Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Does this look like my pfSense was hacked

    General pfSense Questions
    3
    5
    2.9k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      guardian Rebel Alliance
      last edited by

      I had a power failure today (pfSense is just being tested, so I don't have it on a UPS), and I tried to log in as root with SSH and it didn't work.  Fortunately I had another userid with sudo, so I was able to get the root password fixed, but before I changed the password, I had a look in /etc/master.passwd and I saw the following:

      root:$–----REMOVED----------m:0:0::0:0:Charlie &:/root:/bin/sh
      toor::0:0::0:0:Bourne-again Superuser:/root:
      daemon:
      :1:1::0:0:Owner of many system processes:/root:/usr/sbin/nologin

      Two things I am wondering about:

      • Where did 'Charlie &' come from?  My name is not Charlie and there is not way I put that into the setup.

      • is toor:*:0:0::0:0:Bourne-again Superuser:/root: a normal entry?

      I'm wondering if this is normal, did I likely suffer corruption, or was I likely hacked and should wipe the box and reload it?

      I can't remember exactly, but the box started out as v2.3 and I have done all the upgrades.  I have also installed / removed a number of packages.

      Also, I can't remember, is root access normally allowed or does the standard install force the use of admin and sudo?

      Does pfSense have anything like rkhunter to detect unauthorized changes?

      Any assistance is much appreciated.

      If you find my post useful, please give it a thumbs up!
      pfSense 2.7.2-RELEASE

      1 Reply Last reply Reply Quote 0
      • M
        maverick_slo
        last edited by

        Normal…

        https://forum.pfsense.org/index.php?topic=53429.0

        1 Reply Last reply Reply Quote 0
        • G
          guardian Rebel Alliance
          last edited by

          Thanks… that Charlie had me scared!

          If you find my post useful, please give it a thumbs up!
          pfSense 2.7.2-RELEASE

          1 Reply Last reply Reply Quote 0
          • K
            kpa
            last edited by

            https://en.wikipedia.org/wiki/Charlie_Root  ;)

            1 Reply Last reply Reply Quote 0
            • G
              guardian Rebel Alliance
              last edited by

              Thanks… I was wondering what that was about... obviously someone has a sense of humour that was a bit too obscure for me  ;)

              If you find my post useful, please give it a thumbs up!
              pfSense 2.7.2-RELEASE

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.