LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-06-2003, 02:26 PM   #1
ekdya
Member
 
Registered: Oct 2003
Posts: 280

Rep: Reputation: 30
strange uer in my ls -l


$ls -l
-rw------- 1 man users 7434 Oct 5 14:27 zmanBOYRtR
I don't remeber making an account for this user or even having a group named uses.

how do I go about this?

thanks
 
Old 10-06-2003, 02:59 PM   #2
Blinker_Fluid
Member
 
Registered: Jul 2003
Location: Clinging to my guns and religion.
Posts: 683

Rep: Reputation: 63
users is a default group. I have never heard of a default man user though...
Some things to check:
last <-- does this show any users that you don't know or are unfamiliar with?
/etc/passwd <-- There are system users that you probably won't want to get rid of most will have /sbin/nologin for the shell. What shell does the man user have?
/etc/shadow <-- does the man user have a password set? (second field) I believe !! indicates nologin

Other than that maybe check /var/log/messages or /var/log/secure...
There is a start anyway...
 
Old 10-07-2003, 02:02 AM   #3
ekdya
Member
 
Registered: Oct 2003
Posts: 280

Original Poster
Rep: Reputation: 30
Quote:
Originally posted by Blinker_Fluid
users is a default group. I have never heard of a default man user though...
Some things to check:
last <-- does this show any users that you don't know or are unfamiliar with?

no mention of man here

/etc/passwd <-- There are system users that you probably won't want to get rid of most will have /sbin/nologin for the shell. What shell does the man user have?

~# grep "man" /etc/passwd
man:x:6:100:man:/var/cache/man:/bin/sh


/etc/shadow <-- does the man user have a password set? (second field) I believe !! indicates nologin

# grep "man" /etc/shadow
man:*:12285:0:99999:7:::

Other than that maybe check /var/log/messages or /var/log/secure...
There is a start anyway...
 
Old 10-07-2003, 03:09 AM   #4
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
Perhaps you should start by saying where you found the file and what the contents are (or what the file type is)?

Is it in /tmp? If not, where?

What file type is it?
file zmanBOYRtR

What are the contents?
less zmanBOYRtR

Do you have chkrootkit or tripwire installed (apparently not)? When you do get it figured out, it would be a good idea to install some file system monitoring tools.
 
Old 10-07-2003, 04:49 AM   #5
ekdya
Member
 
Registered: Oct 2003
Posts: 280

Original Poster
Rep: Reputation: 30
/tmp# file zmanBOYRtR
zmanBOYRtR: troff or preprocessor input text
/tmp# less zmanBOYRtR

.\" $OpenBSD: lpr.1,v 1.3 2000/03/19 17:57:06 aaron Exp $
.\"
.\" Copyright (c) 1980, 1990, 1993
.\" The Regents of the University of California. All rights reserved.
.\"
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
a very strange need mchitrakar Linux - Software 1 10-15-2005 01:14 PM
Strange New Look Boffy Mandriva 4 04-14-2005 07:23 PM
Something strange nm+ Linux - General 2 12-23-2004 07:06 AM
strange, strange alsa problem: sound is grainy/pixellated? fenderman11111 Linux - Software 1 11-01-2004 05:16 PM
Sound Issues with XMMS/ mpg123 strange (strange noises) thegreatbob Linux - Software 0 06-25-2004 03:18 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:00 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration