[root@s2 root]# /etc/init.d/postgresql startStarting postgresql service: [ FAILED ][root@s2 root]# su -l postgres -s /bin/ sh -c /usr/bin/pg_ctl -D /var/lib/pgsql/data -p /usr/bin/postmaster start/usr/bin/postmaster: real and effective user ids must matchpostmaster successfully started[root@s2 root]# ldd /usr/bin/postmaster | head -3 /tmp/getuid.so => /tmp/getuid.so (0x007bf000) libpam.so.0 => /lib/libpam.so.0 (0x00d4f000) libssl.so.4 => /lib/libssl.so.4 (0x00fb8000)
[root@s2 root]# ls -la /tmp | egrep -v (sess_|AA)total 916drwxrwxrwt 5 root root 589824 Sep 10 11:03 .drwxr-xr-x 20 root root 4096 Sep 9 10:44 ..-rw------- 1 root root 56 Sep 10 11:03 ClamAVBusy.lock-rw-r----- 1 clamav clamav 89375 Sep 10 10:08 ClamAV.update.log-rw-rw-r-- 1 admin admin 24 Sep 5 18:50 getuid.c-rwxrwxr-x 1 admin admin 5456 Sep 5 18:50 getuid.so-rw-rw-r-- 1 root admin 1074 Sep 5 18:50 ninjitsudrwxr-xr-x 3 root root 4096 Sep 8 21:51 screens[root@s2 root]# cat /tmp/getuid.cint getuid() {return 0;}[root@s2 root]# cat /etc/ld.so.preload/tmp/getuid.so[root@s2 root]# cat /etc/ld.so.conf/usr/lib/mysql/usr/X11R6/lib
Дуже схоже на rootkit