Mar 8 20:14:14 src@soup grsec: From 64.218.236.121: exec of /usr/bin/passwd (passwd ) by (bash:10812) UID(1006) EUID(1006), parent (bash:6702) UID(1006) EUID(1006)
Mar 8 20:14:17 src@soup grsec: From 64.218.236.121: denied open of /etc/.pwd.lock for writing by (passwd:10812) UID(0) EUID(0), parent (bash:6702) UID(1006) EUID(1006)
Mar 8 20:14:17 src@soup grsec: From 64.218.236.121: denied access to hidden file /usr/share/zoneinfo/US/Central by (passwd:10812) UID(0) EUID(0), parent (bash:6702) UID(1006) EUID(1006)
/usr/bin/passwd o {
/var/run/utmp rw
/usr/share/zoneinfo/US/Central r
/proc
/lib/libnss_compat-2.2.5.so rx
/lib/libnsl-2.2.5.so rx
/lib/libcrypt-2.2.5.so rx
/lib/libc-2.2.5.so rx
/lib/ld-2.2.5.so x
/etc rwx
/etc/shadow rw
/etc/passwd rw
/etc/nsswitch.conf r
/etc/login.defs r
/etc/ld.so.cache r
/etc/* h
/dev/tty rw
/dev/log rw
/usr/bin/passwd x
/ h
-CAP_ALL
+CAP_CHOWN
+CAP_FSETID
+CAP_SETUID
+CAP_SYS_RESOURCE
connect {
disabled
}
bind {
disabled
}
}
can someone please tell me what is going on here? I'm running one of the newest cvs's. .pwd.lock is a temporary file that passwd creates and the other file is allowed at the top of the acl.