On Jun 15, 2002 at 12:01 +0200, Sven wrote: > I have get pass login thanks to init=/bin/bash > > But now (pure curiosity), a program overwrited my shadow with > string containnig word UMASTER (I attached the shadow file), > I can only login if not using file shadowing - because it is stil > overwriting the /etc/shadow again and again, while saving untouched > file as shadow-. > ps -aux command shows nothing, > but most of my logs are gone and syslogd is not anymore on my tty8. > I face with this kind of problem for a first time in my life - > no telnet nor ssh services were on, and remote user could not login > as a root. > So, what happened???
Virus or worm? Sounds suspicious... -- Thatcher Ulrich http://tulrich.com -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

