Peter Stuge wrote:
I apologize for the delay, Peter...On Wed, Jan 04, 2006 at 11:03:38AM +0100, Network Operation Center FMC Luxemburg wrote:Hi Andy, There is this file, attached Francois --
Network Operation Center
LUXEMBURG E-mail: [EMAIL PROTECTED]
|
8919 select(1, [0], NULL, NULL, {40, 450000}) = 1 (in [0], left {33, 480000})
8919 gettimeofday({1136187981, 369590}, NULL) = 0
8919 read(0, "2 authenticate plain\r\n", 1024) = 22
8919 alarm(1200) = 0
8919 write(1, "+ \r\n", 4) = 4
8919 alarm(0) = 1200
8919 gettimeofday({1136187981, 370607}, NULL) = 0
8919 select(1, [0], NULL, NULL, NULL) = 1 (in [0])
8919 gettimeofday({1136187981, 670221}, NULL) = 0
8919 read(0, "AGluZm8uc2VjdXJpdG1haWwAZm1jMzUybHU=\r\n", 1024) = 38
8919 brk(0) = 0x8080000
8919 brk(0x8081000) = 0x8081000
8919 brk(0) = 0x8081000
8919 brk(0x8082000) = 0x8082000
8919 pipe([4, 5]) = 0
8919 pipe([6, 7]) = 0
8919 pipe([8, 9]) = 0
8919 time(NULL) = 1136187981
8919 clone(child_stack=0, flags=CLONE_CHILD_CLEARTID|CLONE_CHILD_SETTID|0x11,
<ignored>, <ignored>, 0x400fd788) = 9703
8919 close(4 <unfinished ...>
9703 --- SIGSTOP (Stopped (signal)) @ 0 (0) ---
8919 <... close resumed> ) = 0
9703 --- SIGSTOP (Stopped (signal)) @ 0 (0) ---
8919 rt_sigaction(SIGPIPE, {SIG_IGN}, <unfinished ...>
9703 close(5 <unfinished ...>
8919 <... rt_sigaction resumed> {SIG_DFL}, 8) = 0
9703 <... close resumed> ) = 0
8919 write(5, "info.securitmail", 16 <unfinished ...>
9703 close(8 <unfinished ...>
8919 <... write resumed> ) = 16
9703 <... close resumed> ) = 0
8919 write(5, "\0", 1 <unfinished ...>
9703 close(7 <unfinished ...>
8919 <... write resumed> ) = 1
9703 <... close resumed> ) = 0
8919 write(5, "fmc352lu", 8 <unfinished ...>
9703 dup2(9, 1 <unfinished ...>
8919 <... write resumed> ) = 8
9703 <... dup2 resumed> ) = 1
8919 write(5, "\0", 1 <unfinished ...>
9703 dup2(6, 0 <unfinished ...>
8919 <... write resumed> ) = 1
9703 <... dup2 resumed> ) = 0
8919 write(5, "Mon Jan 2 07:46:21 2006\n", 25 <unfinished ...>
9703 dup2(4, 3 <unfinished ...>
8919 <... write resumed> ) = 25
9703 <... dup2 resumed> ) = 3
8919 write(5, "\0", 1 <unfinished ...>
9703 execve("/bin/checkpassword", ["/bin/checkpassword",
"/usr/local/bin/imapd"], [/* 53 vars */] <unfinished ...>
8919 <... write resumed> ) = 1
9703 <... execve resumed> ) = 0
8919 close(5) = 0
9703 uname( <unfinished ...>
8919 close(9 <unfinished ...>
9703 <... uname resumed> {sys="Linux", node="saturn.eurofmc.com", ...}) = 0
8919 <... close resumed> ) = 0
9703 brk(0 <unfinished ...>
8919 close(6 <unfinished ...>
9703 <... brk resumed> ) = 0x804af00
8919 <... close resumed> ) = 0
9703 old_mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1,
0 <unfinished ...>
8919 select(9, [0 8], NULL, NULL, {2160, 0} <unfinished ...>
9703 <... old_mmap resumed> ) = 0x40016000
9703 open("/etc/ld.so.preload", O_RDONLY) = -1 ENOENT (No such file or
directory)
9703 open("/etc/ld.so.cache", O_RDONLY) = 5
9703 fstat64(5, {st_mode=S_IFREG|0644, st_size=24061, ...}) = 0
9703 old_mmap(NULL, 24061, PROT_READ, MAP_PRIVATE, 5, 0) = 0x40017000
9703 close(5) = 0
9703 open("/lib/libcrypt.so.1", O_RDONLY) = 5
9703 read(5,
"\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\240\t\0\0004\0\0\0\304W\0\0\0\0\0\0004\0
\0\6\0(\0\36\0\35\0\6\0\0\0004\0\0\0004\0\0\0004\0\0\0\300\0\0\0\300\0\0\0\5\0\0\0\4\0\0\0\3\0\0\0\343A\0\0\343A\0\0\343A\0\0\23\0\0\0\23\0\0\0\4\0\0\0\1\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\374A\0\0\374A\0\0\5\0\0\0\0\20\0\0\1\0\0\0\374A\0\0\374Q\0\0\374Q\0\0L\1\0\0Dr\2\0\6\0\0\0\0\20\0\0\2\0\0\0\10B\0\0\10R\0\0\10R\0\0\330\0\0\0\330\0\0\0\6\0\0\0\4\0\0\0\4\0\0\0\364\0\0\0\364\0\0\0\364\0\0\0
\0\0\0
\0\0\0\4\0\0\0\4\0\0\0\4\0\0\0\20\0\0\0\1\0\0\0GNU\0\0\0\0\0\2\0\0\0\2\0\0\0\5\0\0\0&\0\0\0009\0\0\0-\0\0\0%\0\0\0\0\0\0\0\0\0\0\0\'\0\0\0\0\0\0\0\0\0\0\0001\0\0\0006\0\0\0008\0\0\0#\0\0\0\0\0\0\0)\0\0\0\0\0\0\0/\0\0\0\0\0\0\0\0\0\0\0005\0\0\0000\0\0\0(\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0002\0\0\0004\0\0\0007\0\0\0\0\0\0\0&\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0*\0\0\0\0\0\0\0.\0\0\0003\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0",
512) = 512
9703 fstat64(5, {st_mode=S_IFREG|0755, st_size=23668, ...}) = 0
9703 old_mmap(NULL, 181312, PROT_READ|PROT_EXEC, MAP_PRIVATE, 5, 0) =
0x4001d000
9703 old_mmap(0x40022000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED,
5, 0x4000) = 0x40022000
9703 old_mmap(0x40023000, 156736, PROT_READ|PROT_WRITE,
MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x40023000
9703 close(5) = 0
9703 open("/lib/tls/libc.so.6", O_RDONLY) = 5
9703 read(5,
"\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0`V\1B4\0\0\0\340R\27\0\0\0\0\0004\0
\0\10\0(\0?\0>\0\6\0\0\0004\0\0\0004\0\0B4\0\0B\0\1\0\0\0\1\0\0\5\0\0\0\4\0\0\0\3\0\0\0p\304\22\0p\304\22Bp\304\22B\23\0\0\0\23\0\0\0\4\0\0\0\1\0\0\0\1\0\0\0\0\0\0\0\0\0\0B\0\0\0B\374\330\22\0\374\330\22\0\5\0\0\0\0\20\0\0\1\0\0\0\0\340\22\0\0\340\22B\0\340\22B\274,\0\0\10O\0\0\6\0\0\0\0\20\0\0\2\0\0\0
\t\23\0 \t\23B
\t\23B\340\0\0\0\340\0\0\0\6\0\0\0\4\0\0\0\4\0\0\0004\1\0\0004\1\0B4\1\0B
\0\0\0
\0\0\0\4\0\0\0\4\0\0\0\7\0\0\0\30\t\23\0\30\t\23B\30\t\23B\10\0\0\0004\2\0\0\4\0\0\0
\0\0\0P\345td\204\304\22\0\204\304\22B\204\304\22B\24\3\0\0\24\3\0\0\4\0\0\0\4\0\0\0\4\0\0\0\20\0\0\0\1\0\0\0GNU\0\0\0\0\0\2\0\0\0\4\0\0\0\24\0\0\0\377\3\0\0\217\10\0\0006\1\0\0\267\6\0\0~\2\0\0\376\0\0\0
\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\246\6\0\0\5\6\0\0\0\0\0\0I\10\0\0\260\6\0\0>\2\0\0\323\2\0\0]\10\0\0P\4\0\0R\10\0\0]\3\0\0\346\6\0\0\246\2\0\0!\10\0\0R\6\0\0\367\4\0\0\366\7\0\0\300\7\0\0\0\0\0\0\326\4\0\0\347\5\0\0V\10\0\0l\7\0\0\0\0\0\0\0\0\0\0\207\5\0\0f\4\0\0\325\3\0\0-\5\0\0[\10\0\0\0\0\0\0\"\10\0\0",
512) = 512
9703 fstat64(5, {st_mode=S_IFREG|0755, st_size=1531064, ...}) = 0
9703 old_mmap(0x42000000, 1257224, PROT_READ|PROT_EXEC, MAP_PRIVATE, 5, 0) =
0x42000000
9703 old_mmap(0x4212e000, 12288, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED,
5, 0x12e000) = 0x4212e000
9703 old_mmap(0x42131000, 7944, PROT_READ|PROT_WRITE,
MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x42131000
9703 close(5) = 0
9703 old_mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1,
0) = 0x4004a000
9703 set_thread_area({entry_number:-1 -> 6, base_addr:0x4004a280,
limit:1048575, seg_32bit:1, contents:0, read_exec_only:0, limit_in_pages:1,
seg_not_present:0, useable:1}) = 0
9703 munmap(0x40017000, 24061) = 0
9703 read(3, "info.securitmail\0fmc352lu\0Mon Jan 2 07:46:21 2006\n\0", 513)
= 52
9703 read(3, "", 461) = 0
9703 close(3) = 0
9703 brk(0) = 0x804af00
9703 brk(0x804bf00) = 0x804bf00
9703 brk(0) = 0x804bf00
9703 brk(0x804c000) = 0x804c000
9703 socket(PF_UNIX, SOCK_STREAM, 0) = 3
9703 connect(3, {sa_family=AF_UNIX, path="/var/run/.nscd_socket"}, 110) = -1
ENOENT (No such file or directory)
9703 close(3) = 0
9703 open("/etc/nsswitch.conf", O_RDONLY) = 3
9703 fstat64(3, {st_mode=S_IFREG|0644, st_size=1686, ...}) = 0
9703 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0)
= 0x40017000
9703 read(3, "#\n# /etc/nsswitch.conf\n#\n# An example Name Service Switch
config file. This file should be\n# sorted with the most-used services at the
beginning.\n#\n# The entry \'[NOTFOUND=return]\' means that the search for
an\n# entry should stop if the search in the previous entry turned\n# up
nothing. Note that if the search failed due to some other reason\n# (like no
NIS server responding) then the search continues with the\n# next entry.\n#\n#
Legal entries are:\n#\n#\tnisplus or nis+\t\tUse NIS+ (NIS version 3)\n#\tnis
or yp\t\tUse NIS (NIS version 2), also called YP\n#\tdns\t\t\tUse DNS (Domain
Name Service)\n#\tfiles\t\t\tUse the local files\n#\tdb\t\t\tUse the local
database (.db) files\n#\tcompat\t\t\tUse NIS on compat mode\n#\thesiod\t\t\tUse
Hesiod for user lookups\n#\t[NOTFOUND=return]\tStop searching if not found so
far\n#\n\n# To use db, put the \"db\" in front of \"files\" for entries you
want to be\n# looked up first in the databases\n#\n# Example:\n#passwd: db
files nisplus nis\n#shadow: db files nisplus nis\n#group: db files
nisplus nis\n\npasswd: fil"..., 4096) = 1686
9703 read(3, "", 4096) = 0
9703 close(3) = 0
9703 munmap(0x40017000, 4096) = 0
9703 open("/etc/ld.so.cache", O_RDONLY) = 3
9703 fstat64(3, {st_mode=S_IFREG|0644, st_size=24061, ...}) = 0
9703 old_mmap(NULL, 24061, PROT_READ, MAP_PRIVATE, 3, 0) = 0x40017000
9703 close(3) = 0
9703 open("/lib/libnss_files.so.2", O_RDONLY) = 3
9703 read(3,
"\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\20\35\0\0004\0\0\0p\310\0\0\0\0\0\0004\0
\0\6\0(\0\35\0\34\0\6\0\0\0004\0\0\0004\0\0\0004\0\0\0\300\0\0\0\300\0\0\0\5\0\0\0\4\0\0\0\3\0\0\0\25\244\0\0\25\244\0\0\25\244\0\0\23\0\0\0\23\0\0\0\4\0\0\0\1\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0,\244\0\0,\244\0\0\5\0\0\0\0\20\0\0\1\0\0\0,\244\0\0,\264\0\0,\264\0\0\320\1\0\0\260\3\0\0\6\0\0\0\0\20\0\0\2\0\0\0004\244\0\0004\264\0\0004\264\0\0\330\0\0\0\330\0\0\0\6\0\0\0\4\0\0\0\4\0\0\0\364\0\0\0\364\0\0\0\364\0\0\0
\0\0\0
\0\0\0\4\0\0\0\4\0\0\0\4\0\0\0\20\0\0\0\1\0\0\0GNU\0\0\0\0\0\2\0\0\0\2\0\0\0\5\0\0\0\265\0\0\0\212\0\0\0\0\0\0\0q\0\0\0,[EMAIL
PROTECTED]|\0\0\0B\0\0\0\0\0\0\0f\0\0\0\0\0\0\0", 512) = 512
9703 fstat64(3, {st_mode=S_IFREG|0755, st_size=52472, ...}) = 0
9703 old_mmap(NULL, 47068, PROT_READ|PROT_EXEC, MAP_PRIVATE, 3, 0) = 0x4004b000
9703 old_mmap(0x40056000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED,
3, 0xa000) = 0x40056000
9703 close(3) = 0
9703 munmap(0x40017000, 24061) = 0
9703 open("/etc/passwd", O_RDONLY) = 3
9703 fcntl64(3, F_GETFD) = 0
9703 fcntl64(3, F_SETFD, FD_CLOEXEC) = 0
9703 fstat64(3, {st_mode=S_IFREG|0664, st_size=5564, ...}) = 0
9703 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0)
= 0x40017000
9703 read(3,
"root:x:0:0:root:/root:/bin/bash\nbin:x:1:1:bin:/bin:/sbin/nologin\ndaemon:x:2:2:daemon:/sbin:/sbin/nologin\nadm:x:3:4:adm:/var/adm:/sbin/nologin\nlp:x:4:7:lp:/var/spool/lpd:/sbin/nologin\nsync:x:5:0:sync:/sbin:/bin/sync\nshutdown:x:6:0:shutdown:/sbin:/sbin/shutdown\nhalt:x:7:0:halt:/sbin:/sbin/halt\nmail:x:8:12:mail:/var/spool/mail:/sbin/nologin\nnews:x:9:13:news:/etc/news:\nuucp:x:10:14:uucp:/var/spool/uucp:/sbin/nologin\noperator:x:11:0:operator:/root:/sbin/nologin\ngames:x:12:100:games:/usr/games:/sbin/nologin\ngopher:x:13:30:gopher:/var/gopher:/sbin/nologin\nftp:x:14:50:FTP
User:/var/ftp:/sbin/nologin\nnobody:x:99:99:Nobody:/:/sbin/nologin\nrpm:x:37:37::/var/lib/rpm:/bin/bash\nvcsa:x:69:69:virtual
console memory owner:/dev:/sbin/nologin\nnscd:x:28:28:NSCD
Daemon:/:/sbin/nologin\nsshd:x:74:74:Privilege-separated
SSH:/var/empty/sshd:/sbin/nologin\nrpc:x:32:32:Portmapper RPC
user:/:/sbin/nologin\nrpcuser:x:29:29:RPC Service
User:/var/lib/nfs:/sbin/nologin\nnfsnobody:x:65534:65534:Anonymous NFS
User:/var/lib/nfs:/sbin/nologin\nmail"..., 4096) = 4096
9703 close(3) = 0
9703 munmap(0x40017000, 4096) = 0
9703 brk(0) = 0x804c000
9703 brk(0x804d000) = 0x804d000
9703 open("/etc/shadow", O_RDONLY) = 3
9703 fcntl64(3, F_GETFD) = 0
9703 fcntl64(3, F_SETFD, FD_CLOEXEC) = 0
9703 fstat64(3, {st_mode=S_IFREG|0400, st_size=4663, ...}) = 0
9703 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0)
= 0x40017000
9703 read(3,
"root:$1$rCboBhmu$M3Z50Yfu3QCdPPNIzLrGz/:12864:0:99999:7:::\nbin:*:12446:0:99999:7:::\ndaemon:*:12446:0:99999:7:::\nadm:*:12446:0:99999:7:::\nlp:*:12446:0:99999:7:::\nsync:*:12446:0:99999:7:::\nshutdown:*:12446:0:99999:7:::\nhalt:*:12446:0:99999:7:::\nmail:*:12446:0:99999:7:::\nnews:*:12446:0:99999:7:::\nuucp:*:12446:0:99999:7:::\noperator:*:12446:0:99999:7:::\ngames:*:12446:0:99999:7:::\ngopher:*:12446:0:99999:7:::\nftp:*:12446:0:99999:7:::\nnobody:*:12446:0:99999:7:::\nrpm:!!:12446:0:99999:7:::\nvcsa:!!:12446:0:99999:7:::\nnscd:!!:12446:0:99999:7:::\nsshd:!!:12446:0:99999:7:::\nrpc:!!:12446:0:99999:7:::\nrpcuser:!!:12446:0:99999:7:::\nnfsnobody:!!:12446:0:99999:7:::\nmailnull:!!:12446:0:99999:7:::\nsmmsp:!!:12446:0:99999:7:::\npcap:!!:12446:0:99999:7:::\napache:!!:12446:0:99999:7:::\nxfs:!!:12446:0:99999:7:::\nnamed:!!:12446:0:99999:7:::\nntp:!!:12446:0:99999:7:::\nmonnetf:$1$pr2EqnmY$gqNcBpzdAAhbOFYPFCzuw1:12446:0:99999:7:::\nmysql:$1$R2MTts81$VpyJnSoEFq1/H9xJcLYUD.:12741:0:99999:7:::\nqmaild:!!:12581:0:99999:7:::\nqmaill:!!:12581:0:99999:"...,
4096) = 4096
9703 close(3) = 0
9703 munmap(0x40017000, 4096) = 0
9703 setgroups32(0x1, 0xbfffe050) = 0
9703 setgid32(0x1f9 <unfinished ...>
8919 <... select resumed> ) = 1 (in [0], left {2145, 550000})
8919 gettimeofday({1136187996, 130923}, NULL) = 0
8919 select(1, [0], NULL, NULL, NULL) = 1 (in [0])
8919 gettimeofday({1136187996, 132479}, NULL) = 0
8919 read(0, "3 logout\r\n", 1024) = 10
8919 rt_sigaction(SIGPIPE, {SIG_IGN}, {SIG_IGN}, 8) = 0
8919 write(7, "3 logout\r\n", 10) = 10
8919 select(9, [0 8], NULL, NULL, {2160, 0}) = 1 (in [0], left {2160, 0})
8919 gettimeofday({1136187996, 133719}, NULL) = 0
8919 select(1, [0], NULL, NULL, NULL) = 1 (in [0])
8919 gettimeofday({1136187996, 134137}, NULL) = 0
8919 read(0, "", 1024) = 0
8919 close(8) = 0
8919 close(7) = 0
8919 wait4(9703, <unfinished ...>
