Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

apache

Posted on 2008-10-04
6
Medium Priority
?
273 Views
Last Modified: 2013-12-27
Can you please tell me whether " /Apache/platform/apache-2.0.55/bin/httpd -k start"  reads passwd and shadow files.  in solaris.. Thanks in advance..
0
Comment
Question by:conversekid
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 40

Assisted Solution

by:omarfarid
omarfarid earned 800 total points
ID: 22640914
why you think that it reads the passwd and shadow files?
0
 

Author Comment

by:conversekid
ID: 22641151
Apache is the only software running on the server and the passwd fie is getting corrupted once in a while..
0
 
LVL 40

Assisted Solution

by:omarfarid
omarfarid earned 800 total points
ID: 22641275
reading file does not corrupt it. Look for some other reason for that. Do you have any script that updates the passwd file?
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:conversekid
ID: 22641471
We checked all that before. Please check http://www.experts-exchange.com/OS/Unix/Solaris/Q_23748034.html.. This is one question which arose in the final discussion...
0
 
LVL 9

Assisted Solution

by:chingmd
chingmd earned 400 total points
ID: 22642011
Check the process list to make sure that httpd is running mostly as a non root account.  

You can also check the httpd.conf file to ensure that it is running as a non root account.   It may be that the a hole/page/exploit is running that is allowing right access to the password file.  

Check the permissions on the password file.  

Parse the access and error logs of the apache server to find out if there are access / http post  to the password/shadow file.  

look at the command "last".. see if there are any unusual activity on the log account or source.   An emtpy log is suspect too.


0
 
LVL 13

Accepted Solution

by:
Rowley earned 800 total points
ID: 22648057
Why not use some IDS software to help you figure out what is changing the file. Tripwire  is some commercial software you could use to help you, otherwise you could try http://www.la-samhna.de/ .

Solaris also comes with its own file accounting software - BART. http://docs.sun.com/app/docs/doc/816-4557/bart-1?a=view
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Over the last year I have answered a couple of basic URL rewriting questions several times so I thought I might as well have a stab at: explaining the basics, providing a few useful links and consolidating some of the most common queries into a sing…
Java performance on Solaris - Managing CPUs There are various resource controls in operating system which directly/indirectly influence the performance of application. one of the most important resource controls is "CPU".   In a multithreaded…
Learn several ways to interact with files and get file information from the bash shell. ls lists the contents of a directory: Using the -a flag displays hidden files: Using the -l flag formats the output in a long list: The file command gives us mor…
Learn how to get help with Linux/Unix bash shell commands. Use help to read help documents for built in bash shell commands.: Use man to interface with the online reference manuals for shell commands.: Use man to search man pages for unknown command…
Suggested Courses

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question