TCLUG Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TCLUG:12706] VENIX



On Fri, 21 Jan 2000, Dan Debertin wrote:

> > You speak as if from experience...? I might have to be real impressed,
> > and then come over and bug you for fun stories. :)
> 
> Yup. Every time tripwire reports that something weird like 'du' or 'ls'
> has changed on a system, I pull out truss, strings and hexedit and have at
> it. Sometimes it turns out to be benign .... other times it's something
> like 'ooh look, what might open("/etc/shadow", O_RDONLY) be doing in the
> 'ls' program??'

heh :) My hat's off, man. So what, do real function calls show up when you
look at a bin with one of those tools? Seems unlikely. And where can I
get hexedit -- is that standard? I see here truss is showing that kind of
thing in its output. Fun.


--
Christopher Reid Palmer : www.innerfireworks.com

Let go of the hangers-on.