Advertisement
Guest User

Untitled

a guest
Sep 15th, 2017
146
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 60.38 KB | None | 0 0
  1. execve("/usr/bin/sudo", ["sudo", "su", "-"], [/* 12 vars */]) = 0
  2. brk(NULL) = 0x55a011d50000
  3. access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
  4. mmap(NULL, 12288, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f51e80db000
  5. access("/etc/ld.so.preload", R_OK) = -1 ENOENT (No such file or directory)
  6. open("/usr/lib/sudo/tls/x86_64/libaudit.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory)
  7. stat("/usr/lib/sudo/tls/x86_64", 0x7ffcc94963f0) = -1 ENOENT (No such file or directory)
  8. open("/usr/lib/sudo/tls/libaudit.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory)
  9. stat("/usr/lib/sudo/tls", 0x7ffcc94963f0) = -1 ENOENT (No such file or directory)
  10. open("/usr/lib/sudo/x86_64/libaudit.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory)
  11. stat("/usr/lib/sudo/x86_64", 0x7ffcc94963f0) = -1 ENOENT (No such file or directory)
  12. open("/usr/lib/sudo/libaudit.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory)
  13. stat("/usr/lib/sudo", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0
  14. open("/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 3
  15. fstat(3, {st_mode=S_IFREG|0644, st_size=110784, ...}) = 0
  16. mmap(NULL, 110784, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f51e80bf000
  17. close(3) = 0
  18. access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
  19. open("/lib/x86_64-linux-gnu/libaudit.so.1", O_RDONLY|O_CLOEXEC) = 3
  20. read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0-\0\0\0\0\0\0"..., 832) = 832
  21. fstat(3, {st_mode=S_IFREG|0644, st_size=120752, ...}) = 0
  22. mmap(NULL, 2257000, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f51e7c93000
  23. mprotect(0x7f51e7cb0000, 2093056, PROT_NONE) = 0
  24. mmap(0x7f51e7eaf000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1c000) = 0x7f51e7eaf000
  25. mmap(0x7f51e7eb1000, 36968, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f51e7eb1000
  26. close(3) = 0
  27. open("/usr/lib/sudo/libselinux.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory)
  28. access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
  29. open("/lib/x86_64-linux-gnu/libselinux.so.1", O_RDONLY|O_CLOEXEC) = 3
  30. read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0000k\0\0\0\0\0\0"..., 832) = 832
  31. fstat(3, {st_mode=S_IFREG|0644, st_size=155400, ...}) = 0
  32. mmap(NULL, 2259664, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f51e7a6b000
  33. mprotect(0x7f51e7a90000, 2093056, PROT_NONE) = 0
  34. mmap(0x7f51e7c8f000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x24000) = 0x7f51e7c8f000
  35. mmap(0x7f51e7c91000, 6864, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f51e7c91000
  36. close(3) = 0
  37. open("/usr/lib/sudo/libutil.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory)
  38. access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
  39. open("/lib/x86_64-linux-gnu/libutil.so.1", O_RDONLY|O_CLOEXEC) = 3
  40. read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0@\16\0\0\0\0\0\0"..., 832) = 832
  41. fstat(3, {st_mode=S_IFREG|0644, st_size=10688, ...}) = 0
  42. mmap(NULL, 2105608, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f51e7868000
  43. mprotect(0x7f51e786a000, 2093056, PROT_NONE) = 0
  44. mmap(0x7f51e7a69000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1000) = 0x7f51e7a69000
  45. close(3) = 0
  46. open("/usr/lib/sudo/libsudo_util.so.0", O_RDONLY|O_CLOEXEC) = 3
  47. read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0`>\0\0\0\0\0\0"..., 832) = 832
  48. fstat(3, {st_mode=S_IFREG|0644, st_size=80264, ...}) = 0
  49. mmap(NULL, 2175848, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f51e7654000
  50. mprotect(0x7f51e7667000, 2093056, PROT_NONE) = 0
  51. mmap(0x7f51e7866000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x12000) = 0x7f51e7866000
  52. close(3) = 0
  53. open("/usr/lib/sudo/libdl.so.2", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory)
  54. access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
  55. open("/lib/x86_64-linux-gnu/libdl.so.2", O_RDONLY|O_CLOEXEC) = 3
  56. read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\200\r\0\0\0\0\0\0"..., 832) = 832
  57. fstat(3, {st_mode=S_IFREG|0644, st_size=14640, ...}) = 0
  58. mmap(NULL, 2109680, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f51e7450000
  59. mprotect(0x7f51e7453000, 2093056, PROT_NONE) = 0
  60. mmap(0x7f51e7652000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x2000) = 0x7f51e7652000
  61. close(3) = 0
  62. open("/usr/lib/sudo/libc.so.6", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory)
  63. access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
  64. open("/lib/x86_64-linux-gnu/libc.so.6", O_RDONLY|O_CLOEXEC) = 3
  65. read(3, "\177ELF\2\1\1\3\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\320\3\2\0\0\0\0\0"..., 832) = 832
  66. fstat(3, {st_mode=S_IFREG|0755, st_size=1689360, ...}) = 0
  67. mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f51e80bd000
  68. mmap(NULL, 3795360, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f51e70b1000
  69. mprotect(0x7f51e7246000, 2097152, PROT_NONE) = 0
  70. mmap(0x7f51e7446000, 24576, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x195000) = 0x7f51e7446000
  71. mmap(0x7f51e744c000, 14752, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f51e744c000
  72. close(3) = 0
  73. access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
  74. open("/lib/x86_64-linux-gnu/libcap-ng.so.0", O_RDONLY|O_CLOEXEC) = 3
  75. read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\20\25\0\0\0\0\0\0"..., 832) = 832
  76. fstat(3, {st_mode=S_IFREG|0644, st_size=22944, ...}) = 0
  77. mmap(NULL, 2118008, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f51e6eab000
  78. mprotect(0x7f51e6eaf000, 2097152, PROT_NONE) = 0
  79. mmap(0x7f51e70af000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x4000) = 0x7f51e70af000
  80. close(3) = 0
  81. access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
  82. open("/lib/x86_64-linux-gnu/libpcre.so.3", O_RDONLY|O_CLOEXEC) = 3
  83. read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\320\25\0\0\0\0\0\0"..., 832) = 832
  84. fstat(3, {st_mode=S_IFREG|0644, st_size=468920, ...}) = 0
  85. mmap(NULL, 2564360, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f51e6c38000
  86. mprotect(0x7f51e6caa000, 2093056, PROT_NONE) = 0
  87. mmap(0x7f51e6ea9000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x71000) = 0x7f51e6ea9000
  88. close(3) = 0
  89. access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
  90. open("/lib/x86_64-linux-gnu/libpthread.so.0", O_RDONLY|O_CLOEXEC) = 3
  91. read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0Pa\0\0\0\0\0\0"..., 832) = 832
  92. fstat(3, {st_mode=S_IFREG|0755, st_size=135440, ...}) = 0
  93. mmap(NULL, 2212936, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f51e6a1b000
  94. mprotect(0x7f51e6a33000, 2093056, PROT_NONE) = 0
  95. mmap(0x7f51e6c32000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x17000) = 0x7f51e6c32000
  96. mmap(0x7f51e6c34000, 13384, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f51e6c34000
  97. close(3) = 0
  98. mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f51e80bb000
  99. arch_prctl(ARCH_SET_FS, 0x7f51e80bbec0) = 0
  100. mprotect(0x7f51e7446000, 16384, PROT_READ) = 0
  101. mprotect(0x7f51e6c32000, 4096, PROT_READ) = 0
  102. mprotect(0x7f51e6ea9000, 4096, PROT_READ) = 0
  103. mprotect(0x7f51e70af000, 4096, PROT_READ) = 0
  104. mprotect(0x7f51e7652000, 4096, PROT_READ) = 0
  105. mprotect(0x7f51e7866000, 4096, PROT_READ) = 0
  106. mprotect(0x7f51e7a69000, 4096, PROT_READ) = 0
  107. mprotect(0x7f51e7c8f000, 4096, PROT_READ) = 0
  108. mprotect(0x7f51e7eaf000, 4096, PROT_READ) = 0
  109. mprotect(0x55a0116c0000, 4096, PROT_READ) = 0
  110. mprotect(0x7f51e80de000, 4096, PROT_READ) = 0
  111. munmap(0x7f51e80bf000, 110784) = 0
  112. set_tid_address(0x7f51e80bc190) = 738
  113. set_robust_list(0x7f51e80bc1a0, 24) = 0
  114. rt_sigaction(SIGRTMIN, {sa_handler=0x7f51e6a20bd0, sa_mask=[], sa_flags=SA_RESTORER|SA_SIGINFO, sa_restorer=0x7f51e6a2c0c0}, NULL, 8) = 0
  115. rt_sigaction(SIGRT_1, {sa_handler=0x7f51e6a20c60, sa_mask=[], sa_flags=SA_RESTORER|SA_RESTART|SA_SIGINFO, sa_restorer=0x7f51e6a2c0c0}, NULL, 8) = 0
  116. rt_sigprocmask(SIG_UNBLOCK, [RTMIN RT_1], NULL, 8) = 0
  117. getrlimit(RLIMIT_STACK, {rlim_cur=8192*1024, rlim_max=RLIM64_INFINITY}) = 0
  118. statfs("/sys/fs/selinux", 0x7ffcc9497c40) = -1 ENOENT (No such file or directory)
  119. statfs("/selinux", 0x7ffcc9497c40) = -1 ENOENT (No such file or directory)
  120. brk(NULL) = 0x55a011d50000
  121. brk(0x55a011d71000) = 0x55a011d71000
  122. open("/proc/filesystems", O_RDONLY) = 3
  123. fstat(3, {st_mode=S_IFREG|0444, st_size=0, ...}) = 0
  124. read(3, "nodev\tsysfs\nnodev\trootfs\nnodev\tr"..., 1024) = 306
  125. read(3, "", 1024) = 0
  126. close(3) = 0
  127. access("/etc/selinux/config", F_OK) = -1 ENOENT (No such file or directory)
  128. fcntl(0, F_GETFL) = 0x8002 (flags O_RDWR|O_LARGEFILE)
  129. fcntl(1, F_GETFL) = 0x8002 (flags O_RDWR|O_LARGEFILE)
  130. fcntl(2, F_GETFL) = 0x8002 (flags O_RDWR|O_LARGEFILE)
  131. open("/usr/lib/locale/locale-archive", O_RDONLY|O_CLOEXEC) = 3
  132. fstat(3, {st_mode=S_IFREG|0644, st_size=1679488, ...}) = 0
  133. mmap(NULL, 1679488, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f51e7f20000
  134. close(3) = 0
  135. open("/etc/localtime", O_RDONLY|O_CLOEXEC) = 3
  136. fstat(3, {st_mode=S_IFREG|0644, st_size=2016, ...}) = 0
  137. fstat(3, {st_mode=S_IFREG|0644, st_size=2016, ...}) = 0
  138. read(3, "TZif2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3\0\0\0\3\0\0\0\0"..., 4096) = 2016
  139. lseek(3, -1291, SEEK_CUR) = 725
  140. read(3, "TZif2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3\0\0\0\3\0\0\0\0"..., 4096) = 1291
  141. close(3) = 0
  142. stat("/etc/sudo.conf", 0x7ffcc9497920) = -1 ENOENT (No such file or directory)
  143. geteuid() = 0
  144. rt_sigaction(SIGALRM, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
  145. rt_sigaction(SIGCHLD, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
  146. rt_sigaction(SIGCONT, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
  147. rt_sigaction(SIGHUP, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
  148. rt_sigaction(SIGINT, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
  149. rt_sigaction(SIGPIPE, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
  150. rt_sigaction(SIGQUIT, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
  151. rt_sigaction(SIGTERM, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
  152. rt_sigaction(SIGTSTP, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
  153. rt_sigaction(SIGTTIN, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
  154. rt_sigaction(SIGTTOU, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
  155. rt_sigaction(SIGUSR1, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
  156. rt_sigaction(SIGUSR2, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
  157. pipe([3, 4]) = 0
  158. fcntl(3, F_GETFL) = 0 (flags O_RDONLY)
  159. fcntl(3, F_SETFL, O_RDONLY|O_NONBLOCK) = 0
  160. fcntl(4, F_GETFL) = 0x1 (flags O_WRONLY)
  161. fcntl(4, F_SETFL, O_WRONLY|O_NONBLOCK) = 0
  162. rt_sigaction(SIGALRM, {sa_handler=0x55a0114b17f0, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_RESTART, sa_restorer=0x7f51e70e4030}, NULL, 8) = 0
  163. rt_sigaction(SIGHUP, {sa_handler=0x55a0114b17f0, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_RESTART, sa_restorer=0x7f51e70e4030}, NULL, 8) = 0
  164. rt_sigaction(SIGINT, {sa_handler=0x55a0114b17f0, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_RESTART, sa_restorer=0x7f51e70e4030}, NULL, 8) = 0
  165. rt_sigaction(SIGQUIT, {sa_handler=0x55a0114b17f0, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_RESTART, sa_restorer=0x7f51e70e4030}, NULL, 8) = 0
  166. rt_sigaction(SIGTERM, {sa_handler=0x55a0114b17f0, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_RESTART, sa_restorer=0x7f51e70e4030}, NULL, 8) = 0
  167. rt_sigaction(SIGTSTP, {sa_handler=0x55a0114b17f0, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_RESTART, sa_restorer=0x7f51e70e4030}, NULL, 8) = 0
  168. rt_sigaction(SIGUSR1, {sa_handler=0x55a0114b17f0, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_RESTART, sa_restorer=0x7f51e70e4030}, NULL, 8) = 0
  169. rt_sigaction(SIGUSR2, {sa_handler=0x55a0114b17f0, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_RESTART, sa_restorer=0x7f51e70e4030}, NULL, 8) = 0
  170. rt_sigaction(SIGPIPE, {sa_handler=SIG_IGN, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_RESTART, sa_restorer=0x7f51e70e4030}, NULL, 8) = 0
  171. rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
  172. stat("/etc/sudo.conf", 0x7ffcc9497920) = -1 ENOENT (No such file or directory)
  173. getpid() = 738
  174. getppid() = 736
  175. getpgid(0) = 736
  176. open("/dev/tty", O_RDWR) = 5
  177. ioctl(5, TIOCGPGRP, [736]) = 0
  178. close(5) = 0
  179. getsid(0) = 735
  180. getuid() = 0
  181. geteuid() = 0
  182. getgid() = 0
  183. getegid() = 0
  184. socket(AF_UNIX, SOCK_STREAM|SOCK_CLOEXEC|SOCK_NONBLOCK, 0) = 5
  185. connect(5, {sa_family=AF_UNIX, sun_path="/var/run/nscd/socket"}, 110) = -1 ENOENT (No such file or directory)
  186. close(5) = 0
  187. socket(AF_UNIX, SOCK_STREAM|SOCK_CLOEXEC|SOCK_NONBLOCK, 0) = 5
  188. connect(5, {sa_family=AF_UNIX, sun_path="/var/run/nscd/socket"}, 110) = -1 ENOENT (No such file or directory)
  189. close(5) = 0
  190. open("/etc/nsswitch.conf", O_RDONLY|O_CLOEXEC) = 5
  191. fstat(5, {st_mode=S_IFREG|0644, st_size=540, ...}) = 0
  192. read(5, "# /etc/nsswitch.conf\n#\n# Example"..., 4096) = 540
  193. read(5, "", 4096) = 0
  194. close(5) = 0
  195. open("/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 5
  196. fstat(5, {st_mode=S_IFREG|0644, st_size=110784, ...}) = 0
  197. mmap(NULL, 110784, PROT_READ, MAP_PRIVATE, 5, 0) = 0x7f51e80bf000
  198. close(5) = 0
  199. access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
  200. open("/lib/x86_64-linux-gnu/libnss_compat.so.2", O_RDONLY|O_CLOEXEC) = 5
  201. read(5, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\260\22\0\0\0\0\0\0"..., 832) = 832
  202. fstat(5, {st_mode=S_IFREG|0644, st_size=31616, ...}) = 0
  203. mmap(NULL, 2126944, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 5, 0) = 0x7f51e6813000
  204. mprotect(0x7f51e681a000, 2093056, PROT_NONE) = 0
  205. mmap(0x7f51e6a19000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 5, 0x6000) = 0x7f51e6a19000
  206. close(5) = 0
  207. access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
  208. open("/lib/x86_64-linux-gnu/libnsl.so.1", O_RDONLY|O_CLOEXEC) = 5
  209. read(5, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\320?\0\0\0\0\0\0"..., 832) = 832
  210. fstat(5, {st_mode=S_IFREG|0644, st_size=89064, ...}) = 0
  211. mmap(NULL, 2194008, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 5, 0) = 0x7f51e65fb000
  212. mprotect(0x7f51e660f000, 2097152, PROT_NONE) = 0
  213. mmap(0x7f51e680f000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 5, 0x14000) = 0x7f51e680f000
  214. mmap(0x7f51e6811000, 6744, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f51e6811000
  215. close(5) = 0
  216. mprotect(0x7f51e680f000, 4096, PROT_READ) = 0
  217. mprotect(0x7f51e6a19000, 4096, PROT_READ) = 0
  218. munmap(0x7f51e80bf000, 110784) = 0
  219. open("/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 5
  220. fstat(5, {st_mode=S_IFREG|0644, st_size=110784, ...}) = 0
  221. mmap(NULL, 110784, PROT_READ, MAP_PRIVATE, 5, 0) = 0x7f51e80bf000
  222. close(5) = 0
  223. access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
  224. open("/lib/x86_64-linux-gnu/libnss_nis.so.2", O_RDONLY|O_CLOEXEC) = 5
  225. read(5, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\340 \0\0\0\0\0\0"..., 832) = 832
  226. fstat(5, {st_mode=S_IFREG|0644, st_size=47688, ...}) = 0
  227. mmap(NULL, 2143656, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 5, 0) = 0x7f51e63ef000
  228. mprotect(0x7f51e63fa000, 2093056, PROT_NONE) = 0
  229. mmap(0x7f51e65f9000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 5, 0xa000) = 0x7f51e65f9000
  230. close(5) = 0
  231. access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
  232. open("/lib/x86_64-linux-gnu/libnss_files.so.2", O_RDONLY|O_CLOEXEC) = 5
  233. read(5, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\320!\0\0\0\0\0\0"..., 832) = 832
  234. fstat(5, {st_mode=S_IFREG|0644, st_size=47632, ...}) = 0
  235. mmap(NULL, 2168600, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 5, 0) = 0x7f51e61dd000
  236. mprotect(0x7f51e61e7000, 2097152, PROT_NONE) = 0
  237. mmap(0x7f51e63e7000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 5, 0xa000) = 0x7f51e63e7000
  238. mmap(0x7f51e63e9000, 22296, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f51e63e9000
  239. close(5) = 0
  240. mprotect(0x7f51e63e7000, 4096, PROT_READ) = 0
  241. mprotect(0x7f51e65f9000, 4096, PROT_READ) = 0
  242. munmap(0x7f51e80bf000, 110784) = 0
  243. open("/etc/passwd", O_RDONLY|O_CLOEXEC) = 5
  244. lseek(5, 0, SEEK_CUR) = 0
  245. fstat(5, {st_mode=S_IFREG|0644, st_size=2415, ...}) = 0
  246. mmap(NULL, 2415, PROT_READ, MAP_SHARED, 5, 0) = 0x7f51e80da000
  247. lseek(5, 2415, SEEK_SET) = 2415
  248. munmap(0x7f51e80da000, 2415) = 0
  249. close(5) = 0
  250. open("/proc/sys/kernel/ngroups_max", O_RDONLY) = 5
  251. read(5, "65536\n", 31) = 6
  252. close(5) = 0
  253. getgroups(0, NULL) = 1
  254. getgroups(1, [0]) = 1
  255. umask(000) = 022
  256. umask(022) = 000
  257. getcwd("/root", 4096) = 6
  258. open("/proc/self/stat", O_RDONLY|O_NOFOLLOW) = 5
  259. read(5, "738 (sudo) R 736 736 735 34816 7"..., 1024) = 308
  260. read(5, "", 716) = 0
  261. stat("/dev/console", {st_mode=S_IFCHR|0600, st_rdev=makedev(5, 1), ...}) = 0
  262. stat("/dev/pts/0", {st_mode=S_IFCHR|0620, st_rdev=makedev(136, 0), ...}) = 0
  263. close(5) = 0
  264. uname({sysname="Linux", nodename="localhost.localdomain", ...}) = 0
  265. ioctl(2, TIOCGWINSZ, {ws_row=37, ws_col=100, ws_xpixel=0, ws_ypixel=0}) = 0
  266. getrlimit(RLIMIT_CORE, {rlim_cur=0, rlim_max=RLIM64_INFINITY}) = 0
  267. setrlimit(RLIMIT_CORE, {rlim_cur=0, rlim_max=RLIM64_INFINITY}) = 0
  268. socket(AF_NETLINK, SOCK_RAW, NETLINK_ROUTE) = 5
  269. bind(5, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, 12) = 0
  270. getsockname(5, {sa_family=AF_NETLINK, nl_pid=738, nl_groups=00000000}, [12]) = 0
  271. sendto(5, {{len=20, type=0x12 /* NLMSG_??? */, flags=NLM_F_REQUEST|0x300, seq=1505345795, pid=0}, "\0\0\0\0"}, 20, 0, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, 12) = 20
  272. recvmsg(5, {msg_name={sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, msg_namelen=12, msg_iov=[{iov_base=[{{len=1232, type=0x10 /* NLMSG_??? */, flags=NLM_F_MULTI, seq=1505345795, pid=738}, "\0\0\4\3\1\0\0\0I\0\1\0\0\0\0\0\7\0\3\0lo\0\0\10\0\r\0\1\0\0\0"...}, {{len=1240, type=0x10 /* NLMSG_??? */, flags=NLM_F_MULTI, seq=1505345795, pid=738}, "\0\0\1\0\2\0\0\0C\20\1\0\0\0\0\0\v\0\3\0enp0s3\0\0\10\0\r\0"...}, {{len=1240, type=0x10 /* NLMSG_??? */, flags=NLM_F_MULTI, seq=1505345795, pid=738}, "\0\0\1\0\3\0\0\0C\20\1\0\0\0\0\0\v\0\3\0enp0s8\0\0\10\0\r\0"...}, {{len=0, type=0 /* NLMSG_??? */, flags=0, seq=0, pid=0}}], iov_len=4096}], msg_iovlen=1, msg_controllen=0, msg_flags=0}, 0) = 3712
  273. recvmsg(5, {msg_name={sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, msg_namelen=12, msg_iov=[{iov_base=[{{len=20, type=NLMSG_DONE, flags=NLM_F_MULTI, seq=1505345795, pid=738}, "\0\0\0\0"}, {{len=1, type=0x49 /* NLMSG_??? */, flags=NLM_F_REQUEST, seq=0, pid=196615}}], iov_len=4096}], msg_iovlen=1, msg_controllen=0, msg_flags=0}, 0) = 20
  274. sendto(5, {{len=20, type=0x16 /* NLMSG_??? */, flags=NLM_F_REQUEST|0x300, seq=1505345796, pid=0}, "\0\0\0\0"}, 20, 0, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, 12) = 20
  275. recvmsg(5, {msg_name={sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, msg_namelen=12, msg_iov=[{iov_base=[{{len=76, type=0x14 /* NLMSG_??? */, flags=NLM_F_MULTI, seq=1505345796, pid=738}, "\2\10\200\376\1\0\0\0\10\0\1\0\177\0\0\1\10\0\2\0\177\0\0\1\7\0\3\0lo\0\0"...}, {{len=88, type=0x14 /* NLMSG_??? */, flags=NLM_F_MULTI, seq=1505345796, pid=738}, "\2\30\200\0\2\0\0\0\10\0\1\0\300\250\0007\10\0\2\0\300\250\0007\10\0\4\0\300\250\0\377"...}, {{len=88, type=0x14 /* NLMSG_??? */, flags=NLM_F_MULTI, seq=1505345796, pid=738}, "\2\30\200\0\3\0\0\0\10\0\1\0\300\2508x\10\0\2\0\300\2508x\10\0\4\0\300\2508\377"...}, {{len=0, type=0 /* NLMSG_??? */, flags=0, seq=0, pid=0}}], iov_len=4096}], msg_iovlen=1, msg_controllen=0, msg_flags=0}, 0) = 252
  276. recvmsg(5, {msg_name={sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, msg_namelen=12, msg_iov=[{iov_base=[{{len=20, type=NLMSG_DONE, flags=NLM_F_MULTI, seq=1505345796, pid=738}, "\0\0\0\0"}, {{len=1, type=0x8 /* NLMSG_??? */, flags=NLM_F_REQUEST, seq=16777343, pid=131080}}], iov_len=4096}], msg_iovlen=1, msg_controllen=0, msg_flags=0}, 0) = 20
  277. close(5) = 0
  278. stat("/usr/lib/sudo/sudoers.so", {st_mode=S_IFREG|0644, st_size=337696, ...}) = 0
  279. futex(0x7f51e76530a8, FUTEX_WAKE_PRIVATE, 2147483647) = 0
  280. open("/usr/lib/sudo/sudoers.so", O_RDONLY|O_CLOEXEC) = 5
  281. read(5, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\20h\0\0\0\0\0\0"..., 832) = 832
  282. fstat(5, {st_mode=S_IFREG|0644, st_size=337696, ...}) = 0
  283. mmap(NULL, 2435336, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 5, 0) = 0x7f51e5f8a000
  284. mprotect(0x7f51e5fda000, 2093056, PROT_NONE) = 0
  285. mmap(0x7f51e61d9000, 12288, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 5, 0x4f000) = 0x7f51e61d9000
  286. mmap(0x7f51e61dc000, 2312, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f51e61dc000
  287. close(5) = 0
  288. open("/usr/lib/sudo/libpam.so.0", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory)
  289. open("/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 5
  290. fstat(5, {st_mode=S_IFREG|0644, st_size=110784, ...}) = 0
  291. mmap(NULL, 110784, PROT_READ, MAP_PRIVATE, 5, 0) = 0x7f51e80bf000
  292. close(5) = 0
  293. access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
  294. open("/lib/x86_64-linux-gnu/libpam.so.0", O_RDONLY|O_CLOEXEC) = 5
  295. read(5, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\260&\0\0\0\0\0\0"..., 832) = 832
  296. fstat(5, {st_mode=S_IFREG|0644, st_size=56016, ...}) = 0
  297. mmap(NULL, 2151000, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 5, 0) = 0x7f51e5d7c000
  298. mprotect(0x7f51e5d89000, 2093056, PROT_NONE) = 0
  299. mmap(0x7f51e5f88000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 5, 0xc000) = 0x7f51e5f88000
  300. close(5) = 0
  301. mprotect(0x7f51e5f88000, 4096, PROT_READ) = 0
  302. mprotect(0x7f51e61d9000, 4096, PROT_READ) = 0
  303. munmap(0x7f51e80bf000, 110784) = 0
  304. stat("/usr/lib/sudo/sudoers.so", {st_mode=S_IFREG|0644, st_size=337696, ...}) = 0
  305. open("/usr/share/locale/locale.alias", O_RDONLY|O_CLOEXEC) = 5
  306. fstat(5, {st_mode=S_IFREG|0644, st_size=2995, ...}) = 0
  307. read(5, "# Locale name alias data base.\n#"..., 4096) = 2995
  308. read(5, "", 4096) = 0
  309. close(5) = 0
  310. open("/usr/share/locale/en_US/LC_MESSAGES/sudoers.mo", O_RDONLY) = -1 ENOENT (No such file or directory)
  311. open("/usr/share/locale/en/LC_MESSAGES/sudoers.mo", O_RDONLY) = -1 ENOENT (No such file or directory)
  312. open("/etc/passwd", O_RDONLY|O_CLOEXEC) = 5
  313. lseek(5, 0, SEEK_CUR) = 0
  314. fstat(5, {st_mode=S_IFREG|0644, st_size=2415, ...}) = 0
  315. mmap(NULL, 2415, PROT_READ, MAP_SHARED, 5, 0) = 0x7f51e80da000
  316. lseek(5, 2415, SEEK_SET) = 2415
  317. munmap(0x7f51e80da000, 2415) = 0
  318. close(5) = 0
  319. getresuid([0], [0], [0]) = 0
  320. getresgid([0], [0], [0]) = 0
  321. open("/etc/nsswitch.conf", O_RDONLY) = 5
  322. fstat(5, {st_mode=S_IFREG|0644, st_size=540, ...}) = 0
  323. read(5, "# /etc/nsswitch.conf\n#\n# Example"..., 4096) = 540
  324. read(5, "", 4096) = 0
  325. close(5) = 0
  326. setresuid(-1, 1, -1) = 0
  327. stat("/etc/sudoers", {st_mode=S_IFREG|0440, st_size=700, ...}) = 0
  328. open("/etc/sudoers", O_RDONLY) = 5
  329. fstat(5, {st_mode=S_IFREG|0440, st_size=700, ...}) = 0
  330. read(5, "#\n# This file MUST be edited wit"..., 4096) = 700
  331. lseek(5, 0, SEEK_SET) = 0
  332. fcntl(5, F_SETFD, FD_CLOEXEC) = 0
  333. setresuid(-1, 0, -1) = 0
  334. setresuid(-1, 0, -1) = 0
  335. setresgid(-1, -1, -1) = 0
  336. ioctl(5, TCGETS, 0x7ffcc9497860) = -1 ENOTTY (Inappropriate ioctl for device)
  337. read(5, "#\n# This file MUST be edited wit"..., 8192) = 700
  338. read(5, "", 4096) = 0
  339. stat("/etc/sudoers.d", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0
  340. open("/etc/sudoers.d", O_RDONLY|O_NONBLOCK|O_DIRECTORY|O_CLOEXEC) = 6
  341. fstat(6, {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0
  342. getdents(6, /* 3 entries */, 32768) = 80
  343. stat("/etc/sudoers.d/README", {st_mode=S_IFREG|0440, st_size=958, ...}) = 0
  344. getdents(6, /* 0 entries */, 32768) = 0
  345. close(6) = 0
  346. setresuid(-1, 1, -1) = 0
  347. stat("/etc/sudoers.d/README", {st_mode=S_IFREG|0440, st_size=958, ...}) = 0
  348. open("/etc/sudoers.d/README", O_RDONLY) = 6
  349. fstat(6, {st_mode=S_IFREG|0440, st_size=958, ...}) = 0
  350. read(6, "#\n# As of Debian version 1.7.2p1"..., 4096) = 958
  351. lseek(6, 0, SEEK_SET) = 0
  352. fcntl(6, F_SETFD, FD_CLOEXEC) = 0
  353. setresuid(-1, 0, -1) = 0
  354. setresuid(-1, 0, -1) = 0
  355. setresgid(-1, -1, -1) = 0
  356. ioctl(6, TCGETS, 0x7ffcc94976b0) = -1 ENOTTY (Inappropriate ioctl for device)
  357. read(6, "#\n# As of Debian version 1.7.2p1"..., 8192) = 958
  358. read(6, "", 4096) = 0
  359. read(6, "", 8192) = 0
  360. ioctl(6, TCGETS, 0x7ffcc9497860) = -1 ENOTTY (Inappropriate ioctl for device)
  361. close(6) = 0
  362. read(5, "", 8192) = 0
  363. ioctl(5, TCGETS, 0x7ffcc9497860) = -1 ENOTTY (Inappropriate ioctl for device)
  364. socket(AF_UNIX, SOCK_STREAM|SOCK_CLOEXEC|SOCK_NONBLOCK, 0) = 6
  365. connect(6, {sa_family=AF_UNIX, sun_path="/var/run/nscd/socket"}, 110) = -1 ENOENT (No such file or directory)
  366. close(6) = 0
  367. socket(AF_UNIX, SOCK_STREAM|SOCK_CLOEXEC|SOCK_NONBLOCK, 0) = 6
  368. connect(6, {sa_family=AF_UNIX, sun_path="/var/run/nscd/socket"}, 110) = -1 ENOENT (No such file or directory)
  369. close(6) = 0
  370. open("/etc/host.conf", O_RDONLY|O_CLOEXEC) = 6
  371. fstat(6, {st_mode=S_IFREG|0644, st_size=9, ...}) = 0
  372. read(6, "multi on\n", 4096) = 9
  373. read(6, "", 4096) = 0
  374. close(6) = 0
  375. futex(0x7f51e744ea64, FUTEX_WAKE_PRIVATE, 2147483647) = 0
  376. getpid() = 738
  377. open("/etc/resolv.conf", O_RDONLY|O_CLOEXEC) = 6
  378. fstat(6, {st_mode=S_IFREG|0644, st_size=20, ...}) = 0
  379. read(6, "nameserver 10.1.2.9\n", 4096) = 20
  380. read(6, "", 4096) = 0
  381. close(6) = 0
  382. uname({sysname="Linux", nodename="localhost.localdomain", ...}) = 0
  383. open("/etc/hosts", O_RDONLY|O_CLOEXEC) = 6
  384. fstat(6, {st_mode=S_IFREG|0644, st_size=189, ...}) = 0
  385. read(6, "127.0.0.1\tlocalhost\n127.0.1.1\tlo"..., 4096) = 189
  386. read(6, "", 4096) = 0
  387. close(6) = 0
  388. open("/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 6
  389. fstat(6, {st_mode=S_IFREG|0644, st_size=110784, ...}) = 0
  390. mmap(NULL, 110784, PROT_READ, MAP_PRIVATE, 6, 0) = 0x7f51e80bf000
  391. close(6) = 0
  392. access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
  393. open("/lib/x86_64-linux-gnu/libnss_mdns4_minimal.so.2", O_RDONLY|O_CLOEXEC) = 6
  394. read(6, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0p\v\0\0\0\0\0\0"..., 832) = 832
  395. fstat(6, {st_mode=S_IFREG|0644, st_size=10160, ...}) = 0
  396. mmap(NULL, 2105360, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 6, 0) = 0x7f51e5b79000
  397. mprotect(0x7f51e5b7b000, 2093056, PROT_NONE) = 0
  398. mmap(0x7f51e5d7a000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 6, 0x1000) = 0x7f51e5d7a000
  399. close(6) = 0
  400. mprotect(0x7f51e5d7a000, 4096, PROT_READ) = 0
  401. munmap(0x7f51e80bf000, 110784) = 0
  402. open("/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 6
  403. fstat(6, {st_mode=S_IFREG|0644, st_size=110784, ...}) = 0
  404. mmap(NULL, 110784, PROT_READ, MAP_PRIVATE, 6, 0) = 0x7f51e80bf000
  405. close(6) = 0
  406. access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
  407. open("/lib/x86_64-linux-gnu/libnss_dns.so.2", O_RDONLY|O_CLOEXEC) = 6
  408. read(6, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0p\17\0\0\0\0\0\0"..., 832) = 832
  409. fstat(6, {st_mode=S_IFREG|0644, st_size=22928, ...}) = 0
  410. mmap(NULL, 2117848, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 6, 0) = 0x7f51e5973000
  411. mprotect(0x7f51e5978000, 2093056, PROT_NONE) = 0
  412. mmap(0x7f51e5b77000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 6, 0x4000) = 0x7f51e5b77000
  413. close(6) = 0
  414. access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
  415. open("/lib/x86_64-linux-gnu/libresolv.so.2", O_RDONLY|O_CLOEXEC) = 6
  416. read(6, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0p9\0\0\0\0\0\0"..., 832) = 832
  417. fstat(6, {st_mode=S_IFREG|0644, st_size=84848, ...}) = 0
  418. mmap(NULL, 2189896, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 6, 0) = 0x7f51e575c000
  419. mprotect(0x7f51e5770000, 2093056, PROT_NONE) = 0
  420. mmap(0x7f51e596f000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 6, 0x13000) = 0x7f51e596f000
  421. mmap(0x7f51e5971000, 6728, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f51e5971000
  422. close(6) = 0
  423. mprotect(0x7f51e596f000, 4096, PROT_READ) = 0
  424. mprotect(0x7f51e5b77000, 4096, PROT_READ) = 0
  425. munmap(0x7f51e80bf000, 110784) = 0
  426. stat("/etc/resolv.conf", {st_mode=S_IFREG|0644, st_size=20, ...}) = 0
  427. open("/etc/resolv.conf", O_RDONLY|O_CLOEXEC) = 6
  428. fstat(6, {st_mode=S_IFREG|0644, st_size=20, ...}) = 0
  429. read(6, "nameserver 10.1.2.9\n", 4096) = 20
  430. read(6, "", 4096) = 0
  431. close(6) = 0
  432. uname({sysname="Linux", nodename="localhost.localdomain", ...}) = 0
  433. socket(AF_INET, SOCK_DGRAM|SOCK_NONBLOCK, IPPROTO_IP) = 6
  434. connect(6, {sa_family=AF_INET, sin_port=htons(53), sin_addr=inet_addr("10.1.2.9")}, 16) = 0
  435. poll([{fd=6, events=POLLOUT}], 1, 0) = 1 ([{fd=6, revents=POLLOUT}])
  436. sendmmsg(6, [{msg_hdr={msg_name=NULL, msg_namelen=0, msg_iov=[{iov_base="\372\251\1\0\0\1\0\0\0\0\0\0\tlocalhost\vlocaldoma"..., iov_len=39}], msg_iovlen=1, msg_controllen=0, msg_flags=MSG_OOB|MSG_PEEK}, msg_len=39}, {msg_hdr={msg_name=NULL, msg_namelen=0, msg_iov=[{iov_base="\25\201\1\0\0\1\0\0\0\0\0\0\tlocalhost\vlocaldoma"..., iov_len=39}], msg_iovlen=1, msg_controllen=0, msg_flags=MSG_PEEK}, msg_len=39}], 2, MSG_NOSIGNAL) = 2
  437. poll([{fd=6, events=POLLIN}], 1, 5000) = 0 (Timeout)
  438. poll([{fd=6, events=POLLOUT}], 1, 0) = 1 ([{fd=6, revents=POLLOUT}])
  439. sendmmsg(6, [{msg_hdr={msg_name=NULL, msg_namelen=0, msg_iov=[{iov_base="\372\251\1\0\0\1\0\0\0\0\0\0\tlocalhost\vlocaldoma"..., iov_len=39}], msg_iovlen=1, msg_controllen=0, msg_flags=MSG_OOB|MSG_PEEK}, msg_len=39}, {msg_hdr={msg_name=NULL, msg_namelen=0, msg_iov=[{iov_base="\25\201\1\0\0\1\0\0\0\0\0\0\tlocalhost\vlocaldoma"..., iov_len=39}], msg_iovlen=1, msg_controllen=0, msg_flags=MSG_PEEK}, msg_len=39}], 2, MSG_NOSIGNAL) = 2
  440. poll([{fd=6, events=POLLIN}], 1, 5000) = 0 (Timeout)
  441. close(6) = 0
  442. socket(AF_INET, SOCK_DGRAM|SOCK_NONBLOCK, IPPROTO_IP) = 6
  443. connect(6, {sa_family=AF_INET, sin_port=htons(53), sin_addr=inet_addr("10.1.2.9")}, 16) = 0
  444. poll([{fd=6, events=POLLOUT}], 1, 0) = 1 ([{fd=6, revents=POLLOUT}])
  445. sendmmsg(6, [{msg_hdr={msg_name=NULL, msg_namelen=0, msg_iov=[{iov_base="\313\265\1\0\0\1\0\0\0\0\0\0\tlocalhost\vlocaldoma"..., iov_len=51}], msg_iovlen=1, msg_controllen=0, msg_flags=MSG_OOB|MSG_PEEK}, msg_len=51}, {msg_hdr={msg_name=NULL, msg_namelen=0, msg_iov=[{iov_base="\1\371\1\0\0\1\0\0\0\0\0\0\tlocalhost\vlocaldoma"..., iov_len=51}], msg_iovlen=1, msg_controllen=0, msg_flags=MSG_PEEK}, msg_len=51}], 2, MSG_NOSIGNAL) = 2
  446. poll([{fd=6, events=POLLIN}], 1, 5000
  447.  
  448.  
  449.  
  450.  
  451.  
  452.  
  453.  
  454.  
  455.  
  456.  
  457.  
  458.  
  459.  
  460.  
  461.  
  462.  
  463.  
  464. ) = 0 (Timeout)
  465. poll([{fd=6, events=POLLOUT}], 1, 0) = 1 ([{fd=6, revents=POLLOUT}])
  466. sendmmsg(6, [{msg_hdr={msg_name=NULL, msg_namelen=0, msg_iov=[{iov_base="\313\265\1\0\0\1\0\0\0\0\0\0\tlocalhost\vlocaldoma"..., iov_len=51}], msg_iovlen=1, msg_controllen=0, msg_flags=MSG_OOB|MSG_PEEK}, msg_len=51}, {msg_hdr={msg_name=NULL, msg_namelen=0, msg_iov=[{iov_base="\1\371\1\0\0\1\0\0\0\0\0\0\tlocalhost\vlocaldoma"..., iov_len=51}], msg_iovlen=1, msg_controllen=0, msg_flags=MSG_PEEK}, msg_len=51}], 2, MSG_NOSIGNAL) = 2
  467. poll([{fd=6, events=POLLIN}], 1, 5000
  468.  
  469.  
  470.  
  471.  
  472.  
  473.  
  474.  
  475.  
  476.  
  477.  
  478.  
  479. ) = 0 (Timeout)
  480. close(6) = 0
  481. open("/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 6
  482. fstat(6, {st_mode=S_IFREG|0644, st_size=110784, ...}) = 0
  483. mmap(NULL, 110784, PROT_READ, MAP_PRIVATE, 6, 0) = 0x7f51e80bf000
  484. close(6) = 0
  485. access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
  486. open("/lib/x86_64-linux-gnu/libnss_myhostname.so.2", O_RDONLY|O_CLOEXEC) = 6
  487. read(6, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832
  488. fstat(6, {st_mode=S_IFREG|0644, st_size=76216, ...}) = 0
  489. mmap(NULL, 80080, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 6, 0) = 0x7f51e7f0c000
  490. mmap(0x7f51e7f1d000, 12288, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 6, 0x10000) = 0x7f51e7f1d000
  491. close(6) = 0
  492. access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
  493. open("/lib/x86_64-linux-gnu/librt.so.1", O_RDONLY|O_CLOEXEC) = 6
  494. read(6, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\340 \0\0\0\0\0\0"..., 832) = 832
  495. fstat(6, {st_mode=S_IFREG|0644, st_size=31744, ...}) = 0
  496. mmap(NULL, 2128832, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 6, 0) = 0x7f51e5554000
  497. mprotect(0x7f51e555b000, 2093056, PROT_NONE) = 0
  498. mmap(0x7f51e575a000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 6, 0x6000) = 0x7f51e575a000
  499. close(6) = 0
  500. mprotect(0x7f51e575a000, 4096, PROT_READ) = 0
  501. mprotect(0x7f51e7f1d000, 8192, PROT_READ) = 0
  502. munmap(0x7f51e80bf000, 110784) = 0
  503. rt_sigprocmask(SIG_BLOCK, [HUP USR1 USR2 PIPE ALRM CHLD TSTP URG VTALRM PROF WINCH IO], [], 8) = 0
  504. rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
  505. open("/etc/gai.conf", O_RDONLY|O_CLOEXEC) = 6
  506. fstat(6, {st_mode=S_IFREG|0644, st_size=2584, ...}) = 0
  507. fstat(6, {st_mode=S_IFREG|0644, st_size=2584, ...}) = 0
  508. read(6, "# Configuration for getaddrinfo("..., 4096) = 2584
  509. read(6, "", 4096) = 0
  510. close(6) = 0
  511. futex(0x7f51e744cee4, FUTEX_WAKE_PRIVATE, 2147483647) = 0
  512. socket(AF_NETLINK, SOCK_RAW, NETLINK_ROUTE) = 6
  513. bind(6, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, 12) = 0
  514. getsockname(6, {sa_family=AF_NETLINK, nl_pid=738, nl_groups=00000000}, [12]) = 0
  515. sendto(6, {{len=20, type=0x16 /* NLMSG_??? */, flags=NLM_F_REQUEST|0x300, seq=1505345821, pid=0}, "\0\0\0\0"}, 20, 0, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, 12) = 20
  516. recvmsg(6, {msg_name={sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, msg_namelen=12, msg_iov=[{iov_base=[{{len=76, type=0x14 /* NLMSG_??? */, flags=NLM_F_MULTI, seq=1505345821, pid=738}, "\2\10\200\376\1\0\0\0\10\0\1\0\177\0\0\1\10\0\2\0\177\0\0\1\7\0\3\0lo\0\0"...}, {{len=88, type=0x14 /* NLMSG_??? */, flags=NLM_F_MULTI, seq=1505345821, pid=738}, "\2\30\200\0\2\0\0\0\10\0\1\0\300\250\0007\10\0\2\0\300\250\0007\10\0\4\0\300\250\0\377"...}, {{len=88, type=0x14 /* NLMSG_??? */, flags=NLM_F_MULTI, seq=1505345821, pid=738}, "\2\30\200\0\3\0\0\0\10\0\1\0\300\2508x\10\0\2\0\300\2508x\10\0\4\0\300\2508\377"...}, {{len=32593, type=0x6228 /* NLMSG_??? */, flags=NLM_F_REQUEST|NLM_F_ECHO|0xc940, seq=32764, pid=110}, "\0\0\0\0\10\324\r\350Q\177\0\0\n\0\0\0\0\0\0\0\260Ze\347Q\177\0\0\220gI\311"...}], iov_len=4096}], msg_iovlen=1, msg_controllen=0, msg_flags=0}, 0) = 252
  517. recvmsg(6, {msg_name={sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, msg_namelen=12, msg_iov=[{iov_base=[{{len=20, type=NLMSG_DONE, flags=NLM_F_MULTI, seq=1505345821, pid=738}, "\0\0\0\0"}, {{len=1, type=0x8 /* NLMSG_??? */, flags=NLM_F_REQUEST, seq=16777343, pid=131080}}], iov_len=4096}], msg_iovlen=1, msg_controllen=0, msg_flags=0}, 0) = 20
  518. close(6) = 0
  519. socket(AF_INET, SOCK_DGRAM, IPPROTO_IP) = 6
  520. connect(6, {sa_family=AF_INET, sin_port=htons(0), sin_addr=inet_addr("127.0.0.1")}, 16) = 0
  521. getsockname(6, {sa_family=AF_INET, sin_port=htons(38843), sin_addr=inet_addr("127.0.0.1")}, [28->16]) = 0
  522. close(6) = 0
  523. socket(AF_INET6, SOCK_DGRAM, IPPROTO_IP) = 6
  524. connect(6, {sa_family=AF_INET6, sin6_port=htons(0), inet_pton(AF_INET6, "::1", &sin6_addr), sin6_flowinfo=htonl(0), sin6_scope_id=1}, 28) = -1 EADDRNOTAVAIL (Cannot assign requested address)
  525. close(6) = 0
  526. setresuid(-1, -1, -1) = 0
  527. setresgid(-1, -1, -1) = 0
  528. getrlimit(RLIMIT_NPROC, {rlim_cur=7930, rlim_max=7930}) = 0
  529. setrlimit(RLIMIT_NPROC, {rlim_cur=RLIM64_INFINITY, rlim_max=RLIM64_INFINITY}) = 0
  530. getresuid([0], [0], [0]) = 0
  531. getresgid([0], [0], [0]) = 0
  532. setgroups(1, [0]) = 0
  533. stat("/usr/local/sbin/su", 0x55a011d60160) = -1 ENOENT (No such file or directory)
  534. stat("/usr/local/bin/su", 0x55a011d60160) = -1 ENOENT (No such file or directory)
  535. stat("/usr/sbin/su", 0x55a011d60160) = -1 ENOENT (No such file or directory)
  536. stat("/usr/bin/su", 0x55a011d60160) = -1 ENOENT (No such file or directory)
  537. stat("/sbin/su", 0x55a011d60160) = -1 ENOENT (No such file or directory)
  538. stat("/bin/su", {st_mode=S_IFREG|S_ISUID|0755, st_size=40536, ...}) = 0
  539. setresuid(-1, -1, -1) = 0
  540. setresgid(-1, -1, -1) = 0
  541. setgroups(1, [0]) = 0
  542. socket(AF_UNIX, SOCK_STREAM|SOCK_CLOEXEC|SOCK_NONBLOCK, 0) = 6
  543. connect(6, {sa_family=AF_UNIX, sun_path="/var/run/nscd/socket"}, 110) = -1 ENOENT (No such file or directory)
  544. close(6) = 0
  545. socket(AF_UNIX, SOCK_STREAM|SOCK_CLOEXEC|SOCK_NONBLOCK, 0) = 6
  546. connect(6, {sa_family=AF_UNIX, sun_path="/var/run/nscd/socket"}, 110) = -1 ENOENT (No such file or directory)
  547. close(6) = 0
  548. open("/etc/group", O_RDONLY|O_CLOEXEC) = 6
  549. lseek(6, 0, SEEK_CUR) = 0
  550. fstat(6, {st_mode=S_IFREG|0644, st_size=1008, ...}) = 0
  551. mmap(NULL, 1008, PROT_READ, MAP_SHARED, 6, 0) = 0x7f51e80da000
  552. lseek(6, 1008, SEEK_SET) = 1008
  553. munmap(0x7f51e80da000, 1008) = 0
  554. close(6) = 0
  555. setresuid(-1, -1, -1) = 0
  556. setresgid(-1, -1, -1) = 0
  557. stat("/etc/pam.d", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0
  558. open("/etc/pam.d/sudo", O_RDONLY) = 6
  559. fstat(6, {st_mode=S_IFREG|0644, st_size=95, ...}) = 0
  560. read(6, "#%PAM-1.0\n\n@include common-auth\n"..., 4096) = 95
  561. stat("/etc/pam.d", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0
  562. open("/etc/pam.d/common-auth", O_RDONLY) = 7
  563. fstat(7, {st_mode=S_IFREG|0644, st_size=1249, ...}) = 0
  564. read(7, "#\n# /etc/pam.d/common-auth - aut"..., 4096) = 1249
  565. open("/lib/x86_64-linux-gnu/security/pam_unix.so", O_RDONLY|O_CLOEXEC) = 8
  566. read(8, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0000)\0\0\0\0\0\0"..., 832) = 832
  567. fstat(8, {st_mode=S_IFREG|0644, st_size=60336, ...}) = 0
  568. mmap(NULL, 2204640, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 8, 0) = 0x7f51e5339000
  569. mprotect(0x7f51e5346000, 2097152, PROT_NONE) = 0
  570. mmap(0x7f51e5546000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 8, 0xd000) = 0x7f51e5546000
  571. mmap(0x7f51e5548000, 46048, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f51e5548000
  572. close(8) = 0
  573. open("/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 8
  574. fstat(8, {st_mode=S_IFREG|0644, st_size=110784, ...}) = 0
  575. mmap(NULL, 110784, PROT_READ, MAP_PRIVATE, 8, 0) = 0x7f51e80bf000
  576. close(8) = 0
  577. access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
  578. open("/lib/x86_64-linux-gnu/libcrypt.so.1", O_RDONLY|O_CLOEXEC) = 8
  579. read(8, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0p\v\0\0\0\0\0\0"..., 832) = 832
  580. fstat(8, {st_mode=S_IFREG|0644, st_size=39256, ...}) = 0
  581. mmap(NULL, 2322912, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 8, 0) = 0x7f51e5101000
  582. mprotect(0x7f51e5109000, 2097152, PROT_NONE) = 0
  583. mmap(0x7f51e5309000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 8, 0x8000) = 0x7f51e5309000
  584. mmap(0x7f51e530b000, 184800, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f51e530b000
  585. close(8) = 0
  586. mprotect(0x7f51e5309000, 4096, PROT_READ) = 0
  587. mprotect(0x7f51e5546000, 4096, PROT_READ) = 0
  588. munmap(0x7f51e80bf000, 110784) = 0
  589. open("/lib/x86_64-linux-gnu/security/pam_deny.so", O_RDONLY|O_CLOEXEC) = 8
  590. read(8, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\240\5\0\0\0\0\0\0"..., 832) = 832
  591. fstat(8, {st_mode=S_IFREG|0644, st_size=6000, ...}) = 0
  592. mmap(NULL, 2101288, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 8, 0) = 0x7f51e4eff000
  593. mprotect(0x7f51e4f00000, 2093056, PROT_NONE) = 0
  594. mmap(0x7f51e50ff000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 8, 0) = 0x7f51e50ff000
  595. close(8) = 0
  596. mprotect(0x7f51e50ff000, 4096, PROT_READ) = 0
  597. open("/lib/x86_64-linux-gnu/security/pam_permit.so", O_RDONLY|O_CLOEXEC) = 8
  598. read(8, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\320\6\0\0\0\0\0\0"..., 832) = 832
  599. fstat(8, {st_mode=S_IFREG|0644, st_size=6168, ...}) = 0
  600. mmap(NULL, 2101312, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 8, 0) = 0x7f51e4cfd000
  601. mprotect(0x7f51e4cfe000, 2093056, PROT_NONE) = 0
  602. mmap(0x7f51e4efd000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 8, 0) = 0x7f51e4efd000
  603. close(8) = 0
  604. mprotect(0x7f51e4efd000, 4096, PROT_READ) = 0
  605. open("/lib/x86_64-linux-gnu/security/pam_cap.so", O_RDONLY|O_CLOEXEC) = 8
  606. read(8, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0@\f\0\0\0\0\0\0"..., 832) = 832
  607. fstat(8, {st_mode=S_IFREG|0644, st_size=10080, ...}) = 0
  608. mmap(NULL, 2105360, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 8, 0) = 0x7f51e4afa000
  609. mprotect(0x7f51e4afc000, 2093056, PROT_NONE) = 0
  610. mmap(0x7f51e4cfb000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 8, 0x1000) = 0x7f51e4cfb000
  611. close(8) = 0
  612. open("/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 8
  613. fstat(8, {st_mode=S_IFREG|0644, st_size=110784, ...}) = 0
  614. mmap(NULL, 110784, PROT_READ, MAP_PRIVATE, 8, 0) = 0x7f51e80bf000
  615. close(8) = 0
  616. access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
  617. open("/lib/x86_64-linux-gnu/libcap.so.2", O_RDONLY|O_CLOEXEC) = 8
  618. read(8, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\300\30\0\0\0\0\0\0"..., 832) = 832
  619. fstat(8, {st_mode=S_IFREG|0644, st_size=22768, ...}) = 0
  620. mmap(NULL, 2117976, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 8, 0) = 0x7f51e48f4000
  621. mprotect(0x7f51e48f8000, 2097152, PROT_NONE) = 0
  622. mmap(0x7f51e4af8000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 8, 0x4000) = 0x7f51e4af8000
  623. close(8) = 0
  624. mprotect(0x7f51e4af8000, 4096, PROT_READ) = 0
  625. mprotect(0x7f51e4cfb000, 4096, PROT_READ) = 0
  626. munmap(0x7f51e80bf000, 110784) = 0
  627. read(7, "", 4096) = 0
  628. close(7) = 0
  629. stat("/etc/pam.d", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0
  630. open("/etc/pam.d/common-account", O_RDONLY) = 7
  631. fstat(7, {st_mode=S_IFREG|0644, st_size=1208, ...}) = 0
  632. read(7, "#\n# /etc/pam.d/common-account - "..., 4096) = 1208
  633. read(7, "", 4096) = 0
  634. close(7) = 0
  635. stat("/etc/pam.d", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0
  636. open("/etc/pam.d/common-session-noninteractive", O_RDONLY) = 7
  637. fstat(7, {st_mode=S_IFREG|0644, st_size=1154, ...}) = 0
  638. read(7, "#\n# /etc/pam.d/common-session-no"..., 4096) = 1154
  639. read(7, "", 4096) = 0
  640. close(7) = 0
  641. read(6, "", 4096) = 0
  642. close(6) = 0
  643. open("/etc/pam.d/other", O_RDONLY) = 6
  644. fstat(6, {st_mode=S_IFREG|0644, st_size=520, ...}) = 0
  645. read(6, "#\n# /etc/pam.d/other - specify t"..., 4096) = 520
  646. stat("/etc/pam.d", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0
  647. open("/etc/pam.d/common-auth", O_RDONLY) = 7
  648. fstat(7, {st_mode=S_IFREG|0644, st_size=1249, ...}) = 0
  649. read(7, "#\n# /etc/pam.d/common-auth - aut"..., 4096) = 1249
  650. read(7, "", 4096) = 0
  651. close(7) = 0
  652. stat("/etc/pam.d", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0
  653. open("/etc/pam.d/common-account", O_RDONLY) = 7
  654. fstat(7, {st_mode=S_IFREG|0644, st_size=1208, ...}) = 0
  655. read(7, "#\n# /etc/pam.d/common-account - "..., 4096) = 1208
  656. read(7, "", 4096) = 0
  657. close(7) = 0
  658. stat("/etc/pam.d", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0
  659. open("/etc/pam.d/common-password", O_RDONLY) = 7
  660. fstat(7, {st_mode=S_IFREG|0644, st_size=1480, ...}) = 0
  661. read(7, "#\n# /etc/pam.d/common-password -"..., 4096) = 1480
  662. open("/lib/x86_64-linux-gnu/security/pam_gnome_keyring.so", O_RDONLY|O_CLOEXEC) = 8
  663. read(8, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0p\32\0\0\0\0\0\0"..., 832) = 832
  664. fstat(8, {st_mode=S_IFREG|0644, st_size=42920, ...}) = 0
  665. mmap(NULL, 2138208, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 8, 0) = 0x7f51e46e9000
  666. mprotect(0x7f51e46f3000, 2093056, PROT_NONE) = 0
  667. mmap(0x7f51e48f2000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 8, 0x9000) = 0x7f51e48f2000
  668. close(8) = 0
  669. mprotect(0x7f51e48f2000, 4096, PROT_READ) = 0
  670. read(7, "", 4096) = 0
  671. close(7) = 0
  672. stat("/etc/pam.d", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0
  673. open("/etc/pam.d/common-session", O_RDONLY) = 7
  674. fstat(7, {st_mode=S_IFREG|0644, st_size=1189, ...}) = 0
  675. read(7, "#\n# /etc/pam.d/common-session - "..., 4096) = 1189
  676. open("/lib/x86_64-linux-gnu/security/pam_systemd.so", O_RDONLY|O_CLOEXEC) = 8
  677. read(8, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832
  678. fstat(8, {st_mode=S_IFREG|0644, st_size=279032, ...}) = 0
  679. mmap(NULL, 282752, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 8, 0) = 0x7f51e46a3000
  680. mmap(0x7f51e46e4000, 16384, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 8, 0x40000) = 0x7f51e46e4000
  681. mmap(0x7f51e46e8000, 128, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f51e46e8000
  682. close(8) = 0
  683. open("/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 8
  684. fstat(8, {st_mode=S_IFREG|0644, st_size=110784, ...}) = 0
  685. mmap(NULL, 110784, PROT_READ, MAP_PRIVATE, 8, 0) = 0x7f51e80bf000
  686. close(8) = 0
  687. access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
  688. open("/lib/x86_64-linux-gnu/libpam_misc.so.0", O_RDONLY|O_CLOEXEC) = 8
  689. read(8, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\200\20\0\0\0\0\0\0"..., 832) = 832
  690. fstat(8, {st_mode=S_IFREG|0644, st_size=14640, ...}) = 0
  691. mmap(NULL, 2109744, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 8, 0) = 0x7f51e449f000
  692. mprotect(0x7f51e44a2000, 2093056, PROT_NONE) = 0
  693. mmap(0x7f51e46a1000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 8, 0x2000) = 0x7f51e46a1000
  694. close(8) = 0
  695. mprotect(0x7f51e46a1000, 4096, PROT_READ) = 0
  696. mprotect(0x7f51e46e4000, 12288, PROT_READ) = 0
  697. munmap(0x7f51e80bf000, 110784) = 0
  698. read(7, "", 4096) = 0
  699. close(7) = 0
  700. read(6, "", 4096) = 0
  701. close(6) = 0
  702. socket(AF_UNIX, SOCK_DGRAM|SOCK_CLOEXEC, 0) = 6
  703. connect(6, {sa_family=AF_UNIX, sun_path="/dev/log"}, 110) = 0
  704. sendto(6, "<85>Sep 13 20:37:01 sudo: ro"..., 90, MSG_NOSIGNAL, NULL, 0) = 90
  705. close(6) = 0
  706. setresuid(-1, -1, -1) = 0
  707. setresgid(-1, -1, -1) = 0
  708. close(5) = 0
  709. socket(AF_NETLINK, SOCK_RAW, NETLINK_AUDIT) = 5
  710. fcntl(5, F_SETFD, FD_CLOEXEC) = 0
  711. fcntl(5, F_SETFD, FD_CLOEXEC) = 0
  712. ioctl(0, TCGETS, {B38400 opost isig icanon echo ...}) = 0
  713. fstat(0, {st_mode=S_IFCHR|0620, st_rdev=makedev(136, 0), ...}) = 0
  714. readlink("/proc/self/fd/0", "/dev/pts/0", 31) = 10
  715. stat("/dev/pts/0", {st_mode=S_IFCHR|0620, st_rdev=makedev(136, 0), ...}) = 0
  716. lstat("/dev/pts/0", {st_mode=S_IFCHR|0620, st_rdev=makedev(136, 0), ...}) = 0
  717. getcwd("/root", 4096) = 6
  718. sendto(5, {{len=68, type=0x463 /* NLMSG_??? */, flags=NLM_F_REQUEST|NLM_F_ACK, seq=1, pid=0}, "cwd=\"/root\" cmd=7375202D termina"...}, 68, 0, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, 12) = 68
  719. poll([{fd=5, events=POLLIN}], 1, 500) = 1 ([{fd=5, revents=POLLIN}])
  720. recvfrom(5, {{len=36, type=NLMSG_ERROR, flags=0, seq=1, pid=738}, "\0\0\0\0D\0\0\0c\4\5\0\1\0\0\0\0\0\0\0"}, 8988, MSG_PEEK|MSG_DONTWAIT, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, [12]) = 36
  721. recvfrom(5, {{len=36, type=NLMSG_ERROR, flags=0, seq=1, pid=738}, "\0\0\0\0D\0\0\0c\4\5\0\1\0\0\0\0\0\0\0"}, 8988, MSG_DONTWAIT, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, [12]) = 36
  722. setresuid(-1, -1, -1) = 0
  723. setresgid(-1, -1, -1) = 0
  724. setrlimit(RLIMIT_NPROC, {rlim_cur=7930, rlim_max=7930}) = 0
  725. open("/etc/passwd", O_RDONLY|O_CLOEXEC) = 6
  726. lseek(6, 0, SEEK_CUR) = 0
  727. fstat(6, {st_mode=S_IFREG|0644, st_size=2415, ...}) = 0
  728. mmap(NULL, 2415, PROT_READ, MAP_SHARED, 6, 0) = 0x7f51e80da000
  729. lseek(6, 2415, SEEK_SET) = 2415
  730. munmap(0x7f51e80da000, 2415) = 0
  731. close(6) = 0
  732. open("/etc/passwd", O_RDONLY|O_CLOEXEC) = 6
  733. lseek(6, 0, SEEK_CUR) = 0
  734. fstat(6, {st_mode=S_IFREG|0644, st_size=2415, ...}) = 0
  735. mmap(NULL, 2415, PROT_READ, MAP_SHARED, 6, 0) = 0x7f51e80da000
  736. lseek(6, 2415, SEEK_SET) = 2415
  737. munmap(0x7f51e80da000, 2415) = 0
  738. close(6) = 0
  739. setuid(0) = 0
  740. setrlimit(RLIMIT_CORE, {rlim_cur=0, rlim_max=RLIM64_INFINITY}) = 0
  741. read(3, 0x7ffcc9497960, 1) = -1 EAGAIN (Resource temporarily unavailable)
  742. socketpair(AF_UNIX, SOCK_STREAM, 0, [6, 7]) = 0
  743. rt_sigaction(SIGTERM, {sa_handler=0x55a0114a7200, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_INTERRUPT|SA_SIGINFO, sa_restorer=0x7f51e70e4030}, NULL, 8) = 0
  744. rt_sigaction(SIGHUP, {sa_handler=0x55a0114a7200, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_INTERRUPT|SA_SIGINFO, sa_restorer=0x7f51e70e4030}, NULL, 8) = 0
  745. rt_sigaction(SIGALRM, {sa_handler=0x55a0114a7200, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_INTERRUPT|SA_SIGINFO, sa_restorer=0x7f51e70e4030}, NULL, 8) = 0
  746. rt_sigaction(SIGPIPE, {sa_handler=0x55a0114a7200, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_INTERRUPT|SA_SIGINFO, sa_restorer=0x7f51e70e4030}, NULL, 8) = 0
  747. rt_sigaction(SIGUSR1, {sa_handler=0x55a0114a7200, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_INTERRUPT|SA_SIGINFO, sa_restorer=0x7f51e70e4030}, NULL, 8) = 0
  748. rt_sigaction(SIGUSR2, {sa_handler=0x55a0114a7200, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_INTERRUPT|SA_SIGINFO, sa_restorer=0x7f51e70e4030}, NULL, 8) = 0
  749. rt_sigaction(SIGINT, {sa_handler=0x55a0114a7140, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_INTERRUPT|SA_SIGINFO, sa_restorer=0x7f51e70e4030}, NULL, 8) = 0
  750. rt_sigaction(SIGQUIT, {sa_handler=0x55a0114a7140, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_INTERRUPT|SA_SIGINFO, sa_restorer=0x7f51e70e4030}, NULL, 8) = 0
  751. setgroups(1, [0]) = 0
  752. setgid(0) = 0
  753. socket(AF_NETLINK, SOCK_RAW, NETLINK_AUDIT) = 8
  754. fcntl(8, F_SETFD, FD_CLOEXEC) = 0
  755. readlink("/proc/self/exe", "/usr/bin/sudo", 4096) = 13
  756. sendto(8, {{len=116, type=0x456 /* NLMSG_??? */, flags=NLM_F_REQUEST|NLM_F_ACK, seq=2, pid=0}, "op=PAM:setcred acct=\"root\" exe=\""...}, 116, 0, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, 12) = 116
  757. poll([{fd=8, events=POLLIN}], 1, 500) = 1 ([{fd=8, revents=POLLIN}])
  758. recvfrom(8, {{len=36, type=NLMSG_ERROR, flags=0, seq=2, pid=2553868359}, "\0\0\0\0t\0\0\0V\4\5\0\2\0\0\0\0\0\0\0"}, 8988, MSG_PEEK|MSG_DONTWAIT, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, [12]) = 36
  759. recvfrom(8, {{len=36, type=NLMSG_ERROR, flags=0, seq=2, pid=2553868359}, "\0\0\0\0t\0\0\0V\4\5\0\2\0\0\0\0\0\0\0"}, 8988, MSG_DONTWAIT, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, [12]) = 36
  760. close(8) = 0
  761. getuid() = 0
  762. open("/etc/login.defs", O_RDONLY) = 8
  763. fstat(8, {st_mode=S_IFREG|0644, st_size=10477, ...}) = 0
  764. read(8, "#\n# /etc/login.defs - Configurat"..., 4096) = 4096
  765. read(8, " issuing \n# the \"mesg y\" command"..., 4096) = 4096
  766. read(8, "t supports passwords of unlimite"..., 4096) = 2285
  767. close(8) = 0
  768. access("/var/run/utmpx", F_OK) = -1 ENOENT (No such file or directory)
  769. open("/var/run/utmp", O_RDONLY|O_CLOEXEC) = 8
  770. lseek(8, 0, SEEK_SET) = 0
  771. alarm(0) = 0
  772. rt_sigaction(SIGALRM, {sa_handler=0x7f51e71cdf20, sa_mask=[], sa_flags=SA_RESTORER, sa_restorer=0x7f51e70e4030}, {sa_handler=0x55a0114a7200, sa_mask=~[KILL STOP RTMIN RT_1], sa_flags=SA_RESTORER|SA_INTERRUPT|SA_SIGINFO, sa_restorer=0x7f51e70e4030}, 8) = 0
  773. alarm(10) = 0
  774. fcntl(8, F_SETLKW, {l_type=F_RDLCK, l_whence=SEEK_SET, l_start=0, l_len=0}) = 0
  775. read(8, "\2\0\0\0\0\0\0\0~\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., 384) = 384
  776. read(8, "\1\0\0\0005\0\0\0~\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., 384) = 384
  777. read(8, "\7\0\0\0\303\2\0\0tty2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., 384) = 384
  778. read(8, "", 384) = 0
  779. fcntl(8, F_SETLKW, {l_type=F_UNLCK, l_whence=SEEK_SET, l_start=0, l_len=0}) = 0
  780. alarm(0) = 10
  781. rt_sigaction(SIGALRM, {sa_handler=0x55a0114a7200, sa_mask=~[KILL STOP RTMIN RT_1], sa_flags=SA_RESTORER|SA_INTERRUPT|SA_SIGINFO, sa_restorer=0x7f51e70e4030}, NULL, 8) = 0
  782. close(8) = 0
  783. getuid() = 0
  784. socket(AF_UNIX, SOCK_DGRAM|SOCK_CLOEXEC, 0) = 8
  785. connect(8, {sa_family=AF_UNIX, sun_path="/dev/log"}, 110) = 0
  786. sendto(8, "<86>Sep 13 20:37:01 sudo: pam_un"..., 89, MSG_NOSIGNAL, NULL, 0) = 89
  787. socket(AF_NETLINK, SOCK_RAW, NETLINK_AUDIT) = 9
  788. fcntl(9, F_SETFD, FD_CLOEXEC) = 0
  789. sendto(9, {{len=120, type=0x451 /* NLMSG_??? */, flags=NLM_F_REQUEST|NLM_F_ACK, seq=3, pid=0}, "op=PAM:session_open acct=\"root\" "...}, 120, 0, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, 12) = 120
  790. poll([{fd=9, events=POLLIN}], 1, 500) = 1 ([{fd=9, revents=POLLIN}])
  791. recvfrom(9, {{len=36, type=NLMSG_ERROR, flags=0, seq=3, pid=2208231576}, "\0\0\0\0x\0\0\0Q\4\5\0\3\0\0\0\0\0\0\0"}, 8988, MSG_PEEK|MSG_DONTWAIT, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, [12]) = 36
  792. recvfrom(9, {{len=36, type=NLMSG_ERROR, flags=0, seq=3, pid=2208231576}, "\0\0\0\0x\0\0\0Q\4\5\0\3\0\0\0\0\0\0\0"}, 8988, MSG_DONTWAIT, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, [12]) = 36
  793. close(9) = 0
  794. getpgrp() = 736
  795. rt_sigaction(SIGCHLD, {sa_handler=0x55a0114a7200, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_INTERRUPT|SA_SIGINFO, sa_restorer=0x7f51e70e4030}, NULL, 8) = 0
  796. rt_sigaction(SIGCONT, {sa_handler=0x55a0114a7200, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_INTERRUPT|SA_SIGINFO, sa_restorer=0x7f51e70e4030}, NULL, 8) = 0
  797. rt_sigaction(SIGTSTP, {sa_handler=0x55a0114a7140, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_INTERRUPT|SA_SIGINFO, sa_restorer=0x7f51e70e4030}, NULL, 8) = 0
  798. clone(child_stack=NULL, flags=CLONE_CHILD_CLEARTID|CLONE_CHILD_SETTID|SIGCHLD, child_tidptr=0x7f51e80bc190) = 739
  799. close(7) = 0
  800. poll([{fd=3, events=POLLIN}, {fd=6, events=POLLIN}], 2, -1) = 1 ([{fd=6, revents=POLLIN|POLLHUP}])
  801. recvfrom(6, "", 8, MSG_WAITALL, NULL, NULL) = 0
  802. poll([{fd=3, events=POLLIN}], 1, -1root@localhost:~#
  803. root@localhost:~#
  804. root@localhost:~#
  805. root@localhost:~#
  806. root@localhost:~#
  807. root@localhost:~#
  808. root@localhost:~#
  809. root@localhost:~#
  810. root@localhost:~#
  811. root@localhost:~#
  812. root@localhost:~#
  813. root@localhost:~#
  814. root@localhost:~#
  815. root@localhost:~#
  816. root@localhost:~#
  817. root@localhost:~#
  818. root@localhost:~#
  819. root@localhost:~#
  820. root@localhost:~#
  821. root@localhost:~#
  822. root@localhost:~#
  823. root@localhost:~#
  824. root@localhost:~#
  825. root@localhost:~#
  826. root@localhost:~#
  827. root@localhost:~#
  828. root@localhost:~#
  829. root@localhost:~#
  830. root@localhost:~#
  831. root@localhost:~#
  832. root@localhost:~# logout
  833. ) = ? ERESTART_RESTARTBLOCK (Interrupted by signal)
  834. --- SIGCHLD {si_signo=SIGCHLD, si_code=CLD_EXITED, si_pid=739, si_uid=0, si_status=0, si_utime=0, si_stime=0} ---
  835. write(4, "\21", 1) = 1
  836. rt_sigreturn({mask=[]}) = -1 EINTR (Interrupted system call)
  837. poll([{fd=3, events=POLLIN}], 1, -1) = 1 ([{fd=3, revents=POLLIN}])
  838. read(3, "\21", 1) = 1
  839. wait4(739, [{WIFEXITED(s) && WEXITSTATUS(s) == 0}], WNOHANG|WSTOPPED, NULL) = 739
  840. getuid() = 0
  841. open("/etc/login.defs", O_RDONLY) = 7
  842. fstat(7, {st_mode=S_IFREG|0644, st_size=10477, ...}) = 0
  843. read(7, "#\n# /etc/login.defs - Configurat"..., 4096) = 4096
  844. read(7, " issuing \n# the \"mesg y\" command"..., 4096) = 4096
  845. read(7, "t supports passwords of unlimite"..., 4096) = 2285
  846. close(7) = 0
  847. sendto(8, "<86>Sep 13 20:37:16 sudo: pam_un"..., 78, MSG_NOSIGNAL, NULL, 0) = 78
  848. socket(AF_NETLINK, SOCK_RAW, NETLINK_AUDIT) = 7
  849. fcntl(7, F_SETFD, FD_CLOEXEC) = 0
  850. sendto(7, {{len=120, type=0x452 /* NLMSG_??? */, flags=NLM_F_REQUEST|NLM_F_ACK, seq=4, pid=0}, "op=PAM:session_close acct=\"root\""...}, 120, 0, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, 12) = 120
  851. poll([{fd=7, events=POLLIN}], 1, 500) = 1 ([{fd=7, revents=POLLIN}])
  852. recvfrom(7, {{len=36, type=NLMSG_ERROR, flags=0, seq=4, pid=2196005139}, "\0\0\0\0x\0\0\0R\4\5\0\4\0\0\0\0\0\0\0"}, 8988, MSG_PEEK|MSG_DONTWAIT, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, [12]) = 36
  853. recvfrom(7, {{len=36, type=NLMSG_ERROR, flags=0, seq=4, pid=2196005139}, "\0\0\0\0x\0\0\0R\4\5\0\4\0\0\0\0\0\0\0"}, 8988, MSG_DONTWAIT, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, [12]) = 36
  854. close(7) = 0
  855. socket(AF_NETLINK, SOCK_RAW, NETLINK_AUDIT) = 7
  856. fcntl(7, F_SETFD, FD_CLOEXEC) = 0
  857. sendto(7, {{len=116, type=0x450 /* NLMSG_??? */, flags=NLM_F_REQUEST|NLM_F_ACK, seq=5, pid=0}, "op=PAM:setcred acct=\"root\" exe=\""...}, 116, 0, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, 12) = 116
  858. poll([{fd=7, events=POLLIN}], 1, 500) = 1 ([{fd=7, revents=POLLIN}])
  859. recvfrom(7, {{len=36, type=NLMSG_ERROR, flags=0, seq=5, pid=2419880044}, "\0\0\0\0t\0\0\0P\4\5\0\5\0\0\0\0\0\0\0"}, 8988, MSG_PEEK|MSG_DONTWAIT, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, [12]) = 36
  860. recvfrom(7, {{len=36, type=NLMSG_ERROR, flags=0, seq=5, pid=2419880044}, "\0\0\0\0t\0\0\0P\4\5\0\5\0\0\0\0\0\0\0"}, 8988, MSG_DONTWAIT, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, [12]) = 36
  861. close(7) = 0
  862. munmap(0x7f51e5339000, 2204640) = 0
  863. munmap(0x7f51e5101000, 2322912) = 0
  864. munmap(0x7f51e4eff000, 2101288) = 0
  865. munmap(0x7f51e4cfd000, 2101312) = 0
  866. munmap(0x7f51e4afa000, 2105360) = 0
  867. munmap(0x7f51e48f4000, 2117976) = 0
  868. munmap(0x7f51e46e9000, 2138208) = 0
  869. munmap(0x7f51e46a3000, 282752) = 0
  870. munmap(0x7f51e449f000, 2109744) = 0
  871. exit_group(0) = ?
  872. +++ exited with 0 +++
  873. root@localhost:~# exit
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement