LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-19-2005, 09:38 AM   #46
TruckStuff
Member
 
Registered: Apr 2002
Posts: 498

Original Poster
Rep: Reputation: 30

Quote:
Originally posted by Capt_Caveman
I'm getting the feeling this might have something to do with prelinking. It should be run about the same time as yum by cron. All of the target dirs seem to appear in /etc/prelink.conf. Prelinking binaries can add entries to the end of the .dynamic section for virtual mem addresses locations. It also may explain why some test are coming back clean(those that don't look at the elf header) while others are flagging them (those that do check). Try undoing the prelinking with prelink -au binary and rerun tripwire.
OK, this seems to have "undone" some of the changes. The addresses at the end of the dynamic section of objdump are gone on the affected binaries. I also noticed that the other systems I was checking the binaries against don't have prelink installed, so that would explain why those addresses weren't showing up on those systems.

I ran tripwire and started comparing that report against the previous alarm reports. I've found that some files (/usr/sbin/callback, /usr/sbin/diskdumpctl_proc,/usr/bin/a2p, /usr/bin/c++... ) are back to where they were, e.g. MD5s are now what they were previously, suggesting that prelink updated many of these files.

HOWEVER, not all of them are back to where they were. /usr/bin/aspell, /usr/lib/autofs/autofs-ldap-auto-master, /usr/sbin/iptstate still do not checkout against any previous tripwire reports.

Still looks like I'm going to have to reformat and reinstall...
 
Old 08-19-2005, 10:23 AM   #47
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,683
Blog Entries: 4

Rep: Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947
Perhaps... perhaps not. prelink may well be a "plausible explanation" for what TripWire is saying. TripWire presumably would not know about prelinking. (And for what it's worth, I don't bother to use it here.) If you changed a library, then the consequence of prelink would indeed be a "changed binary," and TripWire would howl.

A quick search of Google for the two terms, tripwire prelink, seemed to hit pay dirt, including the note that in Fedora Core 4, prelinking occurs "every 14 days."

To me, it seems like a strange utility (not suspicious, just strange as in "of dubious value"), and the 14-day schedule makes it more-so. I junked the thing probably six months ago, along with other RH stuff that I couldn't readily explain/justify, and I certainly don't see "slugging performance" in its absence. As others have commented, it seems to me that this would be the kind of thing that one might run "after an RPM update," or "on request," but not "regularly." Yet obviously, RH does so. Again, I'm not saying that this is suspicious.
 
Old 08-19-2005, 10:32 AM   #48
TruckStuff
Member
 
Registered: Apr 2002
Posts: 498

Original Poster
Rep: Reputation: 30
Quote:
Originally posted by sundialsvcs
A quick search of Google for the two terms, tripwire prelink, seemed to hit pay dirt, including the note that in Fedora Core 4, prelinking occurs "every 14 days."
I noticed that FC3 does the same thing while I was exploring the prelink idea. It seems that it will also update every 7 days even if no RPM has been updated. This might be useful information, except that I never experienced such massive changes before the last two weeks. If I could explain all of the changes with this, I would be satisfied that nothing has been compromised.
 
Old 08-19-2005, 11:49 AM   #49
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
Is there any chance the settings in /etc/sysconfig/prelink got changed?
 
Old 08-19-2005, 11:55 AM   #50
TruckStuff
Member
 
Registered: Apr 2002
Posts: 498

Original Poster
Rep: Reputation: 30
Sure its possible, but nothing in it looks out of the ordinary.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:34 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration