LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-07-2012, 09:23 AM   #1
jimmy_cheese
LQ Newbie
 
Registered: Feb 2012
Posts: 2

Rep: Reputation: Disabled
many duplicated binaries - doexec, chage, dig, newgrp


I have a CentOS box that's been up for about a year. It's not got anything hugely important on it, and had a lot of PHP code that I cannot personally vouch for and is fairly old. I realise this is asking for trouble.

I did the things I'm aware of to harden SSH and restrict access via IPTables etc. Today I've noticed a lot of worrying files in /usr/bin/ and /bin/. Lots of what looks like duplicates of binaries, created over a period of a couple of months at the rate of 20 or so a day:

-rw-r--r-- 1 root root 47024 Aug 7 2011 chage;4e3f01f7
-rw-r--r-- 1 root root 47024 Aug 7 2011 chage;4e3f1007
-rw-r--r-- 1 root root 47024 Aug 8 2011 chage;4e3f1e17
-rw-r--r-- 1 root root 47024 Aug 8 2011 chage;4e3f2c27
-rw-r--r-- 1 root root 47024 Aug 8 2011 chage;4e3f3a38
-rw-r--r-- 1 root root 47024 Aug 8 2011 chage;4e3f4846

The other binaries with similar going on are - newgrp, gpasswd, lastlog, dig, usleep and doexec.

The last file date is 8th August so I don't have any logs going back that far. Is anyone able to help me in understanding what has gone on here?
 
Old 02-07-2012, 11:12 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
The file you name are part of the initscripts, shadow-utils and bind-utils packages. Their %{BUILDTIME}s are well before the date you listed. Having duplicates created at the rate of "20 or so a day" sounds like a botched cron job to me. One can encounter "{name};{random_string}" names when RPM isn't able to move the old binary out of the way. Do these binaries incidentally have the immutable bit set?
 
Old 02-07-2012, 11:48 AM   #3
jimmy_cheese
LQ Newbie
 
Registered: Feb 2012
Posts: 2

Original Poster
Rep: Reputation: Disabled
Ah - this is making sense now, thanks. I did install Linux Environment Security initially, but it caused problems so I deactivated it. So, this would have set the immutable bit for these binaries and yum couldn't auto-update, thus creating these files - is that right?
 
Old 02-07-2012, 12:07 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
That might be the case. Luckily LES has an undo function: best use that before you remove it.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
BIND9: dig <hostname> doesn't work, dig <hostname.domain.tld> does. jhwilliams Linux - Server 2 04-09-2010 01:01 PM
dig @ works, dig doesn't eelgueta Linux - Networking 6 07-09-2007 06:45 PM
alternative to newgrp stocks29 Linux - General 4 01-20-2006 09:55 AM
newgrp question bjdea1 Linux - Security 2 09-02-2004 08:55 PM
using newgrp chosmer Linux - Security 1 11-30-2002 01:20 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:50 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration