Q: "Intruder Alert" with a passwd access (whoami, ls -l, etc)

From: Ian Veach <ivo_at_scs.unr.edu>
Date: Wed, 06 Jan 1999 19:11:53 -0800 (PST)

Greetings Great Ones -

I don't think this isn't specifically DU related, but we're running it
on this system, so... 8^)

The machine is running 4.0D and TCR - no yp but is running c2. the auth
db seems to be fine (i.e. edauth works):

We've got a production machine that recently may have had some files
deleted (but she's not sure what ones) during a user update (a tar pipe of
their files (cd dir; tar cf . - | (cd newdir; tar xf -)) files THEN
REMOVE THE OLD COPY and remove their passwd entry). It may have been
buggy code, because we're guessing it started to copy (tar) / right back
to /. It may or may not have remove some files.

Right after she noticed it tarring /, she stopped it, but the system has
been screwy since, saying things like:
        Intruder Alert
when a user types "whoami" (although root's whoami works fine). Other
things that use user info (excepting "who") also fail, such "ls -al",
which simply returns uid's.

We've restored the passwd file from a pre-script backup, and permissions
on /etc/passwd are right, but to no avail.

Anyone got any ideas?

thanks million and a half,
_____________________________________________________________________________
Ian Veach, Systems Software Analyst, UCCSN Systems Computing Services
ivo_at_nevada.edu, VOICE: (702) 784.6486, FAX: (702) 784.1108
_____________________________________________________________________________
Received on Thu Jan 07 1999 - 03:30:15 NZDT

This archive was generated by hypermail 2.4.0 : Wed Nov 08 2023 - 11:53:38 NZDT