Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

missing /usr/lib files & strange tar file - a hack?

Status
Not open for further replies.

dierkerj

MIS
May 2, 2002
3
US
Earlier in the week we encountered two Solaris hosts on our internal network that were "down". After some investigation it was discovered that MANY files and links in the /usr/lib directory structure were gone. After recovering to a point that we could reboot, we check the messages file and find that both servers began reporting errors about missing lib files at around the same time on the same night.

On both boxes, we found a new tar file in the root directory called 2003_Feb_05_22_30_01.tar. This tar file is reported as "English text" when it evaluated with the file command. It reports it's size as 1024. Running cat against the file returns nothing. If I vi the file it looks like an empty file, however the feedback line at the bottom of the vi session reports "0 lines, 1024 characters (1024 null)".

I am not seeking help in recovery - we've done that. Anyone know of a hack/virus going around with similar symptoms? Since the affected boxes were on the internal network (no others were "hit") I would normally suspect an internal attack or errant program. However, I see in a very recent post where another Tek-Tip user is reporting suspiciously similar events.

Thanks in advance.

Joe
 
I haven't heard of this. Did you list the contents of the tar file?
[tt]
tar tvf /2003_Feb_05_22_30_01.tar
[/tt]
If it was a single machine, I would suspect it was pilot error, or something like that. Since it was two machines with the same symptoms, it is suspicious.
 
It isn't really a tar file at all. The output of the file command run against it reports "English text" (note: NOT ascii text).

If I run tar commands against it, tar reports:
"tar: blocksize = 2"

Also note, it happened on two boxes here. I see another post in this groups within the past week from pgrayson (I think) reporting a similar problem with missing lib files on a machine at his location. He does not refer to the tar file...only the missing lib files.

Any other input is greatly appreciated.

Joe
 
No file of this nature on this machine.

Our network of Sun machines is used by a number of software developers who have a habit of breaking things.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top