From: Ahmet Aksoy (ahmetax@axtelsoft.com)
Date: Wed 11 Feb 2004 - 10:47:10 EST
Merhaba,
Mandrake 9.2'yi kurduktan sonra, /var/log/messages dosyasinin icinde asagidakine benzer
yuzlerce satir olusmaya basladi.
"World writeable files found" uyarisi ile asagidaki gibi bir liste olusuyor.
Bu islem saat 04:13'te makine aciksa her gun tekrarlaniyor.
cron.daily'nin icindeki bilgilerden bu islemin hangi surecle ilgili oldugunu bulamadim.
1- Bu listeyi hangi program uretiyor?
2- Listenin olusmasini engellemek icin ne yapabilirim?
3- Listenin sonundaki mesaji tam yorumlayamadim. 'without proper authentication' hangi kosullarda olusuyor olabilir? leblebi.axtel.org adresli makinadan Mandrake kurulu makinaya SSH ile ben kendim baglaniyorum.
Mesaj satirlarinin son bolumu soyle:
........
Feb 10 22:33:57 max200 : - /var/spool/postfix/private/old-cyrus
Feb 10 22:33:57 max200 : - /var/spool/postfix/private/proxymap
Feb 10 22:33:57 max200 : - /var/spool/postfix/private/relay
Feb 10 22:33:57 max200 : - /var/spool/postfix/private/rewrite
Feb 10 22:33:57 max200 : - /var/spool/postfix/private/smtp
Feb 10 22:33:57 max200 : - /var/spool/postfix/private/tlsmgr
Feb 10 22:33:57 max200 : - /var/spool/postfix/private/uucp
Feb 10 22:33:57 max200 : - /var/spool/postfix/private/virtual
Feb 10 22:33:57 max200 : - /var/spool/postfix/public/cleanup
Feb 10 22:33:57 max200 : - /var/spool/postfix/public/flush
Feb 10 22:33:57 max200 : - /var/spool/postfix/public/pickup
Feb 10 22:33:57 max200 : - /var/spool/postfix/public/qmgr
Feb 10 22:33:57 max200 : - /var/spool/postfix/public/showq
Feb 10 22:33:57 max200 : - /var/spool/samba
Feb 10 22:33:57 max200 : - /var/www/html/jawmail/inc/config.php
Feb 10 22:33:57 max200 : - /var/www/html/jawmail/plugins/plugins.php
Feb 10 22:33:57 max200 :
Feb 10 22:33:57 max200 : Security Warning: '+' character found in hosts trusting files,
Feb 10 22:33:57 max200 : this probably mean that you trust certains users/domain
Feb 10 22:33:57 max200 : to connect on this host without proper authentication :
Feb 10 22:33:57 max200 : - /etc/hosts.equiv: + leblebi.axtel.org ahmet
Feb 10 22:34:39 max200 anacron[17922]: Job `cron.daily' terminated (mailing output)
Feb 10 22:36:50 max200 anacron[17922]: Job `cron.weekly' terminated
Feb 10 22:36:50 max200 anacron[17922]: Normal exit (3 jobs run)
---------------- alinti sonu ------------------------------
Sevgiler, saygilar.
Ahmet Aksoy
www.axtelsoft.com
--- linux-baslangic listesinden cikmak ve tum listeci islemleri icin http://liste.linux.org.tr/ adresini kullanabilirisniz. Bu listeden cikmak icin <a href="mailto:linux-baslangic-request@liste.linux.org.tr?Subject=unsubscribe"> tiklayiniz</a>