From owner-freebsd-questions@FreeBSD.ORG Mon Aug 16 15:08:56 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id C238E16A4D0 for ; Mon, 16 Aug 2004 15:08:56 +0000 (GMT) Received: from ddardaar.mine.nu (bwo182.neoplus.adsl.tpnet.pl [83.29.238.182]) by mx1.FreeBSD.org (Postfix) with ESMTP id 689FE43D39 for ; Mon, 16 Aug 2004 15:08:56 +0000 (GMT) (envelope-from radek@raadradd.com) Received: by ddardaar.mine.nu (Postfix, from userid 1001) id D9276A526; Mon, 16 Aug 2004 17:09:00 +0200 (CEST) Date: Mon, 16 Aug 2004 17:09:00 +0200 From: Radek Kozlowski To: freebsd-questions@freebsd.org, jacoulter@jacoulter.net Message-ID: <20040816150900.GC39290@werd> References: <20040816145737.GA3924@sara.mshome.net> Mime-Version: 1.0 Content-Type: text/plain; charset=iso-8859-2 Content-Disposition: inline In-Reply-To: <20040816145737.GA3924@sara.mshome.net> User-Agent: Mutt/1.5.6i Subject: Re: Security question - uids of 0 X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 16 Aug 2004 15:08:56 -0000 On Mon, Aug 16, 2004 at 09:57:37AM -0500, James A. Coulter wrote: > The following appeared in my latest daily security run output: > > Checking for uids of 0: > root 0 > toor 0 > > This is the first time I've seen this message. > > I checked /etc/passwd and found this: > > root:*:0:0:Charlie &:/root:/bin/csh > toor:*:0:0:Bourne-again Superuser:/root: > > I am running FreeBSD 4.10 as a gateway/router/firewall with IPFW for a small > home LAN. > > I ran ps -aux and looked for any processes owned by "toor" but didn't find any. > > Is this something to be concerned about? > > Sorry if this is an obvious question, but I am still very much a newbie > and trying to learn what I can about security. > > Thanks for your patience, http://www.freebsd.org/doc/faq/security.html#TOOR-ACCOUNT -Radek