Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 24 Jul 2001 13:42:50 -0400
From:      Garance A Drosihn <drosih@rpi.edu>
To:        Jon Loeliger <jdl@jdl.com>, security@FreeBSD.ORG
Subject:   Re: Security Check Diffs Question
Message-ID:  <p05101011b7836372657f@[128.113.24.47]>
In-Reply-To: <200107241632.LAA05639@chrome.jdl.com>
References:  <200107241632.LAA05639@chrome.jdl.com>

next in thread | previous in thread | raw e-mail | index | archive | help
At 11:32 AM -0500 7/24/01, Jon Loeliger wrote:
>Hi Folks,
>
>This morning, on a machine that's been up for 33 days,
>I suddenly saw these /etc/security diffs:
>   [...list deleted...]
>
>So, how paranoid am I here?  How concerned am I?
>What compromised of my system just took place?

If I were you, I would be very concerned.  I would do something
to rebuild those binaries, and probably the whole system, before
I let anyone change the password to any userid on the machine.

-- 
Garance Alistair Drosehn            =   gad@eclipse.acs.rpi.edu
Senior Systems Programmer           or  gad@freebsd.org
Rensselaer Polytechnic Institute    or  drosih@rpi.edu

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?p05101011b7836372657f>