03-13-2005
And I googled this... From
this page:
Quote:
SOLARIS ATTACK SIGNATURE
------------------------
If you are checking your Solaris system for signs of an attack,
you can look for the following (this is not a complete list).
Note that the file sizes, etc., may differ from system to system.
Files modified:
/usr/bin/du (Size should be 9380, replaced version is 12352)
/usr/bin/find (Size and date unchanged)
/usr/bin/login (Size and date unchanged)
/usr/bin/ls (Size and date unchanged)
/usr/bin/netstat (Size and date unchanged)
/usr/bin/passwd (Size and date unchanged)
/usr/bin/ps (Size should be 5540, replaced version is 12720)
Files or directories added:
/usr/lib/lpset Password sniffer
/usr/lib/lpstart Startup script for attack tool
/etc/lpd.config
/var/lp/lpacct/lpacct Hacker IRC-like tool
/dev/pts/01/bin Directory with various binaries
/dev/prom/sn.l Password sniffer log
/usr/bin/sshd2 Installed SSH with backdoor
10 More Discussions You Might Find Interesting
1. UNIX for Dummies Questions & Answers
After I log ino the machine, a window pops up indicating that I should check that the HOSTNAME is the same in these three files
/etc//rc.configd/netconf
/etc/hosts
/var/adm/inetd.sec
How do I change the hostname in these files?
Thanks,
Mike h (1 Reply)
Discussion started by: hutchin
1 Replies
2. Solaris
I'm running solaris 2.5.1. My main development server is DEAD, i can't even boot off the cdrom, it powers up, acts like it is starting the boot process but then says cannot find boot device. I've done the search here on this site and saw the other posts, but at the ok prompt it won't even let me... (3 Replies)
Discussion started by: kymberm
3 Replies
3. SuSE
I recently installed SLES 10 on an x86 64bit blade server. I then installed vsftpd from the suse cds through network services; however after configuring the vsftpd.conf file, the server fails to start:
# /etc/init.d/vsftpd start
Starting vsftpd startproc: exit status of parent of... (5 Replies)
Discussion started by: dave521
5 Replies
4. Red Hat
im running rh 9 on my vmware, i tryed changing the graphics card mode
to resize the desktop, after restarting i get a message X Server cannot start.
then it takes me to the consol screen to log on, "im new to using linux as of last night"
It would be helpfull if anyone can help me resolve... (4 Replies)
Discussion started by: aoteg
4 Replies
5. Solaris
if anyone can help me here I will be in debt eternaly. I'm in a spot here fearing for my job.
I tried to install a new scsi array on our E5500. I powered it down correctly, removed the terminator, connected the array and powered it on. It was taking so long to come up I freaked out and powered... (3 Replies)
Discussion started by: NewSolarisAdmin
3 Replies
6. UNIX for Dummies Questions & Answers
on my AIX 6.1 CDE's ToolTalk server won't start. It says:
dtsession: Unable to exec /usr/dt/install/oldrules/dtrmrules.driver.
A file or directory in the path name does not exist.
How can I fix this? (0 Replies)
Discussion started by: rein
0 Replies
7. AIX
Hello:
NOOB here. I attempted to use smit mkcd. Failed on first attempt, not enough space. 2nd attempt tried to place iso on /usr, not enough space there. Cleanup ran for about 5 minutes after aborting. Now AIX won't boot. LCD display on 7029-6E3 says: 0517 MOUNT /USR. Attempted to boot from CD... (11 Replies)
Discussion started by: bbird
11 Replies
8. UNIX for Dummies Questions & Answers
hi guys
I installed NFS server and everything started out fine but I don't have /proc/fs/nfsd entry and so I can't mount nfsd. Therefore I can't start my nfs service.
Why don't I have /proc/fs/nfsd? How do I create that?
Thanks (1 Reply)
Discussion started by: alirezan
1 Replies
9. Red Hat
Hi, I am using redhat enterprise 5.7 have installed vsftpd successfully but every time I try to start the service it comes up with FAILED. Here is the contents of the vsftpd.conf file:
# Allow anonymous FTP? (Beware - allowed by default if you comment this out).
anonymous_enable=YES
#
#... (3 Replies)
Discussion started by: titley100
3 Replies
10. Fedora
Okay, I'm fairly green at Fedora, but it has worked like a gem until now. On startup I get a screen that says this:
Booting 'Fedora (3.6.11-4.fc16.x86_64)'
Loading Fedora (3.611-4.fc16.x86_64)
Loading initial ramdisk ....
_Fedora-16-x86_6: Unexpected inconsistency; run fsck manually.
... (6 Replies)
Discussion started by: Anchorsteamer
6 Replies
lint(1B) SunOS/BSD Compatibility Package Commands lint(1B)
NAME
lint - C program verifier
SYNOPSIS
/usr/ucb/lint [options]
DESCRIPTION
/usr/ucb/lint is the interface to the BSD Compatibility Package C program verifier. It is a script that looks for the link
/usr/ccs/bin/ucblint to the C program verifier. /usr/ccs/bin/ucblint is available only with the SPROcc package, whose default location is
/opt/SUNWspro. /usr/ucb/lint is identical to /usr/ccs/bin/ucblint, except that BSD headers are used and BSD libraries are linked before
base libraries. The /opt/SUNWspro/man/man1/lint.1 man page is available only with the SPROcc package.
OPTIONS
/usr/ucb/lint accepts the same options as /usr/ccs/bin/ucblint, with the following exceptions:
-Idir Search dir for included files whose names do not begin with a slash (/) prior to searching the usual directories. The
directories for multiple -I options are searched in the order specified. The preprocessor first searches for #include files
in the directory containing sourcefile, and then in directories named with -I options (if any), then /usr/ucbinclude, and
finally, in /usr/include.
-Ldir Add dir to the list of directories searched for libraries by /usr/ccs/bin/ucblint. This option is passed to
/usr/ccs/bin/ld. Directories specified with this option are searched before /usr/ucblib and /usr/lib.
-Y P, dir Change the default directory used for finding libraries.
EXIT STATUS
The following exit values are returned:
0 Successful completion.
>0 An error occurred.
FILES
/usr/lint/bin/ld link editor
/usr/lib/libc C library
/usr/ucbinclude BSD Compatibility directory for header files
/usr/ucblib BSD Compatibility directory for libraries
/usr/ucblib/libucb BSD Compatibility C library
/usr/lib/libsocket library containing socket routines
/usr/lib/libnsl library containing network functions
/usr/lib/libelf library containing routines to process ELF object files
/usr/lib/libaio library containing asynchronous I/O routines
ATTRIBUTES
See attributes(5) for descriptions of the following attributes:
+-----------------------------+-----------------------------+
| ATTRIBUTE TYPE | ATTRIBUTE VALUE |
+-----------------------------+-----------------------------+
|Availability |SUNWscpu |
+-----------------------------+-----------------------------+
SEE ALSO
ld(1), a.out(4), attributes(5)
SunOS 5.10 1 Feb 1995 lint(1B)