My RH6.2 BROKEN INTO!

My RH6.2 BROKEN INTO!

Post by Kool Breez » Sat, 27 May 2000 04:00:00



It's my company's IPMASQ box. I noticed I couldn't login.

I also could not log in from the console the next day (as any user or
root).

After verifying all my packages, I noticed that /sbin/telnetd.in was
bad as well as /bin/login.

rpm -Uhv --force util-linux*.rpm did not work (failed installling
/bin/login).

I can not (and still can not) remove, clear, link, mv or chmod
/bin/login.

In the meanwhile, I have grabbed the real /bin/login, renamed it to
/bin/Login and edited the mingetty/telnetd.in/rlogind.in files to use
/bin/Login.

WHY CAN'T I REPLACE /bin/login???

 
 
 

My RH6.2 BROKEN INTO!

Post by Art Haa » Sat, 27 May 2000 04:00:00



> It's my company's IPMASQ box. I noticed I couldn't login.

> I can not (and still can not) remove, clear, link, mv or chmod
> /bin/login.

> WHY CAN'T I REPLACE /bin/login???

Some mischevious devil probably set the immutable flag on it ...

% lsattr /bin/login

Read up on lsattr/chattr for more info

--
###############################
# Art Haas
# (713) 689-2417
###############################

 
 
 

My RH6.2 BROKEN INTO!

Post by Ronald Col » Sun, 28 May 2000 04:00:00



> After verifying all my packages, I noticed that /sbin/telnetd.in was
> bad as well as /bin/login.

You might want to read the LASG and use OpenSSH.  If you must use
telnet and rlogin on your internal network, then use ipchains to deny
access to them from the outside.

Quote:> WHY CAN'T I REPLACE /bin/login???

Probably set immutable.  "man chattr" wants to be your friend.
Again, seek out the LASG...

--
Forte International, P.O. Box 1412, Ridgecrest, CA  93556-1412

President, CEO                             Fax: (760) 499-9152
My GPG fingerprint: C3AF 4BE9 BEA6 F1C2 B084  4A88 8851 E6C8 69E3 B00B

 
 
 

My RH6.2 BROKEN INTO!

Post by Ronald Col » Sun, 28 May 2000 04:00:00


Oh yeah, you should probably take your firewall off the internet and
reformat/reinstall RH6.2.  Then secure your machine and put it back up.

Another alternative to reinstalling RH6.2 is to install RH6.1 and use
the Bastille hardening scripts to vastly improve your security.

--
Forte International, P.O. Box 1412, Ridgecrest, CA  93556-1412

President, CEO                             Fax: (760) 499-9152
My GPG fingerprint: C3AF 4BE9 BEA6 F1C2 B084  4A88 8851 E6C8 69E3 B00B

 
 
 

1. RH6.2: broken Imake?, broken Open Motif?

Hi, several problems I've noticed with a stock RH 6.2 system and with
trying to use imake and building and using Open Motif (not sure of the
Motif version, but it was ICS' first CDROM release).

1. xmkmf, Make Makefile doesn't work on 6.2.  I've used this Imakefile
for a long time and it was working on RH 5.x.  It leaves
'InstallAppDefaults(Xquote)' in the resulting Makefile in column 1.
That won't work.
This issue is not related to OpenMotif, my X apps just can't be built
with imake.  I'm sure its one of those inscrutable file in
/usr/X11r6/lib/X11/config, but which one?

2. The OpenMotif static library (libXm.a) uses a symbol _IO_stdin_, but
it isn't part of libc.  I redefined it as _IO_stdin without the closing
'_' to make it link, but I shouldn't have had to do that.

3. Trying to fix problem 2, I tried to build Open Motif.  This fails
during the build of imake, the Makefile
generates both -c and -o flags to gcc.  Gcc complains you can't combine
those flags (separate compilation and naming the object file
explicitly).

Open Motif was advertised as working on a stock RH6.2, that's not my
experience.  Anyone seen any problems like this or know how to fix any
of these?  I'd really like to get imake working again, the others are
mainly annoyances.

I don't see any RH groups on my server, apologies if there is a better
place for these questions.

Thanks in advance,

Mark

2. KDE, GNOME, and resource grabbing.

3. glibc / RH6.0 broken, needs wizardly help

4. X: possible to run in debug mode?

5. RH6.1 broke ppp

6. How detecting all opened ports and holes?

7. rpm-4.0.2 on rh6.2 breaks database

8. bellmail and delivery problem

9. Rh6.2 broke ntsysv

10. Bonding broke with RH6.0 to RH6.1?!

11. Procmail broke upgrading from RH6.0 -> RH6.1

12. X -query broken in RH6.1??

13. vacation program broken for RH6.0?