[root@localhost strace]# cat mysqld.out.3329 futex(0x12f6d64, FUTEX_WAIT_PRIVATE, 25, NULL) = 0 futex(0x12f4480, FUTEX_WAIT_PRIVATE, 2, NULL) = -1 EAGAIN (Resource temporarily unavailable) futex(0x12f4480, FUTEX_WAKE_PRIVATE, 1) = 0 setsockopt(29, SOL_SOCKET, SO_KEEPALIVE, [1], 4) = 0 sendto(29, "R\0\0\0\n5.6.16-64.2-56\0\16\0\0\0gv=ht/+*"..., 86, MSG_DONTWAIT, NULL, 0) = 86 recvfrom(29, 0x3609450, 4, 64, 0, 0) = -1 EAGAIN (Resource temporarily unavailable) poll([{fd=29, events=POLLIN|POLLPRI}], 1, 10000) = 1 ([{fd=29, revents=POLLIN}]) recvfrom(29, "\276\0\0\1", 4, MSG_DONTWAIT, NULL, NULL) = 4 recvfrom(29, "\205\246\177\0\0\0\0\1!\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., 190, MSG_DONTWAIT, NULL, NULL) = 190 stat("/etc/pam.d", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0 open("/etc/pam.d/mysqld", O_RDONLY) = 31 fstat(31, {st_mode=S_IFREG|0644, st_size=159, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b391561a000 read(31, "auth required pam_warn"..., 4096) = 159 open("/lib64/security/pam_warn.so", O_RDONLY) = 32 read(32, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0`\5\0\0\0\0\0\0"..., 832) = 832 fstat(32, {st_mode=S_IFREG|0755, st_size=5080, ...}) = 0 mmap(NULL, 2100408, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 32, 0) = 0x2b391561b000 mprotect(0x2b391561c000, 2093056, PROT_NONE) = 0 mmap(0x2b391581b000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 32, 0) = 0x2b391581b000 close(32) = 0 open("/lib64/security/pam_unix.so", O_RDONLY) = 32 read(32, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\200%\0\0\0\0\0\0"..., 832) = 832 fstat(32, {st_mode=S_IFREG|0755, st_size=48824, ...}) = 0 mmap(NULL, 2193416, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 32, 0) = 0x2b391581c000 mprotect(0x2b3915827000, 2097152, PROT_NONE) = 0 mmap(0x2b3915a27000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 32, 0xb000) = 0x2b3915a27000 mmap(0x2b3915a28000, 47112, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b3915a28000 close(32) = 0 open("/etc/ld.so.cache", O_RDONLY) = 32 fstat(32, {st_mode=S_IFREG|0644, st_size=67176, ...}) = 0 mmap(NULL, 67176, PROT_READ, MAP_PRIVATE, 32, 0) = 0x2b3915a34000 close(32) = 0 open("/usr/lib64/libcrack.so.2", O_RDONLY) = 32 read(32, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\00008\240\2432\0\0\0"..., 832) = 832 fstat(32, {st_mode=S_IFREG|0755, st_size=40896, ...}) = 0 mmap(0x32a3a00000, 2148896, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 32, 0) = 0x2b3915a45000 mprotect(0x2b3915a4d000, 2097152, PROT_NONE) = 0 mmap(0x2b3915c4d000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 32, 0x8000) = 0x2b3915c4d000 mmap(0x2b3915c4e000, 14880, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b3915c4e000 close(32) = 0 open("/lib64/libnsl.so.1", O_RDONLY) = 32 read(32, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\240@\300\2532\0\0\0"..., 832) = 832 fstat(32, {st_mode=S_IFREG|0755, st_size=114352, ...}) = 0 mmap(0x32abc00000, 2194096, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 32, 0) = 0x32abc00000 mprotect(0x32abc15000, 2093056, PROT_NONE) = 0 mmap(0x32abe14000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 32, 0x14000) = 0x32abe14000 mmap(0x32abe16000, 6832, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x32abe16000 close(32) = 0 mprotect(0x32abe14000, 4096, PROT_READ) = 0 munmap(0x2b3915a34000, 67176) = 0 open("/lib64/security/pam_permit.so", O_RDONLY) = 32 read(32, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0000\5\0\0\0\0\0\0"..., 832) = 832 fstat(32, {st_mode=S_IFREG|0755, st_size=4416, ...}) = 0 mmap(NULL, 2099744, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 32, 0) = 0x2b3915c52000 mprotect(0x2b3915c53000, 2093056, PROT_NONE) = 0 mmap(0x2b3915e52000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 32, 0) = 0x2b3915e52000 close(32) = 0 read(31, "", 4096) = 0 close(31) = 0 munmap(0x2b391561a000, 4096) = 0 open("/etc/pam.d/other", O_RDONLY) = 31 fstat(31, {st_mode=S_IFREG|0644, st_size=154, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b391561a000 read(31, "#%PAM-1.0\nauth required "..., 4096) = 154 open("/lib64/security/pam_deny.so", O_RDONLY) = 32 read(32, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0p\4\0\0\0\0\0\0"..., 832) = 832 fstat(32, {st_mode=S_IFREG|0755, st_size=4040, ...}) = 0 mmap(NULL, 2099440, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 32, 0) = 0x2b3915e53000 mprotect(0x2b3915e54000, 2093056, PROT_NONE) = 0 mmap(0x2b3916053000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 32, 0) = 0x2b3916053000 close(32) = 0 read(31, "", 4096) = 0 close(31) = 0 munmap(0x2b391561a000, 4096) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=265, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=265, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=265, ...}) = 0 sendto(30, "<85>Jun 18 12:35:39 mysqld: pam_"..., 169, MSG_NOSIGNAL, NULL, 0) = 169 getuid() = 101 sendto(29, "\23\0\0\2\376dialog\0\4Password: ", 23, MSG_DONTWAIT, NULL, 0) = 23 recvfrom(29, 0x3609450, 4, 64, 0, 0) = -1 EAGAIN (Resource temporarily unavailable) poll([{fd=29, events=POLLIN|POLLPRI}], 1, 10000) = 1 ([{fd=29, revents=POLLIN}]) recvfrom(29, "\7\0\0\3", 4, MSG_DONTWAIT, NULL, NULL) = 4 recvfrom(29, "apuser\0", 7, MSG_DONTWAIT, NULL, NULL) = 7 open("/etc/passwd", O_RDONLY) = 31 fcntl(31, F_GETFD) = 0 fcntl(31, F_SETFD, FD_CLOEXEC) = 0 fstat(31, {st_mode=S_IFREG|0644, st_size=1747, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b391561a000 read(31, "root:x:0:0:root:/root:/bin/bash\n"..., 4096) = 1747 close(31) = 0 munmap(0x2b391561a000, 4096) = 0 open("/etc/shadow", O_RDONLY) = 31 fcntl(31, F_GETFD) = 0 fcntl(31, F_SETFD, FD_CLOEXEC) = 0 fstat(31, {st_mode=S_IFREG|0440, st_size=1183, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b391561a000 read(31, "root:$1$Gs7zP/6K$3/DrCuNdvgBtwoo"..., 4096) = 1183 close(31) = 0 munmap(0x2b391561a000, 4096) = 0 socket(PF_NETLINK, SOCK_RAW, 9) = 31 fcntl(31, F_SETFD, FD_CLOEXEC) = 0 socket(PF_NETLINK, SOCK_RAW, 0) = 32 bind(32, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0 getsockname(32, {sa_family=AF_NETLINK, pid=3261, groups=00000000}, [12]) = 0 sendto(32, "\24\0\0\0\26\0\1\3C:\241S\0\0\0\0\0\0\0\0", 20, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20 recvmsg(32, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"<\0\0\0\24\0\2\0C:\241S\275\f\0\0\2\10\200\376\1\0\0\0\10\0\1\0\177\0\0\1"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128 recvmsg(32, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0C:\241S\275\f\0\0\0\0\0\0\1\0\0\0\10\0\1\0\177\0\0\1"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20 close(32) = 0 open("/etc/hosts", O_RDONLY) = 32 fcntl(32, F_GETFD) = 0 fcntl(32, F_SETFD, FD_CLOEXEC) = 0 fstat(32, {st_mode=S_IFREG|0644, st_size=187, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b391561a000 read(32, "# Do not remove the following li"..., 4096) = 187 close(32) = 0 munmap(0x2b391561a000, 4096) = 0 readlink("/proc/self/exe", 0x2b3915612cc0, 4096) = -1 EACCES (Permission denied) ioctl(0, SNDCTL_TMR_TIMEBASE or TCGETS, 0x2b3915613a40) = -1 ENOTTY (Inappropriate ioctl for device) ioctl(1, SNDCTL_TMR_TIMEBASE or TCGETS, 0x2b3915613a40) = -1 ENOTTY (Inappropriate ioctl for device) ioctl(2, SNDCTL_TMR_TIMEBASE or TCGETS, 0x2b3915613a40) = -1 ENOTTY (Inappropriate ioctl for device) sendto(31, "|\0\0\0L\4\5\0\33\0\0\0\0\0\0\0PAM: authenticat"..., 124, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 124 poll([{fd=31, events=POLLIN}], 1, 500) = 1 ([{fd=31, revents=POLLIN}]) recvfrom(31, "$\0\0\0\2\0\0\0\33\0\0\0\275\f\0\0\377\377\377\377|\0\0\0L\4\5\0\33\0\0\0"..., 8988, MSG_PEEK|MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 36 recvfrom(31, "$\0\0\0\2\0\0\0\33\0\0\0\275\f\0\0\377\377\377\377|\0\0\0L\4\5\0\33\0\0\0"..., 8988, MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 36 getuid() = 101 close(31) = 0 getuid() = 101 open("/etc/passwd", O_RDONLY) = 31 fcntl(31, F_GETFD) = 0 fcntl(31, F_SETFD, FD_CLOEXEC) = 0 fstat(31, {st_mode=S_IFREG|0644, st_size=1747, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b391561a000 read(31, "root:x:0:0:root:/root:/bin/bash\n"..., 4096) = 1747 close(31) = 0 munmap(0x2b391561a000, 4096) = 0 geteuid() = 101 socket(PF_NETLINK, SOCK_RAW, 9) = 31 fcntl(31, F_SETFD, FD_CLOEXEC) = 0 socket(PF_NETLINK, SOCK_RAW, 0) = 32 bind(32, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0 getsockname(32, {sa_family=AF_NETLINK, pid=3261, groups=00000000}, [12]) = 0 sendto(32, "\24\0\0\0\26\0\1\3C:\241S\0\0\0\0\0\0\0\0", 20, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20 recvmsg(32, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"<\0\0\0\24\0\2\0C:\241S\275\f\0\0\2\10\200\376\1\0\0\0\10\0\1\0\177\0\0\1"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128 recvmsg(32, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0C:\241S\275\f\0\0\0\0\0\0\1\0\0\0\10\0\1\0\177\0\0\1"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20 close(32) = 0 open("/etc/hosts", O_RDONLY) = 32 fcntl(32, F_GETFD) = 0 fcntl(32, F_SETFD, FD_CLOEXEC) = 0 fstat(32, {st_mode=S_IFREG|0644, st_size=187, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b391561a000 read(32, "# Do not remove the following li"..., 4096) = 187 close(32) = 0 munmap(0x2b391561a000, 4096) = 0 readlink("/proc/self/exe", 0x2b3915612cc0, 4096) = -1 EACCES (Permission denied) ioctl(0, SNDCTL_TMR_TIMEBASE or TCGETS, 0x2b3915613a40) = -1 ENOTTY (Inappropriate ioctl for device) ioctl(1, SNDCTL_TMR_TIMEBASE or TCGETS, 0x2b3915613a40) = -1 ENOTTY (Inappropriate ioctl for device) ioctl(2, SNDCTL_TMR_TIMEBASE or TCGETS, 0x2b3915613a40) = -1 ENOTTY (Inappropriate ioctl for device) sendto(31, "x\0\0\0M\4\5\0\34\0\0\0\0\0\0\0PAM: accounting "..., 120, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 120 poll([{fd=31, events=POLLIN}], 1, 500) = 1 ([{fd=31, revents=POLLIN}]) recvfrom(31, "$\0\0\0\2\0\0\0\34\0\0\0\275\f\0\0\377\377\377\377x\0\0\0M\4\5\0\34\0\0\0"..., 8988, MSG_PEEK|MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 36 recvfrom(31, "$\0\0\0\2\0\0\0\34\0\0\0\275\f\0\0\377\377\377\377x\0\0\0M\4\5\0\34\0\0\0"..., 8988, MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 36 getuid() = 101 close(31) = 0 open("/etc/passwd", O_RDONLY) = 31 fcntl(31, F_GETFD) = 0 fcntl(31, F_SETFD, FD_CLOEXEC) = 0 fstat(31, {st_mode=S_IFREG|0644, st_size=1747, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b391561a000 read(31, "root:x:0:0:root:/root:/bin/bash\n"..., 4096) = 1747 close(31) = 0 munmap(0x2b391561a000, 4096) = 0 open("/etc/group", O_RDONLY) = 31 fcntl(31, F_GETFD) = 0 fcntl(31, F_SETFD, FD_CLOEXEC) = 0 fstat(31, {st_mode=S_IFREG|0644, st_size=681, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b391561a000 lseek(31, 0, SEEK_CUR) = 0 read(31, "root:x:0:root\nbin:x:1:root,bin,d"..., 4096) = 681 read(31, "", 4096) = 0 close(31) = 0 munmap(0x2b391561a000, 4096) = 0 munmap(0x2b391561b000, 2100408) = 0 munmap(0x2b391581c000, 2193416) = 0 munmap(0x2b3915a45000, 2148896) = 0 munmap(0x32abc00000, 2194096) = 0 munmap(0x2b3915c52000, 2099744) = 0 munmap(0x2b3915e53000, 2099440) = 0 sendto(29, "\7\0\0\4\0\0\0\2\0\0\0", 11, MSG_DONTWAIT, NULL, 0) = 11 recvfrom(29, 0x3609450, 4, 64, 0, 0) = -1 EAGAIN (Resource temporarily unavailable) poll([{fd=29, events=POLLIN|POLLPRI}], 1, 28800000) = 1 ([{fd=29, revents=POLLIN}]) recvfrom(29, "!\0\0\0", 4, MSG_DONTWAIT, NULL, NULL) = 4 clock_gettime(CLOCK_REALTIME, {1403075139, 797211000}) = 0 recvfrom(29, "\3select @@version_comment limit "..., 33, MSG_DONTWAIT, NULL, NULL) = 33 sendto(29, "\1\0\0\1\1'\0\0\2\3def\0\0\0\21@@version_comme"..., 119, MSG_DONTWAIT, NULL, 0) = 119 clock_gettime(CLOCK_REALTIME, {1403075139, 797387000}) = 0 recvfrom(29, 0x3609450, 4, 64, 0, 0) = -1 EAGAIN (Resource temporarily unavailable) poll([{fd=29, events=POLLIN|POLLPRI}], 1, 28800000) = 1 ([{fd=29, revents=POLLIN|POLLHUP}]) recvfrom(29, "\1\0\0\0", 4, MSG_DONTWAIT, NULL, NULL) = 4 clock_gettime(CLOCK_REALTIME, {1403075141, 126920000}) = 0 recvfrom(29, "\1", 1, MSG_DONTWAIT, NULL, NULL) = 1 clock_gettime(CLOCK_REALTIME, {1403075141, 127136000}) = 0 shutdown(29, 2 /* send and receive */) = 0 close(29) = 0 futex(0x12f6d64, FUTEX_WAIT_PRIVATE, 27, NULL) = 0 futex(0x12f4480, FUTEX_WAIT_PRIVATE, 2, NULL) = -1 EAGAIN (Resource temporarily unavailable) futex(0x12f4480, FUTEX_WAKE_PRIVATE, 1) = 0 setsockopt(29, SOL_SOCKET, SO_KEEPALIVE, [1], 4) = 0 sendto(29, "R\0\0\0\n5.6.16-64.2-56\0\17\0\0\0'P>(IxD'"..., 86, MSG_DONTWAIT, NULL, 0) = 86 recvfrom(29, 0x36050f0, 4, 64, 0, 0) = -1 EAGAIN (Resource temporarily unavailable) poll([{fd=29, events=POLLIN|POLLPRI}], 1, 10000) = 1 ([{fd=29, revents=POLLIN}]) recvfrom(29, "\276\0\0\1", 4, MSG_DONTWAIT, NULL, NULL) = 4 recvfrom(29, "\205\246\177\0\0\0\0\1!\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., 190, MSG_DONTWAIT, NULL, NULL) = 190 stat("/etc/pam.d", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0 open("/etc/pam.d/mysqld", O_RDONLY) = 31 fstat(31, {st_mode=S_IFREG|0644, st_size=160, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b391561a000 read(31, "auth required pam_warn"..., 4096) = 160 open("/lib64/security/pam_warn.so", O_RDONLY) = 32 read(32, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0`\5\0\0\0\0\0\0"..., 832) = 832 fstat(32, {st_mode=S_IFREG|0755, st_size=5080, ...}) = 0 mmap(NULL, 2100408, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 32, 0) = 0x2b391561b000 mprotect(0x2b391561c000, 2093056, PROT_NONE) = 0 mmap(0x2b391581b000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 32, 0) = 0x2b391581b000 close(32) = 0 open("/lib64/security/pam_unix.so", O_RDONLY) = 32 read(32, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\200%\0\0\0\0\0\0"..., 832) = 832 fstat(32, {st_mode=S_IFREG|0755, st_size=48824, ...}) = 0 mmap(NULL, 2193416, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 32, 0) = 0x2b391581c000 mprotect(0x2b3915827000, 2097152, PROT_NONE) = 0 mmap(0x2b3915a27000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 32, 0xb000) = 0x2b3915a27000 mmap(0x2b3915a28000, 47112, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b3915a28000 close(32) = 0 open("/etc/ld.so.cache", O_RDONLY) = 32 fstat(32, {st_mode=S_IFREG|0644, st_size=67176, ...}) = 0 mmap(NULL, 67176, PROT_READ, MAP_PRIVATE, 32, 0) = 0x2b3915a34000 close(32) = 0 open("/usr/lib64/libcrack.so.2", O_RDONLY) = 32 read(32, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\00008\240\2432\0\0\0"..., 832) = 832 fstat(32, {st_mode=S_IFREG|0755, st_size=40896, ...}) = 0 mmap(0x32a3a00000, 2148896, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 32, 0) = 0x2b3915a45000 mprotect(0x2b3915a4d000, 2097152, PROT_NONE) = 0 mmap(0x2b3915c4d000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 32, 0x8000) = 0x2b3915c4d000 mmap(0x2b3915c4e000, 14880, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2b3915c4e000 close(32) = 0 open("/lib64/libnsl.so.1", O_RDONLY) = 32 read(32, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\240@\300\2532\0\0\0"..., 832) = 832 fstat(32, {st_mode=S_IFREG|0755, st_size=114352, ...}) = 0 mmap(0x32abc00000, 2194096, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 32, 0) = 0x32abc00000 mprotect(0x32abc15000, 2093056, PROT_NONE) = 0 mmap(0x32abe14000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 32, 0x14000) = 0x32abe14000 mmap(0x32abe16000, 6832, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x32abe16000 close(32) = 0 mprotect(0x32abe14000, 4096, PROT_READ) = 0 munmap(0x2b3915a34000, 67176) = 0 read(31, "", 4096) = 0 close(31) = 0 munmap(0x2b391561a000, 4096) = 0 open("/etc/pam.d/other", O_RDONLY) = 31 fstat(31, {st_mode=S_IFREG|0644, st_size=154, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b391561a000 read(31, "#%PAM-1.0\nauth required "..., 4096) = 154 open("/lib64/security/pam_deny.so", O_RDONLY) = 32 read(32, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0p\4\0\0\0\0\0\0"..., 832) = 832 fstat(32, {st_mode=S_IFREG|0755, st_size=4040, ...}) = 0 mmap(NULL, 2099440, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 32, 0) = 0x2b3915c52000 mprotect(0x2b3915c53000, 2093056, PROT_NONE) = 0 mmap(0x2b3915e52000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 32, 0) = 0x2b3915e52000 close(32) = 0 read(31, "", 4096) = 0 close(31) = 0 munmap(0x2b391561a000, 4096) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=265, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=265, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=265, ...}) = 0 sendto(30, "<85>Jun 18 12:35:51 mysqld: pam_"..., 169, MSG_NOSIGNAL, NULL, 0) = 169 getuid() = 101 sendto(29, "\23\0\0\2\376dialog\0\4Password: ", 23, MSG_DONTWAIT, NULL, 0) = 23 recvfrom(29, 0x36050f0, 4, 64, 0, 0) = -1 EAGAIN (Resource temporarily unavailable) poll([{fd=29, events=POLLIN|POLLPRI}], 1, 10000) = 1 ([{fd=29, revents=POLLIN}]) recvfrom(29, "\7\0\0\3", 4, MSG_DONTWAIT, NULL, NULL) = 4 recvfrom(29, "apuser\0", 7, MSG_DONTWAIT, NULL, NULL) = 7 open("/etc/passwd", O_RDONLY) = 31 fcntl(31, F_GETFD) = 0 fcntl(31, F_SETFD, FD_CLOEXEC) = 0 fstat(31, {st_mode=S_IFREG|0644, st_size=1747, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b391561a000 read(31, "root:x:0:0:root:/root:/bin/bash\n"..., 4096) = 1747 close(31) = 0 munmap(0x2b391561a000, 4096) = 0 open("/etc/shadow", O_RDONLY) = 31 fcntl(31, F_GETFD) = 0 fcntl(31, F_SETFD, FD_CLOEXEC) = 0 fstat(31, {st_mode=S_IFREG|0440, st_size=1183, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b391561a000 read(31, "root:$1$Gs7zP/6K$3/DrCuNdvgBtwoo"..., 4096) = 1183 close(31) = 0 munmap(0x2b391561a000, 4096) = 0 socket(PF_NETLINK, SOCK_RAW, 9) = 31 fcntl(31, F_SETFD, FD_CLOEXEC) = 0 socket(PF_NETLINK, SOCK_RAW, 0) = 32 bind(32, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0 getsockname(32, {sa_family=AF_NETLINK, pid=3261, groups=00000000}, [12]) = 0 sendto(32, "\24\0\0\0\26\0\1\3O:\241S\0\0\0\0\0\0\0\0", 20, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20 recvmsg(32, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"<\0\0\0\24\0\2\0O:\241S\275\f\0\0\2\10\200\376\1\0\0\0\10\0\1\0\177\0\0\1"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128 recvmsg(32, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0O:\241S\275\f\0\0\0\0\0\0\1\0\0\0\10\0\1\0\177\0\0\1"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20 close(32) = 0 open("/etc/hosts", O_RDONLY) = 32 fcntl(32, F_GETFD) = 0 fcntl(32, F_SETFD, FD_CLOEXEC) = 0 fstat(32, {st_mode=S_IFREG|0644, st_size=187, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b391561a000 read(32, "# Do not remove the following li"..., 4096) = 187 close(32) = 0 munmap(0x2b391561a000, 4096) = 0 readlink("/proc/self/exe", 0x2b3915612cc0, 4096) = -1 EACCES (Permission denied) ioctl(0, SNDCTL_TMR_TIMEBASE or TCGETS, 0x2b3915613a40) = -1 ENOTTY (Inappropriate ioctl for device) ioctl(1, SNDCTL_TMR_TIMEBASE or TCGETS, 0x2b3915613a40) = -1 ENOTTY (Inappropriate ioctl for device) ioctl(2, SNDCTL_TMR_TIMEBASE or TCGETS, 0x2b3915613a40) = -1 ENOTTY (Inappropriate ioctl for device) sendto(31, "|\0\0\0L\4\5\0\35\0\0\0\0\0\0\0PAM: authenticat"..., 124, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 124 poll([{fd=31, events=POLLIN}], 1, 500) = 1 ([{fd=31, revents=POLLIN}]) recvfrom(31, "$\0\0\0\2\0\0\0\35\0\0\0\275\f\0\0\377\377\377\377|\0\0\0L\4\5\0\35\0\0\0"..., 8988, MSG_PEEK|MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 36 recvfrom(31, "$\0\0\0\2\0\0\0\35\0\0\0\275\f\0\0\377\377\377\377|\0\0\0L\4\5\0\35\0\0\0"..., 8988, MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 36 getuid() = 101 close(31) = 0 getuid() = 101 open("/etc/passwd", O_RDONLY) = 31 fcntl(31, F_GETFD) = 0 fcntl(31, F_SETFD, FD_CLOEXEC) = 0 fstat(31, {st_mode=S_IFREG|0644, st_size=1747, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b391561a000 read(31, "root:x:0:0:root:/root:/bin/bash\n"..., 4096) = 1747 close(31) = 0 munmap(0x2b391561a000, 4096) = 0 geteuid() = 101 socket(PF_NETLINK, SOCK_RAW, 9) = 31 fcntl(31, F_SETFD, FD_CLOEXEC) = 0 socket(PF_NETLINK, SOCK_RAW, 0) = 32 bind(32, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0 getsockname(32, {sa_family=AF_NETLINK, pid=3261, groups=00000000}, [12]) = 0 sendto(32, "\24\0\0\0\26\0\1\3O:\241S\0\0\0\0\0\0\0\0", 20, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20 recvmsg(32, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"<\0\0\0\24\0\2\0O:\241S\275\f\0\0\2\10\200\376\1\0\0\0\10\0\1\0\177\0\0\1"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128 recvmsg(32, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0O:\241S\275\f\0\0\0\0\0\0\1\0\0\0\10\0\1\0\177\0\0\1"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20 close(32) = 0 open("/etc/hosts", O_RDONLY) = 32 fcntl(32, F_GETFD) = 0 fcntl(32, F_SETFD, FD_CLOEXEC) = 0 fstat(32, {st_mode=S_IFREG|0644, st_size=187, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b391561a000 read(32, "# Do not remove the following li"..., 4096) = 187 close(32) = 0 munmap(0x2b391561a000, 4096) = 0 readlink("/proc/self/exe", 0x2b3915612cc0, 4096) = -1 EACCES (Permission denied) ioctl(0, SNDCTL_TMR_TIMEBASE or TCGETS, 0x2b3915613a40) = -1 ENOTTY (Inappropriate ioctl for device) ioctl(1, SNDCTL_TMR_TIMEBASE or TCGETS, 0x2b3915613a40) = -1 ENOTTY (Inappropriate ioctl for device) ioctl(2, SNDCTL_TMR_TIMEBASE or TCGETS, 0x2b3915613a40) = -1 ENOTTY (Inappropriate ioctl for device) sendto(31, "x\0\0\0M\4\5\0\36\0\0\0\0\0\0\0PAM: accounting "..., 120, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 120 poll([{fd=31, events=POLLIN}], 1, 500) = 1 ([{fd=31, revents=POLLIN}]) recvfrom(31, "$\0\0\0\2\0\0\0\36\0\0\0\275\f\0\0\377\377\377\377x\0\0\0M\4\5\0\36\0\0\0"..., 8988, MSG_PEEK|MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 36 recvfrom(31, "$\0\0\0\2\0\0\0\36\0\0\0\275\f\0\0\377\377\377\377x\0\0\0M\4\5\0\36\0\0\0"..., 8988, MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 36 getuid() = 101 close(31) = 0 munmap(0x2b391561b000, 2100408) = 0 munmap(0x2b391581c000, 2193416) = 0 munmap(0x2b3915a45000, 2148896) = 0 munmap(0x32abc00000, 2194096) = 0 munmap(0x2b3915c52000, 2099440) = 0 sendto(29, "K\0\0\4\377\25\4#28000Access denied for u"..., 79, MSG_DONTWAIT, NULL, 0) = 79 shutdown(29, 2 /* send and receive */) = 0 close(29) = 0 futex(0x12f6d64, FUTEX_WAIT_PRIVATE, 29, NULL[root@localhost strace]# [root@localhost strace]#