LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-05-2004, 08:40 PM   #1
jbeiter
Member
 
Registered: Jul 2004
Posts: 105

Rep: Reputation: 15
suspicious sgi_fam behavior


I don't think I've been hacked but these log entries have me a little concerned. I have a vague idea of what sgi_fam does so I'm not sure if this is a configuration snafu or if someone has compromised my system.

In /var/log/secure, I'm getting the following floods:
----------------------------------------------------------
Sep 5 10:07:34 glyph xinetd[6152]: FAIL: sgi_fam libwrap from=<no address>
Sep 5 10:07:34 glyph xinetd[5826]: START: sgi_fam pid=6153 from=<no address>
Sep 5 10:07:34 glyph xinetd[6153]: FAIL: sgi_fam libwrap from=<no address>
Sep 5 10:07:34 glyph xinetd[5826]: START: sgi_fam pid=6154 from=<no address>
Sep 5 10:07:34 glyph xinetd[6154]: FAIL: sgi_fam libwrap from=<no address>
-----------------------------------------------------------

/var/log/messages:
---------------------------------------------------------------------
Sep 5 10:07:34 glyph xinetd[6156]: libwrap refused connection to sgi_fam (libwrap=fam) from <no address>
Sep 5 10:07:34 glyph xinetd[5826]: Deactivating service sgi_fam due to excessive incoming connections. Restarting in 30 seconds.
Sep 5 10:08:05 glyph xinetd[5826]: Activating service sgi_fam
----------------------------------------------------------------------

I've had general probes and attempts from .sg and .tw but nothing that looked like someone got in. chkrootkit comes up clean and I have everything pretty well locked down in hosts.deny/allow.

Any comments appreciated.

- JoeB
 
Old 09-06-2004, 06:15 AM   #2
guzzi
Member
 
Registered: Jun 2004
Location: Lawrence, KS
Distribution: Slackware
Posts: 313

Rep: Reputation: 40
log entries

You didn't state what distro you are using, I have seen, Fedora Core 1 has a bug that would cause this to occur.

Also, you state that /etc/hosts and host.deny are locked down. I think you should consider using iptables to really secure your unit. Tcpwrappers is not enough. I learned that the hard way. And iptables isn't enough either, but it's a good start.
 
Old 09-07-2004, 05:24 AM   #3
jbeiter
Member
 
Registered: Jul 2004
Posts: 105

Original Poster
Rep: Reputation: 15
I'm running Redhat AS 3.0.

I'm installing iptables too. Too much activity out there
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
suspicious log activity hoedad Linux - Newbie 3 07-26-2004 07:33 AM
what is sgi_fam? is it needed to be on? zepplin611 Linux - Newbie 2 07-10-2004 12:32 PM
xinetd[id]: START: sgi_fam pid=id from=<no address> Hube Linux - Software 2 06-02-2004 04:51 PM
Suspicious modem-driver MadCactus Linux - Security 1 03-02-2004 05:26 PM
Suspicious network traffic Config Linux - Security 9 03-09-2003 07:23 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:19 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration