LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-07-2010, 12:34 PM   #1
velouria
Member
 
Registered: May 2008
Posts: 57

Rep: Reputation: 15
security issues on fedora 13?


hi there

im using fedora 13. my cat /etc/passwd|cut -d"." -f1 gives

bin:x:1:1:bin:/bin:/sbin/nologin
daemon:x:2:2:daemon:/sbin:/sbin/nologin
adm:x:3:4:adm:/var/adm:/sbin/nologin
lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin
sync:x:5:0:sync:/sbin:/bin/sync
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
halt:x:7:0:halt:/sbin:/sbin/halt
mail:x:8:12:mail:/var/spool/mail:/sbin/nologin
uucp:x:10:14:uucp:/var/spool/uucp:/sbin/nologin
operator:x:11:0perator:/root:/sbin/nologin
games:x:12:100:games:/usr/games:/sbin/nologin
gopher:x:13:30:gopher:/var/gopher:/sbin/nologin
ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin
nobody:x:99:99:Nobody:/:/sbin/nologin
dbus:x:81:81:System message bus:/:/sbin/nologin
usbmuxd:x:113:113:usbmuxd user:/:/sbin/nologin
avahi-autoipd:x:499:499:avahi-autoipd:/var/lib/avahi-autoipd:/sbin/nologin
vcsa:x:69:498:virtual console memory owner:/dev:/sbin/nologin
rtkit:x:498:497:RealtimeKit:/proc:/sbin/nologin
abrt:x:497:495::/etc/abrt:/sbin/nologin
nscd:x:28:494:NSCD Daemon:/:/sbin/nologin
tcpdump:x:72:72::/:/sbin/nologin
avahi:x:496:491:avahi-daemon:/var/run/avahi-daemon:/sbin/nologin
haldaemon:x:68:490:HAL daemon:/:/sbin/nologin
openvpn:x:495:489:OpenVPN:/etc/openvpn:/sbin/nologin
ntp:x:38:38::/etc/ntp:/sbin/nologin
apache:x:48:488:Apache:/var/www:/sbin/nologin
saslauth:x:494:487:"Saslauthd user":/var/empty/saslauth:/sbin/nologin
mailnull:x:47:486::/var/spool/mqueue:/sbin/nologin
smmsp:x:51:485::/var/spool/mqueue:/sbin/nologin
nm-openconnect:x:493:484:NetworkManager user for OpenConnect:/:/sbin/nologin
sshd:x:74:483:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin
smolt:x:492:482:Smolt:/usr/share/smolt:/sbin/nologin
pulse:x:491:481:PulseAudio System Daemon:/var/run/pulse:/sbin/nologin
gdm:x:42:479::/var/lib/gdm:/sbin/nologin
me:x:500:500:me:/home/me:/bin/bash
mysql:x:27:27:MySQL Server:/var/lib/mysql:/bin/bash
hsqldb:x:96:96::/var/lib/hsqldb:/sbin/nologin

is it all normal?

moreover my ps -ef gives
root 1 0 0 10:52 ? 00:00:01 /sbin/init
root 2 0 0 10:52 ? 00:00:00 [kthreadd]
root 3 2 0 10:52 ? 00:00:00 [migration/0]
root 4 2 0 10:52 ? 00:00:00 [ksoftirqd/0]
root 5 2 0 10:52 ? 00:00:00 [watchdog/0]
root 6 2 0 10:52 ? 00:00:00 [migration/1]
root 7 2 0 10:52 ? 00:00:00 [ksoftirqd/1]
root 8 2 0 10:52 ? 00:00:00 [watchdog/1]
root 9 2 0 10:52 ? 00:00:00 [events/0]
root 10 2 0 10:52 ? 00:00:00 [events/1]
root 11 2 0 10:52 ? 00:00:00 [cpuset]
root 12 2 0 10:52 ? 00:00:00 [khelper]
root 13 2 0 10:52 ? 00:00:00 [netns]
root 14 2 0 10:52 ? 00:00:00 [async/mgr]
root 15 2 0 10:52 ? 00:00:00 [pm]
root 16 2 0 10:52 ? 00:00:00 [sync_supers]
root 17 2 0 10:52 ? 00:00:00 [bdi-default]
root 18 2 0 10:52 ? 00:00:00 [kintegrityd/0]
root 19 2 0 10:52 ? 00:00:00 [kintegrityd/1]
root 20 2 0 10:52 ? 00:00:00 [kblockd/0]
root 21 2 0 10:52 ? 00:00:00 [kblockd/1]
root 22 2 0 10:52 ? 00:00:00 [kacpid]
root 23 2 0 10:52 ? 00:00:00 [kacpi_notify]
root 24 2 0 10:52 ? 00:00:00 [kacpi_hotplug]
root 25 2 0 10:52 ? 00:00:00 [ata/0]
root 26 2 0 10:52 ? 00:00:00 [ata/1]
root 27 2 0 10:52 ? 00:00:00 [ata_aux]
root 28 2 0 10:52 ? 00:00:00 [ksuspend_usbd]
root 29 2 0 10:52 ? 00:00:00 [khubd]
root 30 2 0 10:52 ? 00:00:00 [kseriod]
root 33 2 0 10:52 ? 00:00:00 [khungtaskd]
root 34 2 0 10:52 ? 00:00:00 [kswapd0]
root 35 2 0 10:52 ? 00:00:00 [ksmd]
root 36 2 0 10:52 ? 00:00:00 [aio/0]
root 37 2 0 10:52 ? 00:00:00 [aio/1]
root 38 2 0 10:52 ? 00:00:00 [crypto/0]
root 39 2 0 10:52 ? 00:00:00 [crypto/1]
root 52 2 0 10:52 ? 00:00:00 [scsi_eh_0]
root 53 2 0 10:52 ? 00:00:00 [scsi_eh_1]
root 54 2 0 10:52 ? 00:00:00 [scsi_eh_2]
root 55 2 0 10:52 ? 00:00:00 [scsi_eh_3]
root 56 2 0 10:52 ? 00:00:00 [scsi_eh_4]
root 57 2 0 10:52 ? 00:00:01 [scsi_eh_5]
root 63 2 0 10:52 ? 00:00:00 [kpsmoused]
root 64 2 0 10:52 ? 00:00:00 [kstriped]
root 65 2 0 10:52 ? 00:00:00 [ksnapd]
root 66 2 0 10:52 ? 00:00:00 [usbhid_resumer]
root 173 2 0 10:52 ? 00:00:00 [i915]
root 415 2 0 10:52 ? 00:00:00 [kdmflush]
root 422 2 0 10:52 ? 00:00:00 [kdmflush]
root 431 2 0 10:52 ? 00:00:00 [jbd2/dm-0-8]
root 432 2 0 10:52 ? 00:00:00 [ext4-dio-unwrit]
root 433 2 0 10:52 ? 00:00:00 [ext4-dio-unwrit]
root 520 1 0 10:52 ? 00:00:00 /sbin/udevd -d
root 784 2 0 10:52 ? 00:00:00 [cfg80211]
root 801 2 0 10:52 ? 00:00:00 [hd-audio0]
root 806 2 0 10:52 ? 00:00:07 [phy0]
root 924 2 0 10:53 ? 00:00:00 [kdmflush]
root 968 2 0 10:53 ? 00:00:00 [jbd2/sda5-8]
root 969 2 0 10:53 ? 00:00:00 [ext4-dio-unwrit]
root 970 2 0 10:53 ? 00:00:00 [ext4-dio-unwrit]
root 971 2 0 10:53 ? 00:00:00 [jbd2/dm-2-8]
root 972 2 0 10:53 ? 00:00:00 [ext4-dio-unwrit]
root 973 2 0 10:53 ? 00:00:00 [ext4-dio-unwrit]
root 1020 2 0 10:53 ? 00:00:00 [kauditd]
root 1022 1 0 10:53 ? 00:00:00 /usr/bin/system-setup-keyboard
root 1100 2 0 10:53 ? 00:00:00 [flush-253:2]
root 1157 1 0 10:53 ? 00:00:00 auditd
root 1159 1157 0 10:53 ? 00:00:00 /sbin/audispd
root 1172 1159 0 10:53 ? 00:00:00 /usr/sbin/sedispatch
root 1184 1 0 10:53 ? 00:00:00 /sbin/rsyslogd -c 4
root 1205 2 0 10:53 ? 00:00:05 [kondemand/0]
root 1206 2 0 10:53 ? 00:00:05 [kondemand/1]
root 1232 1 0 10:53 ? 00:00:00 mdadm --monitor --scan -f --pid-
dbus 1241 1 0 10:53 ? 00:00:03 dbus-daemon --system
root 1252 1 0 10:53 ? 00:00:01 NetworkManager --pid-file=/var/r
root 1257 1 0 10:53 ? 00:00:00 /usr/sbin/modem-manager
avahi 1263 1 0 10:53 ? 00:00:00 avahi-daemon: running [linux.loc
avahi 1264 1263 0 10:53 ? 00:00:00 avahi-daemon: chroot helper
root 1272 1 0 10:53 ? 00:00:00 /usr/sbin/wpa_supplicant -c /etc
root 1279 1 0 10:53 ? 00:00:00 cupsd -C /etc/cups/cupsd.conf
root 1303 1 0 10:53 ? 00:00:00 /usr/sbin/acpid
68 1311 1 0 10:53 ? 00:00:00 hald
root 1312 1311 0 10:53 ? 00:00:00 hald-runner
root 1341 1312 0 10:53 ? 00:00:00 hald-addon-input: Listening on /
root 1344 1312 0 10:53 ? 00:00:00 /usr/libexec/hald-addon-rfkill-k
root 1351 1312 0 10:53 ? 00:00:00 /usr/libexec/hald-addon-generic-
root 1359 1312 0 10:53 ? 00:00:01 hald-addon-storage: polling /dev
68 1360 1312 0 10:53 ? 00:00:00 /usr/libexec/hald-addon-acpi
ntp 1378 1 0 10:53 ? 00:00:00 ntpd -u ntp:ntp -p /var/run/ntpd
root 1414 1 0 10:53 ? 00:00:00 /usr/sbin/abrtd
root 1423 1 0 10:53 ? 00:00:00 /usr/sbin/gpm -m /dev/input/mice
root 1431 1 0 10:53 ? 00:00:00 crond
root 1442 1 0 10:53 ? 00:00:00 /usr/sbin/atd
root 1455 1 0 10:53 ? 00:00:00 /usr/sbin/gdm-binary -nodaemon
root 1460 1 0 10:53 tty2 00:00:00 /sbin/mingetty /dev/tty2
root 1462 1 0 10:53 tty3 00:00:00 /sbin/mingetty /dev/tty3
root 1464 1 0 10:53 tty4 00:00:00 /sbin/mingetty /dev/tty4
root 1466 520 0 10:53 ? 00:00:00 /sbin/udevd -d
root 1468 520 0 10:53 ? 00:00:00 /sbin/udevd -d
root 1469 1 0 10:53 tty5 00:00:00 /sbin/mingetty /dev/tty5
root 1471 1 0 10:53 tty6 00:00:00 /sbin/mingetty /dev/tty6
root 1483 1455 0 10:53 ? 00:00:00 /usr/libexec/gdm-simple-slave --
root 1486 1483 5 10:53 tty1 00:08:31 /usr/bin/Xorg :0 -nr -verbose -a
root 1502 1 0 10:53 ? 00:00:00 /usr/sbin/console-kit-daemon --n
gdm 1572 1 0 10:53 ? 00:00:00 /usr/bin/dbus-launch --exit-with
root 1578 1 0 10:53 ? 00:00:01 /usr/libexec/upowerd
gdm 1635 1 0 10:53 ? 00:00:00 /usr/libexec/polkit-gnome-authen
root 1639 1 0 10:53 ? 00:00:00 /usr/libexec/polkit-1/polkitd
rtkit 1650 1 0 10:53 ? 00:00:00 /usr/libexec/rtkit-daemon
root 1656 1483 0 10:53 ? 00:00:00 pam: gdm-password

root 3452 2 0 12:53 ? 00:00:00 [flush-253:0]

root 3933 1 0 13:22 ? 00:00:00 /sbin/mount.ntfs /dev/sda2 /medi

root 4000 1252 0 13:28 ? 00:00:00 /sbin/dhclient -d -4 -sf /usr/li
smmsp 4069 1 0 13:28 ? 00:00:00 sendmail: Queue runner@01:00:00
root 4071 1 0 13:28 ? 00:00:00 sendmail: accepting connections

what's the deal with the sendmail entries?

do i need to format and change distribution?
 
Old 08-07-2010, 01:06 PM   #2
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 25,809

Rep: Reputation: 7747Reputation: 7747Reputation: 7747Reputation: 7747Reputation: 7747Reputation: 7747Reputation: 7747Reputation: 7747Reputation: 7747Reputation: 7747Reputation: 7747
Format and change distros if you want. Don't see anything that's wrong with any of what you posted. What, exactly, were you EXPECTING to see???
 
Old 08-07-2010, 01:10 PM   #3
velouria
Member
 
Registered: May 2008
Posts: 57

Original Poster
Rep: Reputation: 15
thanks for replying

i compare with the ubuntu output on my other pc and i dont find a sendmail entry eveytime i connect to the internet for instance. is that normal?
 
Old 08-07-2010, 03:00 PM   #4
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 25,809

Rep: Reputation: 7747Reputation: 7747Reputation: 7747Reputation: 7747Reputation: 7747Reputation: 7747Reputation: 7747Reputation: 7747Reputation: 7747Reputation: 7747Reputation: 7747
Quote:
Originally Posted by velouria View Post
thanks for replying

i compare with the ubuntu output on my other pc and i dont find a sendmail entry eveytime i connect to the internet for instance. is that normal?
No way of knowing, by what you provided. Totally normal if you have sendmail set up and/or running. You CAN have it running on Ubuntu, or not...just like on any other distro.
 
Old 08-07-2010, 08:33 PM   #5
John VV
LQ Muse
 
Registered: Aug 2005
Location: A2 area Mi.
Posts: 17,602

Rep: Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648
fedora has sendmail servise on bu default
it uses it for kernel error logs and se logs

but it is safe to turn it off
see the documentation on the Mjm page -- one of the BEST fedora pages
-- i still use it sometimes and i do not use fedora any more
http://www.mjmwired.net/resources/mjm-fedora-f13.html
and "Services in Fedora 13"
http://www.mjmwired.net/resources/mjm-services-f13.html
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Security issues mattjohnstone22 Linux - Newbie 5 02-07-2007 05:05 PM
Security Issues? Xon Linux - Security 3 10-04-2004 11:45 PM
security issues with a RH 9.2 merlin Linux - Security 1 02-24-2004 04:13 PM
NAT security issues ilumin8d Linux - Security 1 05-10-2002 11:35 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:53 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration