[gentoo-user] Re: hardened: setuid

2006-07-13 Thread Mick
On 12/07/06, James <[EMAIL PROTECTED]> wrote: I have not seen any indication of comprimise. Yes the system had redhat some years ago. It's entirely possible the same partition table was used and therefore these residual files are artifacts of a previous installation. My googling did not find any

Re: [gentoo-user] Re: hardened: setuid

2006-07-12 Thread Donnie Berkholz
James wrote: > Donnie Berkholz gentoo.org> writes: >> Have you tried checking which (if any) packages own these files? Have >> you built anything yourself outside of portage that could have installed >> them? > > Well I used --tree and it revealed nothing. --tree? How does it tell you what owns

[gentoo-user] Re: hardened: setuid

2006-07-12 Thread James
Donnie Berkholz gentoo.org> writes: > > /usr/athena/bin/su > > /usr/athena/bin/otp > > /usr/athena/bin/rcp > > /usr/athena/bin/rsh > > /usr/athena/bin/rlogin > > upon greater inspection this is most troubling: > > -rws--x--x 1 root root 108416 May 4 19:52 /usr/athena/bin/su > > -rws--x--x 1 r

[gentoo-user] Re: hardened: setuid

2006-07-12 Thread James
Mick gmail.com> writes: > > On Wednesday 12 July 2006 20:21, James wrote: > > > which found these peculiar files: > > > > /usr/athena/bin/su > > /usr/athena/bin/otp > > /usr/athena/bin/rcp > > /usr/athena/bin/rsh > > /usr/athena/bin/rlogin > > Did you ever install RedHat, or parts of? I guess