1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
|
aaron tuner # strace /usr/sbin/pppd /dev/ttyUSB0 unit 0 user web remotename ppp0 linkname ppp0 plugin passwordfd.so maxfail 25 updetach debug defaultroute usepeerdns ipcp-accept-remote ipcp-accept-local noipdefault novj nobsdcomp nodeflate novjccomp nopredictor1 nomagic persist lock lcp-echo-interval 5 lcp-echo-failure 3 mtu 1500 mru 1500 115200 modem crtscts passwordfd 0 defaultmetric 4005 connect /usr/sbin/chat -e -E -v -T 'ATDT*99***1#' ABORT BUSY ABORT ERROR ABORT 'NO ANSWER' ABORT 'NO CARRIER' REPORT CONNECT '' ATZ OK 'AT&F' OK AT+CGDCONT=1,"IP","web.vodafone.de" OK ATDT*99***1# CONNECT c
execve("/usr/sbin/pppd", ["/usr/sbin/pppd", "/dev/ttyUSB0", "unit", "0", "user", "web", "remotename", "ppp0", "linkname", "ppp0", "plugin", "passwordfd.so", "maxfail", "25", "updetach", "debug", ...], [/* 52 vars */]) = 0
brk(0) = 0x23cf000
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fb94e5dc000
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fb94e5db000
access("/etc/ld.so.preload", R_OK) = -1 ENOENT (No such file or directory)
open("/etc/ld.so.cache", O_RDONLY) = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=87389, ...}) = 0
mmap(NULL, 87389, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7fb94e5c5000
close(3) = 0
open("/lib/libcrypt.so.1", O_RDONLY) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0`\n\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=39016, ...}) = 0
mmap(NULL, 2322880, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7fb94e189000
mprotect(0x7fb94e191000, 2097152, PROT_NONE) = 0
mmap(0x7fb94e391000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x8000) = 0x7fb94e391000
mmap(0x7fb94e393000, 184768, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fb94e393000
close(3) = 0
open("/lib/libpam.so.0", O_RDONLY) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0 %\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=51576, ...}) = 0
mmap(NULL, 2146800, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7fb94df7c000
mprotect(0x7fb94df88000, 2093056, PROT_NONE) = 0
mmap(0x7fb94e187000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0xb000) = 0x7fb94e187000
close(3) = 0
open("/lib/libdl.so.2", O_RDONLY) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\360\r\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=14512, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fb94e5c4000
mmap(NULL, 2109696, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7fb94dd78000
mprotect(0x7fb94dd7a000, 2097152, PROT_NONE) = 0
mmap(0x7fb94df7a000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x2000) = 0x7fb94df7a000
close(3) = 0
open("/usr/lib/libpcap.so.1", O_RDONLY) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0@\200\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=257928, ...}) = 0
mmap(NULL, 2356448, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7fb94db38000
mprotect(0x7fb94db75000, 2097152, PROT_NONE) = 0
mmap(0x7fb94dd75000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x3d000) = 0x7fb94dd75000
mmap(0x7fb94dd77000, 1248, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fb94dd77000
close(3) = 0
open("/lib/libc.so.6", O_RDONLY) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0@\353\1\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=1399984, ...}) = 0
mmap(NULL, 3508264, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7fb94d7df000
mprotect(0x7fb94d92e000, 2097152, PROT_NONE) = 0
mmap(0x7fb94db2e000, 20480, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x14f000) = 0x7fb94db2e000
mmap(0x7fb94db33000, 18472, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fb94db33000
close(3) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fb94e5c3000
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fb94e5c2000
arch_prctl(ARCH_SET_FS, 0x7fb94e5c26f0) = 0
mprotect(0x7fb94db2e000, 16384, PROT_READ) = 0
mprotect(0x7fb94dd75000, 4096, PROT_READ) = 0
mprotect(0x7fb94df7a000, 4096, PROT_READ) = 0
mprotect(0x7fb94e187000, 4096, PROT_READ) = 0
mprotect(0x7fb94e391000, 4096, PROT_READ) = 0
mprotect(0x64b000, 4096, PROT_READ) = 0
mprotect(0x7fb94e5dd000, 4096, PROT_READ) = 0
munmap(0x7fb94e5c5000, 87389) = 0
socket(PF_FILE, SOCK_DGRAM|SOCK_CLOEXEC, 0) = 3
connect(3, {sa_family=AF_FILE, path="/dev/log"}, 110) = -1 EPROTOTYPE (Protocol wrong type for socket)
close(3) = 0
socket(PF_FILE, SOCK_STREAM|SOCK_CLOEXEC, 0) = 3
connect(3, {sa_family=AF_FILE, path="/dev/log"}, 110) = 0
uname({sys="Linux", node="aaron", ...}) = 0
umask(0777) = 022
umask(022) = 0777
getuid() = 0
brk(0) = 0x23cf000
brk(0x23f0000) = 0x23f0000
getgroups(65536, [0, 1, 2, 3, 4, 6, 10, 11, 20, 26, 27]) = 11
getpid() = 13035
geteuid() = 0
open("/etc/ppp/options", O_RDONLY) = 4
fstat(4, {st_mode=S_IFREG|0644, st_size=5, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fb94e5da000
read(4, "lock\n", 4096) = 5
read(4, "", 4096) = 0
close(4) = 0
munmap(0x7fb94e5da000, 4096) = 0
getuid() = 0
socket(PF_FILE, SOCK_STREAM|SOCK_CLOEXEC|SOCK_NONBLOCK, 0) = 4
connect(4, {sa_family=AF_FILE, path="/var/run/nscd/socket"}, 110) = -1 ENOENT (No such file or directory)
close(4) = 0
socket(PF_FILE, SOCK_STREAM|SOCK_CLOEXEC|SOCK_NONBLOCK, 0) = 4
connect(4, {sa_family=AF_FILE, path="/var/run/nscd/socket"}, 110) = -1 ENOENT (No such file or directory)
close(4) = 0
open("/etc/nsswitch.conf", O_RDONLY) = 4
fstat(4, {st_mode=S_IFREG|0644, st_size=508, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fb94e5da000
read(4, "# /etc/nsswitch.conf:\n# $Header:"..., 4096) = 508
read(4, "", 4096) = 0
close(4) = 0
munmap(0x7fb94e5da000, 4096) = 0
open("/etc/ld.so.cache", O_RDONLY) = 4
fstat(4, {st_mode=S_IFREG|0644, st_size=87389, ...}) = 0
mmap(NULL, 87389, PROT_READ, MAP_PRIVATE, 4, 0) = 0x7fb94e5c5000
close(4) = 0
open("/lib/libnss_compat.so.2", O_RDONLY) = 4
read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0 \23\0\0\0\0\0\0"..., 832) = 832
fstat(4, {st_mode=S_IFREG|0755, st_size=31432, ...}) = 0
mmap(NULL, 2127088, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fb94d5d7000
mprotect(0x7fb94d5de000, 2093056, PROT_NONE) = 0
mmap(0x7fb94d7dd000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x6000) = 0x7fb94d7dd000
close(4) = 0
open("/lib/libnsl.so.1", O_RDONLY) = 4
read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\320@\0\0\0\0\0\0"..., 832) = 832
fstat(4, {st_mode=S_IFREG|0755, st_size=88880, ...}) = 0
mmap(NULL, 2194128, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fb94d3bf000
mprotect(0x7fb94d3d4000, 2093056, PROT_NONE) = 0
mmap(0x7fb94d5d3000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x14000) = 0x7fb94d5d3000
mmap(0x7fb94d5d5000, 6864, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fb94d5d5000
close(4) = 0
mprotect(0x7fb94d5d3000, 4096, PROT_READ) = 0
mprotect(0x7fb94d7dd000, 4096, PROT_READ) = 0
munmap(0x7fb94e5c5000, 87389) = 0
open("/etc/ld.so.cache", O_RDONLY) = 4
fstat(4, {st_mode=S_IFREG|0644, st_size=87389, ...}) = 0
mmap(NULL, 87389, PROT_READ, MAP_PRIVATE, 4, 0) = 0x7fb94e5c5000
close(4) = 0
open("/lib/libnss_nis.so.2", O_RDONLY) = 4
read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\320 \0\0\0\0\0\0"..., 832) = 832
fstat(4, {st_mode=S_IFREG|0755, st_size=43384, ...}) = 0
mmap(NULL, 2139352, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fb94d1b4000
mprotect(0x7fb94d1be000, 2093056, PROT_NONE) = 0
mmap(0x7fb94d3bd000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x9000) = 0x7fb94d3bd000
close(4) = 0
open("/lib/libnss_files.so.2", O_RDONLY) = 4
read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0p!\0\0\0\0\0\0"..., 832) = 832
fstat(4, {st_mode=S_IFREG|0755, st_size=47432, ...}) = 0
mmap(NULL, 2143632, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fb94cfa8000
mprotect(0x7fb94cfb3000, 2093056, PROT_NONE) = 0
mmap(0x7fb94d1b2000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0xa000) = 0x7fb94d1b2000
close(4) = 0
mprotect(0x7fb94d1b2000, 4096, PROT_READ) = 0
mprotect(0x7fb94d3bd000, 4096, PROT_READ) = 0
munmap(0x7fb94e5c5000, 87389) = 0
open("/etc/passwd", O_RDONLY|O_CLOEXEC) = 4
fcntl(4, F_GETFD) = 0x1 (flags FD_CLOEXEC)
lseek(4, 0, SEEK_CUR) = 0
fstat(4, {st_mode=S_IFREG|0644, st_size=1241, ...}) = 0
mmap(NULL, 1241, PROT_READ, MAP_SHARED, 4, 0) = 0x7fb94e5da000
lseek(4, 1241, SEEK_SET) = 1241
munmap(0x7fb94e5da000, 1241) = 0
close(4) = 0
geteuid() = 0
getuid() = 0
setresuid(-1, 0, -1) = 0
open("/root/.ppprc", O_RDONLY) = -1 ENOENT (No such file or directory)
setresuid(-1, 0, -1) = 0
stat("/dev/ttyUSB0", {st_mode=S_IFCHR|0660, st_rdev=makedev(188, 0), ...}) = 0
stat("/dev/ttyUSB0", {st_mode=S_IFCHR|0660, st_rdev=makedev(188, 0), ...}) = 0
open("/usr/lib64/pppd/2.4.4/passwordfd.so", O_RDONLY) = 4
read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\200\10\0\0\0\0\0\0"..., 832) = 832
fstat(4, {st_mode=S_IFREG|0755, st_size=6128, ...}) = 0
mmap(NULL, 2101792, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fb94cda6000
mprotect(0x7fb94cda7000, 2093056, PROT_NONE) = 0
mmap(0x7fb94cfa6000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0) = 0x7fb94cfa6000
close(4) = 0
mprotect(0x7fb94cfa6000, 4096, PROT_READ) = 0
open("/etc/localtime", O_RDONLY) = 4
fstat(4, {st_mode=S_IFREG|0644, st_size=2309, ...}) = 0
fstat(4, {st_mode=S_IFREG|0644, st_size=2309, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fb94e5da000
read(4, "TZif2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\10\0\0\0\0"..., 4096) = 2309
lseek(4, -1467, SEEK_CUR) = 842
read(4, "TZif2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\t\0\0\0\t\0\0\0\0"..., 4096) = 1467
close(4) = 0
munmap(0x7fb94e5da000, 4096) = 0
sendto(3, "<30>May 22 20:26:08 pppd[13035]:"..., 62, MSG_NOSIGNAL, NULL, 0) = 62
write(1, "Plugin passwordfd.so loaded.", 28Plugin passwordfd.so loaded.) = 28
write(1, "\n", 1
) = 1
stat("/dev/115200", 0x7fff2e0b5d30) = -1 ENOENT (No such file or directory)
read(0,
|