To register for an Internet.com membership to receive newsletters and white papers, use the Register button ABOVE.
To participate in the message forums BELOW, click here


EIT Planet's Security News
 Symantec Warns of New Security Breach
 Security Vulnerabilities Prove Increasingly Costly
 IPS Market Approaches $1 Billion

Security Products
 BugBopper (BugBopper)
 VBA Password Remover Tool (VBA Password Remover)
 VBA Password Remover Software (VBA Password Remover Software)
 Free keylogger download (Free keylogger download)
 Monitoring Software (Monitoring software)
 Retrieve Outlook 2007 Password (Retrieve PST Password)


Go Back   Antionline Forums - Maximum Security for a Connected World > Security Discussions > *nix Security Discussions

*nix Security Discussions Security issues related to *nix & *nix apps.

Reply
 
Thread Tools Display Modes
Old February 8th, 2010, 09:09 PM   #1
insuredjester
Junior Member
 
Join Date: Feb 2010
Posts: 3
insuredjester is on a distinguished road
Is my ROOT jacked?

Hello all,

I have a strange situation I would like to recount and get some input on.

The short version is that when I run the TAR command with -xvf as root
the extracted files show up in a directory owned by a different user and a
numerical group (500 to be exact). When I attempt to CD into the directory
the system tells me that the directory does not exist. After I chown the dir back to root and chgrp it out of 500 land, I can access the directory just fine.

I have checked the .bash_profile and disconnected the server from ldap using authconfig (this is CENTOS 4 btw) and the problem still persists... This is making me think that something is subverting commands created by root and executing them as another user... how can this be done? I was always under the impression that root is root and no one else.

If I need to post any config files or logs let me know.
insuredjester is offline   Reply With Quote
Old February 9th, 2010, 04:04 PM   #2
SegPhault
Banned
 
Join Date: Feb 2010
Posts: 35
SegPhault has a little shameless behaviour in the past
Quote:
Originally Posted by insuredjester View Post
The short version is that when I run the TAR command with -xvf as root the extracted files show up in a directory owned by a different user and a numerical group
Root should not be jacked. You are running "tar" as root instead of a regular user. You activated the safety mechanism which prevents possible damage to the root account.

use tar -oxvf instead of -xvf. This will always make your files belong to user root and group root.
SegPhault is offline   Reply With Quote
Old February 9th, 2010, 07:05 PM   #3
insuredjester
Junior Member
 
Join Date: Feb 2010
Posts: 3
insuredjester is on a distinguished road
Fixed

Works perfectly.

I was building source from a trusted source and figured it was safe to do the deed as root from start to finish... Thanks for the help.
insuredjester is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Many connections from 127.0.0.1 nancy Newbie Security Questions 19 December 11th, 2008 07:39 AM
Additional Security Measures for *nix thehorse13 *nix Security Discussions 15 May 15th, 2003 12:14 PM
Installation of a secure webserver. instronics The Security Tutorials Forum 0 January 19th, 2003 12:53 PM
Solaris Hardening R0n1n *nix Security Discussions 3 November 20th, 2002 01:20 PM
Linux Security Measures [part 1] Nitro The Security Tutorials Forum 2 July 3rd, 2002 06:37 AM


All times are GMT +1. The time now is 04:04 PM.












Acceptable Use Policy

Internet.com
The Network for Technology Professionals

Search:

About Internet.com

Legal Notices, Licensing, Permissions, Privacy Policy.
Advertise | Newsletters | E-mail Offers

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.