Date: Mon, 27 Dec 1999 08:36:11 -0500 (EST) From: Stan Brown <stanb@netcom.com> To: freebsd-stable@freebsd.org (FreeBSD Stable List) Subject: Huge differences in suid programs ? Message-ID: <199912271336.FAA14584@netcom.com>
next in thread | raw e-mail | index | archive | help
I cvsuped 3 machines and did a make worlds on the yesterday. I got HUGE differences on the suid files in the security report this morning: polar.fas.com setuid diffs: 1,12c1,12 < -r-xr-sr-x 1 root operator 51196 Dec 5 22:22:13 1999 /bin/df < -r-xr-sr-x 1 root kmem 189664 Dec 5 22:22:26 1999 /bin/ps < -r-sr-xr-x 1 root wheel 208408 Dec 5 22:22:29 1999 /bin/rcp < -r-xr-sr-x 1 root kmem 100148 Dec 5 22:33:20 1999 /sbin/ccdconfig < -r-xr-sr-x 1 root kmem 103696 Dec 5 22:33:27 1999 /sbin/dmesg < -r-xr-sr-x 2 root tty 221736 Dec 5 22:33:28 1999 /sbin/dump < -r-sr-xr-x 1 root wheel 145528 Dec 5 22:34:11 1999 /sbin/ping < -r-xr-sr-x 2 root tty 221736 Dec 5 22:33:28 1999 /sbin/rdump < -r-xr-sr-x 2 root tty 244920 Dec 5 22:34:16 1999 /sbin/restore < -r-sr-xr-x 1 root wheel 153760 Dec 5 22:34:18 1999 /sbin/route < -r-xr-sr-x 2 root tty 244920 Dec 5 22:34:16 1999 /sbin/rrestore < -r-sr-x--- 1 root operator 151712 Dec 5 22:34:22 1999 /sbin/shutdown --- > -r-xr-sr-x 1 root operator 51204 Dec 26 15:01:26 1999 /bin/df > -r-xr-sr-x 1 root kmem 190016 Dec 26 15:01:40 1999 /bin/ps > -r-sr-xr-x 1 root wheel 208408 Dec 26 15:01:43 1999 /bin/rcp > -r-xr-sr-x 1 root kmem 100156 Dec 26 15:12:33 1999 /sbin/ccdconfig > -r-xr-sr-x 1 root kmem 103872 Dec 26 15:12:39 1999 /sbin/dmesg > -r-xr-sr-x 2 root tty 221768 Dec 26 15:12:40 1999 /sbin/dump > -r-sr-xr-x 1 root wheel 145544 Dec 26 15:13:24 1999 /sbin/ping > -r-xr-sr-x 2 root tty 221768 Dec 26 15:12:40 1999 /sbin/rdump > -r-xr-sr-x 2 root tty 244920 Dec 26 15:13:28 1999 /sbin/restore > -r-sr-xr-x 1 root wheel 153760 Dec 26 15:13:30 1999 /sbin/route > -r-xr-sr-x 2 root tty 244920 Dec 26 15:13:28 1999 /sbin/rrestore > -r-sr-x--- 1 root operator 151712 Dec 26 15:13:36 1999 /sbin/shutdown 23,50c23,50 < -r-sr-xr-x 4 root wheel 17448 Dec 5 22:39:01 1999 /usr/bin/at < -r-sr-xr-x 4 root wheel 17448 Dec 5 22:39:01 1999 /usr/bin/atq < -r-sr-xr-x 4 root wheel 17448 Dec 5 22:39:01 1999 /usr/bin/atrm < -r-sr-xr-x 4 root wheel 17448 Dec 5 22:39:01 1999 /usr/bin/batch < -r-sr-xr-x 6 root wheel 28932 Dec 5 22:39:15 1999 /usr/bin/chfn < -r-sr-xr-x 6 root wheel 28932 Dec 5 22:39:15 1999 /usr/bin/chpass < -r-sr-xr-x 6 root wheel 28932 Dec 5 22:39:15 1999 /usr/bin/chsh < -r-sr-xr-x 1 root wheel 21028 Dec 5 22:42:54 1999 /usr/bin/crontab < -r-sr-sr-x 1 uucp dialer 110760 Dec 5 22:24:40 1999 /usr/bin/cu < -r-xr-sr-x 1 root kmem 10160 Dec 5 22:39:53 1999 /usr/bin/fstat < -r-sr-xr-x 5 root wheel 290448 Dec 5 22:44:46 1999 /usr/bin/hoststat < -r-xr-sr-x 1 root kmem 8728 Dec 5 22:40:07 1999 /usr/bin/ipcs < -r-sr-xr-x 1 root wheel 514 Dec 5 22:40:11 1999 /usr/bin/keyinfo < -r-sr-xr-x 1 root wheel 6556 Dec 5 22:40:12 1999 /usr/bin/keyinit < -r-sr-xr-x 1 root wheel 5656 Dec 5 22:40:26 1999 /usr/bin/lock < -r-sr-xr-x 1 root wheel 17624 Dec 5 22:40:29 1999 /usr/bin/login < -r-sr-sr-x 1 root daemon 18064 Dec 5 22:43:18 1999 /usr/bin/lpq < -r-sr-sr-x 1 root daemon 20864 Dec 5 22:43:19 1999 /usr/bin/lpr < -r-sr-sr-x 1 root daemon 17624 Dec 5 22:43:20 1999 /usr/bin/lprm < -r-sr-xr-x 5 root wheel 290448 Dec 5 22:44:46 1999 /usr/bin/mailq < -r-sr-xr-x 1 man wheel 23948 Dec 5 22:27:28 1999 /usr/bin/man < -r-xr-sr-x 1 root kmem 44536 Dec 5 22:40:52 1999 /usr/bin/netstat < -r-sr-xr-x 5 root wheel 290448 Dec 5 22:44:46 1999 /usr/bin/newaliases < -r-xr-sr-x 1 root kmem 7380 Dec 5 22:40:54 1999 /usr/bin/nfsstat < -r-sr-xr-x 2 root wheel 23984 Dec 5 22:41:02 1999 /usr/bin/passwd < -r-sr-xr-x 1 root wheel 10036 Dec 5 22:41:06 1999 /usr/bin/quota < -r-sr-xr-x 1 root wheel 8888 Dec 5 22:41:08 1999 /usr/bin/rlogin < -r-sr-xr-x 1 root wheel 6768 Dec 5 22:41:11 1999 /usr/bin/rsh --- > -r-sr-xr-x 4 root wheel 17448 Dec 26 15:18:22 1999 /usr/bin/at > -r-sr-xr-x 4 root wheel 17448 Dec 26 15:18:22 1999 /usr/bin/atq > -r-sr-xr-x 4 root wheel 17448 Dec 26 15:18:22 1999 /usr/bin/atrm > -r-sr-xr-x 4 root wheel 17448 Dec 26 15:18:22 1999 /usr/bin/batch > -r-sr-xr-x 6 root wheel 28932 Dec 26 15:18:36 1999 /usr/bin/chfn > -r-sr-xr-x 6 root wheel 28932 Dec 26 15:18:36 1999 /usr/bin/chpass > -r-sr-xr-x 6 root wheel 28932 Dec 26 15:18:36 1999 /usr/bin/chsh > -r-sr-xr-x 1 root wheel 21028 Dec 26 15:22:19 1999 /usr/bin/crontab > -r-sr-sr-x 1 uucp dialer 110760 Dec 26 15:03:55 1999 /usr/bin/cu > -r-xr-sr-x 1 root kmem 10160 Dec 26 15:19:12 1999 /usr/bin/fstat > -r-sr-xr-x 5 root wheel 290448 Dec 26 15:24:16 1999 /usr/bin/hoststat > -r-xr-sr-x 1 root kmem 8728 Dec 26 15:19:26 1999 /usr/bin/ipcs > -r-sr-xr-x 1 root wheel 514 Dec 26 15:19:31 1999 /usr/bin/keyinfo > -r-sr-xr-x 1 root wheel 6556 Dec 26 15:19:31 1999 /usr/bin/keyinit > -r-sr-xr-x 1 root wheel 5656 Dec 26 15:19:46 1999 /usr/bin/lock > -r-sr-xr-x 1 root wheel 17624 Dec 26 15:19:48 1999 /usr/bin/login > -r-sr-sr-x 1 root daemon 18064 Dec 26 15:22:44 1999 /usr/bin/lpq > -r-sr-sr-x 1 root daemon 20864 Dec 26 15:22:45 1999 /usr/bin/lpr > -r-sr-sr-x 1 root daemon 17624 Dec 26 15:22:46 1999 /usr/bin/lprm > -r-sr-xr-x 5 root wheel 290448 Dec 26 15:24:16 1999 /usr/bin/mailq > -r-sr-xr-x 1 man wheel 23948 Dec 26 15:06:43 1999 /usr/bin/man > -r-xr-sr-x 1 root kmem 44536 Dec 26 15:20:12 1999 /usr/bin/netstat > -r-sr-xr-x 5 root wheel 290448 Dec 26 15:24:16 1999 /usr/bin/newaliases > -r-xr-sr-x 1 root kmem 7380 Dec 26 15:20:14 1999 /usr/bin/nfsstat > -r-sr-xr-x 2 root wheel 23984 Dec 26 15:20:22 1999 /usr/bin/passwd > -r-sr-xr-x 1 root wheel 10036 Dec 26 15:20:25 1999 /usr/bin/quota > -r-sr-xr-x 1 root wheel 8888 Dec 26 15:20:28 1999 /usr/bin/rlogin > -r-sr-xr-x 1 root wheel 6768 Dec 26 15:20:30 1999 /usr/bin/rsh 52,73c52,73 < -r-s--x--x 2 root wheel 47472 Dec 5 22:30:18 1999 /usr/bin/sperl5.00503 < -r-sr-xr-x 1 root wheel 7404 Dec 5 22:41:21 1999 /usr/bin/su < -r-s--x--x 2 root wheel 47472 Dec 5 22:30:18 1999 /usr/bin/suidperl < -r-xr-sr-x 1 root kmem 52424 Dec 5 22:41:23 1999 /usr/bin/systat < -r-xr-sr-x 1 root kmem 30376 Dec 5 22:41:34 1999 /usr/bin/top < -r-xr-sr-x 2 root kmem 10576 Dec 5 22:41:59 1999 /usr/bin/uptime < -r-sr-xr-x 1 uucp wheel 79112 Dec 5 22:24:45 1999 /usr/bin/uucp < -r-sr-xr-x 1 uucp wheel 33480 Dec 5 22:24:46 1999 /usr/bin/uuname < -r-sr-sr-x 1 uucp dialer 86556 Dec 5 22:24:50 1999 /usr/bin/uustat < -r-sr-xr-x 1 uucp wheel 79936 Dec 5 22:24:51 1999 /usr/bin/uux < -r-xr-sr-x 1 root kmem 14536 Dec 5 22:41:58 1999 /usr/bin/vmstat < -r-xr-sr-x 2 root kmem 10576 Dec 5 22:41:59 1999 /usr/bin/w < -r-xr-sr-x 1 root tty 8108 Dec 5 22:42:01 1999 /usr/bin/wall < -r-xr-sr-x 1 root tty 6692 Dec 5 22:42:07 1999 /usr/bin/write < -r-sr-xr-x 6 root wheel 28932 Dec 5 22:39:15 1999 /usr/bin/ypchfn < -r-sr-xr-x 6 root wheel 28932 Dec 5 22:39:15 1999 /usr/bin/ypchpass < -r-sr-xr-x 6 root wheel 28932 Dec 5 22:39:15 1999 /usr/bin/ypchsh < -r-sr-xr-x 2 root wheel 23984 Dec 5 22:41:02 1999 /usr/bin/yppasswd < -r-xr-sr-x 1 root games 6188 Dec 5 22:22:52 1999 /usr/games/dm < -r-sr-xr-x 1 root wheel 15040 Dec 5 22:33:10 1999 /usr/libexec/mail.local < -r-sr-sr-x 1 uucp dialer 197552 Dec 5 22:24:43 1999 /usr/libexec/uucp/uucico < -r-sr-s--- 1 uucp uucp 89160 Dec 5 22:24:53 1999 /usr/libexec/uucp/uuxqt --- > -r-s--x--x 2 root wheel 47472 Dec 26 15:09:31 1999 /usr/bin/sperl5.00503 > -r-sr-xr-x 1 root wheel 7404 Dec 26 15:20:40 1999 /usr/bin/su > -r-s--x--x 2 root wheel 47472 Dec 26 15:09:31 1999 /usr/bin/suidperl > -r-xr-sr-x 1 root kmem 52424 Dec 26 15:20:42 1999 /usr/bin/systat > -r-xr-sr-x 1 root kmem 30376 Dec 26 15:20:53 1999 /usr/bin/top > -r-xr-sr-x 2 root kmem 10576 Dec 26 15:21:19 1999 /usr/bin/uptime > -r-sr-xr-x 1 uucp wheel 79112 Dec 26 15:03:59 1999 /usr/bin/uucp > -r-sr-xr-x 1 uucp wheel 33480 Dec 26 15:04:01 1999 /usr/bin/uuname > -r-sr-sr-x 1 uucp dialer 86556 Dec 26 15:04:04 1999 /usr/bin/uustat > -r-sr-xr-x 1 uucp wheel 79936 Dec 26 15:04:06 1999 /usr/bin/uux > -r-xr-sr-x 1 root kmem 14536 Dec 26 15:21:17 1999 /usr/bin/vmstat > -r-xr-sr-x 2 root kmem 10576 Dec 26 15:21:19 1999 /usr/bin/w > -r-xr-sr-x 1 root tty 8108 Dec 26 15:21:20 1999 /usr/bin/wall > -r-xr-sr-x 1 root tty 6692 Dec 26 15:21:26 1999 /usr/bin/write > -r-sr-xr-x 6 root wheel 28932 Dec 26 15:18:36 1999 /usr/bin/ypchfn > -r-sr-xr-x 6 root wheel 28932 Dec 26 15:18:36 1999 /usr/bin/ypchpass > -r-sr-xr-x 6 root wheel 28932 Dec 26 15:18:36 1999 /usr/bin/ypchsh > -r-sr-xr-x 2 root wheel 23984 Dec 26 15:20:22 1999 /usr/bin/yppasswd > -r-xr-sr-x 1 root games 6188 Dec 26 15:02:07 1999 /usr/games/dm > -r-sr-xr-x 1 root wheel 15040 Dec 26 15:12:21 1999 /usr/libexec/mail.local > -r-sr-sr-x 1 uucp dialer 197552 Dec 26 15:03:58 1999 /usr/libexec/uucp/uucico > -r-sr-s--- 1 uucp uucp 89160 Dec 26 15:04:07 1999 /usr/libexec/uucp/uuxqt 80,93c80,93 < -r-xr-sr-x 1 root kmem 9472 Dec 5 22:43:02 1999 /usr/sbin/iostat < -r-xr-sr-x 1 root daemon 23968 Dec 5 22:43:16 1999 /usr/sbin/lpc < -r-sr-xr-x 1 root wheel 14528 Dec 5 22:43:29 1999 /usr/sbin/mrinfo < -r-sr-xr-x 1 root wheel 27528 Dec 5 22:43:30 1999 /usr/sbin/mtrace < -r-sr-xr-- 1 root network 237236 Dec 5 22:43:52 1999 /usr/sbin/ppp < -r-sr-xr-x 1 root wheel 86632 Dec 5 22:43:54 1999 /usr/sbin/pppd < -r-xr-sr-x 2 root kmem 13184 Dec 5 22:43:56 1999 /usr/sbin/pstat < -r-sr-xr-x 5 root wheel 290448 Dec 5 22:44:46 1999 /usr/sbin/purgestat < -r-sr-xr-x 5 root wheel 290448 Dec 5 22:44:46 1999 /usr/sbin/sendmail < -r-sr-x--- 1 root network 9768 Dec 5 22:44:10 1999 /usr/sbin/sliplogin < -r-xr-sr-x 2 root kmem 13184 Dec 5 22:43:56 1999 /usr/sbin/swapinfo < -r-sr-xr-x 1 root wheel 13440 Dec 5 22:44:19 1999 /usr/sbin/timedc < -r-sr-xr-x 1 root wheel 11232 Dec 5 22:44:20 1999 /usr/sbin/traceroute < -r-xr-sr-x 1 root kmem 7036 Dec 5 22:44:21 1999 /usr/sbin/trpt --- > -r-xr-sr-x 1 root kmem 9472 Dec 26 15:22:29 1999 /usr/sbin/iostat > -r-xr-sr-x 1 root daemon 23968 Dec 26 15:22:42 1999 /usr/sbin/lpc > -r-sr-xr-x 1 root wheel 14528 Dec 26 15:22:54 1999 /usr/sbin/mrinfo > -r-sr-xr-x 1 root wheel 27528 Dec 26 15:22:55 1999 /usr/sbin/mtrace > -r-sr-xr-- 1 root network 237240 Dec 26 15:23:15 1999 /usr/sbin/ppp > -r-sr-xr-x 1 root wheel 86632 Dec 26 15:23:18 1999 /usr/sbin/pppd > -r-xr-sr-x 2 root kmem 13184 Dec 26 15:23:20 1999 /usr/sbin/pstat > -r-sr-xr-x 5 root wheel 290448 Dec 26 15:24:16 1999 /usr/sbin/purgestat > -r-sr-xr-x 5 root wheel 290448 Dec 26 15:24:16 1999 /usr/sbin/sendmail > -r-sr-x--- 1 root network 9768 Dec 26 15:23:33 1999 /usr/sbin/sliplogin > -r-xr-sr-x 2 root kmem 13184 Dec 26 15:23:20 1999 /usr/sbin/swapinfo > -r-sr-xr-x 1 root wheel 13440 Dec 26 15:23:42 1999 /usr/sbin/timedc > -r-sr-xr-x 1 root wheel 11232 Dec 26 15:23:42 1999 /usr/sbin/traceroute > -r-xr-sr-x 1 root kmem 7036 Dec 26 15:23:43 1999 /usr/sbin/trpt Whats going on here? -- Stan Brown stanb@netcom.com 404-996-6955 Factory Automation Systems Atlanta Ga. -- Look, look, see Windows 95. Buy, lemmings, buy! Pay no attention to that cliff ahead... Henry Spencer (c) 1998 Stan Brown. Redistribution via the Microsoft Network is prohibited. To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-stable" in the body of the message
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199912271336.FAA14584>