lugoteehalt
11-10-2009, 10:20 AM
fido:/home/lugo# chattr +i /bin/ps
fido:/home/lugo# /usr/bin/lsattr `echo $PATH | tr ':' ' '` | grep "i--"
/usr/bin/lsattr: Operation not supported While reading flags on /usr/sbin/addgroup
/usr/bin/lsattr: Operation not supported While reading flags on /usr/sbin/traceroute
/usr/bin/lsattr: Operation not supported While reading flags on /usr/sbin/rsmtp
/usr/bin/lsattr: Operation not supported While reading flags on /usr/sbin/update-updmap
/usr/bin/lsattr: Operation not supported While reading flags on /usr/sbin/ramsize
<snip>
/usr/bin/lsattr: Operation not supported While reading flags on /sbin/fsck.msdos
/usr/bin/lsattr: Operation not supported While reading flags on /sbin/reboot
/usr/bin/lsattr: Operation not supported While reading flags on /bin/rbash
/usr/bin/lsattr: Operation not supported While reading flags on /bin/rnano
/usr/bin/lsattr: Operation not supported While reading flags on /bin/nc
/usr/bin/lsattr: Operation not supported While reading flags on /bin/sh
/usr/bin/lsattr: Operation not supported While reading flags on /bin/mt
/usr/bin/lsattr: Operation not supported While reading flags on /bin/netcat
/usr/bin/lsattr: Operation not supported While reading flags on /bin/bzegrep
/usr/bin/lsattr: Operation not supported While reading flags on /bin/bzcmp
/usr/bin/lsattr: Operation not supported While reading flags on /bin/pidof
/usr/bin/lsattr: Operation not supported While reading flags on /bin/bzfgrep
/usr/bin/lsattr: Operation not supported While reading flags on /bin/bzless
----i-------------- /bin/ps
fido:/home/lugo# chattr -i /bin/ps
I'm probably being oversensitive because have just put thing on internet. But www.tldp.org/HOWTO/Security-Quickstart-HOWTO/intrusion.html#HACKED says: A quick sanity check:
# chattr +i /bin/ps
# /usr/bin/lsattr `echo $PATH | tr ':' ' '` | grep "i--"
---i---------- /bin/ps
# chattr -i /bin/ps
This is just to verify the system is not tampered with to the point that lsattr is completely unreliable. The third line is exactly what you should see.And clearly this is part of what I see but not *exactly* what I see . Thanks any help.
fido:/home/lugo# /usr/bin/lsattr `echo $PATH | tr ':' ' '` | grep "i--"
/usr/bin/lsattr: Operation not supported While reading flags on /usr/sbin/addgroup
/usr/bin/lsattr: Operation not supported While reading flags on /usr/sbin/traceroute
/usr/bin/lsattr: Operation not supported While reading flags on /usr/sbin/rsmtp
/usr/bin/lsattr: Operation not supported While reading flags on /usr/sbin/update-updmap
/usr/bin/lsattr: Operation not supported While reading flags on /usr/sbin/ramsize
<snip>
/usr/bin/lsattr: Operation not supported While reading flags on /sbin/fsck.msdos
/usr/bin/lsattr: Operation not supported While reading flags on /sbin/reboot
/usr/bin/lsattr: Operation not supported While reading flags on /bin/rbash
/usr/bin/lsattr: Operation not supported While reading flags on /bin/rnano
/usr/bin/lsattr: Operation not supported While reading flags on /bin/nc
/usr/bin/lsattr: Operation not supported While reading flags on /bin/sh
/usr/bin/lsattr: Operation not supported While reading flags on /bin/mt
/usr/bin/lsattr: Operation not supported While reading flags on /bin/netcat
/usr/bin/lsattr: Operation not supported While reading flags on /bin/bzegrep
/usr/bin/lsattr: Operation not supported While reading flags on /bin/bzcmp
/usr/bin/lsattr: Operation not supported While reading flags on /bin/pidof
/usr/bin/lsattr: Operation not supported While reading flags on /bin/bzfgrep
/usr/bin/lsattr: Operation not supported While reading flags on /bin/bzless
----i-------------- /bin/ps
fido:/home/lugo# chattr -i /bin/ps
I'm probably being oversensitive because have just put thing on internet. But www.tldp.org/HOWTO/Security-Quickstart-HOWTO/intrusion.html#HACKED says: A quick sanity check:
# chattr +i /bin/ps
# /usr/bin/lsattr `echo $PATH | tr ':' ' '` | grep "i--"
---i---------- /bin/ps
# chattr -i /bin/ps
This is just to verify the system is not tampered with to the point that lsattr is completely unreliable. The third line is exactly what you should see.And clearly this is part of what I see but not *exactly* what I see . Thanks any help.