Re: root can't write to /bin, /sbin, or /usr/sbin

From: Bill Unruh (unruh_at_string.physics.ubc.ca)
Date: 10/28/04


Date: 28 Oct 2004 16:16:52 GMT

Jean-David Beyer <jdbeyer@exit109.com> writes:

]Mark Juric wrote:
]> I haven't posted for help in 5 years but I'm really stuck on this one.
]> I have a Redhat 9.0 (Shrike) box, same kernel that came with it
]> (2.4.20-8) that's been chugging along for over a year now.

]You might wish to upgrade that to the kernel-smp-2.4.20-31.9 (or the
]uniprocessing version) that I have on my RHL9 box. It would be reallysmart
]to upgrade to the latest and greatest that Red Hat have to offer. Since I
]am on dial-up, it took me about 2 days to download the upgrades I needed.
]I have burned them onto a CD-ROM in case I must start from scratch. But
]unlikely, since I do full backups to tape everyday.

That has nothing to do with his problem, except it may indicate that he is
very very lax about installing security upgrades, and he has been cracked.

]> I went to upgrade MySQL and it errored out because it was unable to
]> write to /usr/sbin. I don't know how long this has been the case, but
]> root can not write to /bin, /sbin, or /usr/sbin. It's the damndest
]> thing I've ever seen. The permissions are correct, and even if they
]> weren't root can't chmod or chown the directories anyway. I've booted
]> to an LFS CD and mounted the filesystem and still no joy.
]>
]> Anyone ever heard of this before? It's an EXT3 filesystem and I've
]> forced fsck on it several times and it found no errors. Is there some
]> secret inode lock that I've never heard of that I'm being affected by?
]> It's really frustrating!
]>
]You might have the directory attributes set too strictly.

]man chattr
]man lsattr

(Almost) no user ever sets these. If he did he would know about it. It is
an almost foolproof sign that a cracker has visited and his box is broken.
Reinstall, and then sweep for suid files on the stuff you restored. SO NOT
SIMPLE use chattr to reset the permissions. That is like discovering a
cancerous mole and putting some face powder on it to make it go away.



Relevant Pages

  • Re: Access to Network and Dial-Up Connections blocked
    ... We don't know that the driver upgrades are necessarily the ... if a NoPropertiesMyComputer policy exists: ... I re-enabled Remove Network Connection from ... If this is a permissions issue check and make sure that you have ...
    (microsoft.public.win2000.general)
  • Problem managing my domain
    ... I thought the upgrades to XP SP2 and 2003 applications might be causing the ... I then set the permissions back on the C: and D: drives of the servers to ...
    (microsoft.public.win2000.group_policy)
  • Re: AD issues
    ... a security group all by itself. ... Make sure AD is in native mode (unless you still have NT domain ... Outlook is not recognising Delegate permissions on these groups. ... It appears that the domain has been through a few upgrades (I see Exch 5.5 ...
    (microsoft.public.win2000.general)
  • XP Home: other users cant send mail, dont get IE popups
    ... I have Windows XP Home and I always install upgrades whenever Win XP ... This got me to thinking the whole problem is one of permissions. ... - send/receive email using Outlook. ...
    (microsoft.public.windowsxp.security_admin)

Loading