete this file?

Is there a way of seeing what #proc I have running, not by numbers.
If so, how do I stop or get rid of any #proc that I do not want or require.

Thanks for looking

Last edited by High-gain; 11-21-2010 at 04:43 AM.
 
Old 11-21-2010, 07:31 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599
Quote:
Originally Posted by High-gain View Post
Security Warning: the md5 checksum for one of your SUID files has changed
That's Mandrake's "msec"...


Quote:
Originally Posted by High-gain View Post
I have recently added the audio software 'Lame', so wonder if this would be the cause of this message.
Can I just delete this file?
How do I deal with this please?
No, 'lame' is an audio encoder, pam_timestamp_check is part of PAM (as in 'rpm -qi pam').
No, you don't delete the file. If you don't need something then you un-install the package.
Run 'rpm -Vv `rpm -qf /sbin/pam_timestamp_check --qf="%{NAME}\n"`|grep -v '^\.\{8\};' and see if '/sbin/pam_timestamp_check' is in the output?


Quote:
Originally Posted by High-gain View Post
Is there a way of seeing what #proc I have running, not by numbers. If so, how do I stop or get rid of any #proc that I do not want or require.
Completely different question. Please be verbose and specific. If you mean running unnecessary services then your (command line or UI) service interface will tell you how to stop the service and keep it from starting on reboot. If you mean other processes please show an example. Of course we could tell you to just kill it but killing processes haphazardly isn't always a good Thing.
 
Old 11-22-2010, 10:09 AM   #3
High-gain
Member
 
Registered: Dec 2004
Location: London,UK
Distribution: Mandriva 2007
Posts: 156

Original Poster
Rep: Reputation: 15
Thanks unSpawn for your help.

All copied on the first two parts of my question.

Sorry about the last part, looking at it later should
have realized it was not the same topic.
Will google it and get more info that way.

Again, thank you for your input.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Back Door message + permission changes High-gain Linux - Security 10 09-21-2010 05:13 PM
LXer: A keyhole for your system's back door LXer Syndicated Linux News 0 05-08-2007 02:46 AM
How do I hook up the net first through a linux pc then to my win pc for no back door? mwemaammeocm Linux - Networking 3 06-27-2006 06:55 AM
How do I hook up the net first through a linux pc then to my win pc for no back door? mwemaammeocm Linux - Hardware 1 06-24-2006 06:47 PM
How do I hook up the net first through a linux pc then to my win pc for no back door? mwemaammeocm Linux - Software 1 06-24-2006 06:32 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:06 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration