SUMMARY: login problem.

From: Sandeep pandit (spandit@bme.utmem.edu)
Date: Mon Nov 01 1999 - 11:56:30 CST


Dear managers,

Thanks to
Casper Dik
Sean Quaint
Marina Daniels

The problem was what i was suspecting but hoping had not happened:
somebody had hacked in and replaced the login binary file and other
binaries as well. I was able to login and once the correct login binary
was restored from the CDROM. Cleaning up the system is goig to be a long
and ardous task though.

The original question:
=========================================================================
Dear managers,

i am unable to get the "passwd" prompt at the console for any user as well
as the root. if i try a remote login, the connection is being refused by
the m/c. the m/c is sparc/sol2.5.1. at the same time i am able to ftp into
the m/c as an ordinary user.

i have not changed/added anything recently. On checking in the maintenance
mode, the file permission for "/" seems to be ok. The inetd.conf file and
/etc/services file seem to be proper. The only unusual message the
"/var/adm/message" seems to have is
"inetd[104] config: 100068/rpc/udp still active and was not reconfigures"
"inetd[104] config: 100083/rpc/tcp still active and was not reconfigured"
i am not sure if this pertinent at all. also the /etc/passwd and
/etc/shadow files seem ok.

i would appreciate any pointers,
TIA,
sandeep.



This archive was generated by hypermail 2.1.2 : Fri Sep 28 2001 - 23:13:31 CDT