LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-24-2007, 11:13 PM   #1
ElGeorge
LQ Newbie
 
Registered: May 2007
Posts: 8

Rep: Reputation: 0
Question Tripwire reports that all my files had the "Device Number" modified


Hello,

Recently I transfered my site to a new provider and before putting the new server live I installed Tripwire as my IDS. Reports for the first 4 days the site was live on the new server were fine, but on day 5 the report made me gasp when reading it because according to it basically all of the files on my server had been modified (around 12k files).

After checking the details of the report I felt somewhat puzzled, because there was no change in date, size, permissions or anything on the file. All of the reported files had the same type of "Device Number" modification. Following is a sample of the report (as I mentioned all of the files have the same thing):

PHP Code:
Modified object name:  /usr/sbin/gpm

  Property
:            Expected                    Observed
  
-------------        -----------                 -----------
Device Number        51                          31 
I'm a newbie on managing a Linux Server so I'm not familiar with that "Device Number" property, could anyone give some ideas what is this all about. Was my site hacked or theres something else going on?

I haven't noticed anything weird on the site/server itself. I ran chkrootkit and rkhunter and none of them report anything unusual.

These are my specs:
  • Virtual Private Server with 1 GB of dedicated RAM (provider uses OpenVZ for virtualization)
  • CentOS 4.5

One fact that I should mention is that my provider announced recently that they were going to do some updates on the servers, because they wanted to update the OpenVZ to the latest kernel release. I wonder if this matter has anything to do with that, although the provider said that they would notify VPS users when their server was going to be upgraded, and so far they've not notified me about the update of the server where my account is located.

Thanks,

George

Last edited by ElGeorge; 06-24-2007 at 11:15 PM.
 
Old 06-26-2007, 10:22 AM   #2
macemoneta
Senior Member
 
Registered: Jan 2005
Location: Manalapan, NJ
Distribution: Fedora x86 and x86_64, Debian PPC and ARM, Android
Posts: 4,593
Blog Entries: 2

Rep: Reputation: 344Reputation: 344Reputation: 344Reputation: 344
The device number is the device pointed to by the inode. This can change for a number of reasons; changing volumes with LVM2, adding/removing physical drives, probably changes in RAID configuration. It should be safe to ignore.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Killing Modified File Auto Backups ("~") - Mandriva 2006 dalter Mandriva 2 06-29-2006 02:04 PM
pilot-xfer w/ Kyocera 7135 "device lied about number of ports" meznak Linux - Laptop and Netbook 2 11-17-2005 04:33 PM
"Successful install" results in "Boot device not found" slackr007 Fedora 2 06-21-2005 04:05 PM
"Successful install" results in "Boot device not found" slackr007 Linux - Newbie 2 05-31-2005 08:02 PM
"X-MS" cant open because "x-Multimedia System" cant access files at "smb&qu ponchy5 Linux - Networking 0 03-29-2004 11:18 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:29 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration