From owner-freebsd-questions Sun May 5 21:19: 5 2002 Delivered-To: freebsd-questions@freebsd.org Received: from apollo.pwhsnet.com (adsl-64-168-102-95.dsl.scrm01.pacbell.net [64.168.102.95]) by hub.freebsd.org (Postfix) with ESMTP id E217F37B401 for ; Sun, 5 May 2002 21:18:59 -0700 (PDT) Received: (from root@localhost) by apollo.pwhsnet.com (8.11.6/8.11.6) id g464Qcq28116; Sun, 5 May 2002 21:26:38 -0700 (PDT) (envelope-from patrick@pwhsnet.com) Received: from zeus (patrick@zeus.pwhsnet.com [192.168.0.3]) by apollo.pwhsnet.com (8.11.6/8.11.6) with SMTP id g464QcI28070; Sun, 5 May 2002 21:26:38 -0700 (PDT) (envelope-from patrick@pwhsnet.com) Message-ID: <008c01c1f4b4$c9f63110$0300a8c0@zeus> From: "Patrick O. Fish" To: "Jacob Rhoden" , References: <005101c1f4b2$9baa4d70$3b12fa80@its.unimelb.edu.au> Subject: Re: su problem: s/key 94 snosoft2 Date: Sun, 5 May 2002 21:16:26 -0700 MIME-Version: 1.0 X-scanner: scanned by Inflex 1.0.12.2 - (http://pldaniels.com/inflex/) Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 5.50.4807.1700 X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4910.0300 Sender: owner-freebsd-questions@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG Someone ran a exploit on your box (local user), they must of changed the root password. Search some mailing lists for information on the explot. If you have psyical access to the machine, you can boot into single-user mode and change it back. 2) To patch your present system: a) Download the relevant patch from the location below, and verify the detached PGP signature using your PGP utility. # fetch ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:23/stdio.patch # fetch ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:23/stdio.patch.asc b) Execute the following commands as root: # cd /usr/src # patch < /path/to/patch c) Recompile your kernel as described in http://www.freebsd.org/handbook/kernelconfig.html and reboot the system. ----- Original Message ----- From: "Jacob Rhoden" To: Sent: Sunday, May 05, 2002 9:00 PM Subject: su problem: s/key 94 snosoft2 > Hi, > > Today when I logged into my box and tried to su to do some admin stuff, I > got the message 's/key 94 snosoft2' before the password prompt. It now will > not accept my password. What could possibly be the problem? > > Regards > Jacob Rhoden > > > To Unsubscribe: send mail to majordomo@FreeBSD.org > with "unsubscribe freebsd-questions" in the body of the message > ______________________________________ Scanned and protected by Inflex Inflex Scanning software Available at http://pldaniels.com/inflex To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-questions" in the body of the message