Thank you for your reply.
Quote:
Originally Posted by unSpawn
Not enough nfo:
- what does the TW log actually say?
|
Rule Name: User binaries (/usr/bin)
Severity Level: 66
-------------------------------------------------------------------------------
----------------------------------------
Modified Objects: 1
----------------------------------------
Modified object name: /usr/bin/dbilogstrip
Property: Expected Observed
------------- ----------- -----------
Object Type Regular File Regular File
Device Number 2051 2051
Inode Number 286925 286925
Mode -rwxr-xr-x -rwxr-xr-x
Num Links 1 1
UID root (0) root (0)
GID root (0) root (0)
Size 1465 1465
* Modify Time Thu 19 Aug 2010 08:28:07 PM EDT
Sun 30 Mar 2014 07:56:56 PM EDT
Blocks 8 8
CRC32 CzdFNl CzdFNl
MD5 DzanBe3QqtT9R4G9cK2Hgb DzanBe3QqtT9R4G9cK2Hgb
Quote:
Originally Posted by unSpawn
- what does 'rpm -Vv $(rpm -qf /usr/bin/dbilogstrip --qf="%{name}\n")|grep -v '^\.\{8\}';' return?
|
.......T. /usr/bin/dbilogstrip
Quote:
Originally Posted by unSpawn
- do you run prelink?
|
Not that I'm aware of. That was the first time I had heard of it.
Quote:
Originally Posted by unSpawn
- what does 'stat /usr/bin/dbilogstrip' return?
|
File: `/usr/bin/dbilogstrip'
Size: 1465 Blocks: 8 IO Block: 4096 regular file
Device: 803h/2051d Inode: 286925 Links: 1
Access: (0755/-rwxr-xr-x) Uid: ( 0/ root) Gid: ( 0/ root)
Access: 2014-04-02 03:36:29.841107654 -0400
Modify: 2014-03-30 19:56:56.165746180 -0400
Change: 2014-03-30 19:56:56.165746180 -0400
Quote:
Originally Posted by unSpawn
- any other files with similar or close by mtime?
|
These files are sorted by mtime.
/sys/module/xt_state/sections/.gnu.linkonce.this_module
/sys/module/xt_state/sections/.init.text
/sys/module/xt_state/sections/.note.gnu.build-id
/sys/module/xt_state/sections/.rheldata
/sys/module/xt_state/sections/.rodata.str1.4
/sys/module/xt_state/sections/.strtab
/sys/module/xt_state/sections/.symtab
/sys/module/xt_state/sections/.text
/sys/module/xt_state/srcversion
/sys/power
/sys/power/disk
/sys/power/image_size
/sys/power/resume
/sys/power/state
/tmp
/tmp/orbit-OtagoHarbour
/tmp/orbit-OtagoHarbour/linc-48ec-0-d17e592d0ffb
/usr/bin
/usr/bin/dbilogstrip
/usr/lib
/usr/libexec
/usr/libexec/git-core
/usr/lib/mysql
/usr/lib/sse2
/var/cache/man/whatis
/var/db/sudo/OtagoHarbour/0
/var/db/sudo/OtagoHarbour/1
/var/db/sudo/OtagoHarbour/2
/var/lib/dhclient/dhclient-b561f11e-333a-420d-a847-43662ad773ac-eth0.lease
/var/lib/logrotate.status
/var/lib/mlocate
/var/lib/mlocate/mlocate.db
/var/lib/NetworkManager
/var/lib/NetworkManager/timestamps
/var/lib/ntp
/var/lib/ntp/drift
/var/lib/php/session
/var/lib/php/session/sess_0fj5jci0idsh1tjllcmquh4te4
Quote:
Originally Posted by unSpawn
- what (automated?) processes or jobs ran around the mtime?
|
LAMP (Apache and PHP) Also Anaconda is running and leaving logs.
Quote:
Originally Posted by unSpawn
- user logins around the time?
|
No user logins since the previous day.
Quote:
Originally Posted by unSpawn
- system / daemon log entries?
|
[ 91178.816] AUDIT: Sun Mar 30 19:25:31 2014: 1633: client 34 connected from local host ( uid=500 gid=500 pid=7354 )
[ 91202.400] AUDIT: Sun Mar 30 19:25:55 2014: 1633: client 34 disconnected
[ 91223.838] AUDIT: Sun Mar 30 19:26:16 2014: 1633: client 34 connected from local host ( uid=500 gid=500 pid=7364 )
[ 91224.023] AUDIT: Sun Mar 30 19:26:16 2014: 1633: client 34 disconnected
[ 91260.008] AUDIT: Sun Mar 30 19:26:52 2014: 1633: client 34 connected from local host ( uid=500 gid=500 pid=7375 )
[ 91260.160] AUDIT: Sun Mar 30 19:26:53 2014: 1633: client 34 disconnected
[ 93093.992] AUDIT: Sun Mar 30 19:57:26 2014: 1633: client 34 connected from local host ( uid=500 gid=500 pid=7510 )
[ 93094.095] AUDIT: Sun Mar 30 19:57:26 2014: 1633: client 34 disconnected
Thanks,
OH