Strange hidden Files .#gshadowxxxxxx

Discussion in 'Installation/Configuration' started by Gerd, Jun 7, 2023.

  1. Gerd

    Gerd New Member HowtoForge Supporter

    Hi HowtoForge Community!
    i have found a lot ( +800) strange files on my server. The files names are like that:
    /etc/.#gshadowzfpXan
    /etc/.#gshadowqK2cgQ
    and so on. Some files are relatively new, (2 days). The files are all empty and got same owner and perm. as /etc/gshadow
    Does someone know what that is about? Google did not help me ...
    Yours, Gerd
     
  2. ahrasis

    ahrasis Well-Known Member HowtoForge Supporter

    If you don't know anything that can help us help you, we know nothing more than you.
     
  3. Gerd

    Gerd New Member HowtoForge Supporter

    Oh sorry, i forgot to give the system infos because i thought this is so characteristic that someone might know what this is:
    Debian 10 (Buster) System With dovecot, apache, bind9 and ISPConfig.
    grep gsha /var/log/syslog or
    grep gsha /var/log/messages
    returns nothing. The system runs quite normally, it is just that i am trying to understand what causes these strange files.
    Yours, Gerd
     
  4. ahrasis

    ahrasis Well-Known Member HowtoForge Supporter

    1. When it is an ISPConfig server, you should post in its specifc board, instead of general linux, which may help us to help you better knowing your server build and setup.

    2. No, we normally do not know more than you do. If your research / google returned with nothing concrete / specific, normally so do we.

    3. In any event, you should check your access log and when did the claimed mysterious folders / files appeared in that /etc folder. Simple command like ls -lah may provide their date and time stamps.
     
    Last edited: Jun 7, 2023
  5. till

    till Super Moderator Staff Member ISPConfig Developer

    I've not seen that yet. What I can tell you at least is that it's nothing that ISPConfig is normally doing. ISPConfig is just using regular Linux commands like useradd to add or manage Linux system users.
     
    ahrasis likes this.
  6. ahrasis

    ahrasis Well-Known Member HowtoForge Supporter

    By the way, did you install / use google drive or something on your server / system?
     
  7. Gerd

    Gerd New Member HowtoForge Supporter

    No no google drive or something.
    I found that the files are created at boot time. lsof do not show any process using the files.
    I keep searching and will report any findings.
    Yours, Gerd
     
  8. ahrasis

    ahrasis Well-Known Member HowtoForge Supporter

    Last edited: Jun 7, 2023
  9. buhler

    buhler Member

    Good morning, It happens to me too.
    Debian buster and Ispconfig latest version.
    Only happens when restarting the server.
    Did you manage to find any solution?
     
  10. till

    till Super Moderator Staff Member ISPConfig Developer

    Here is an answer from ChatGPT about what the origin might be:

     
  11. buhler

    buhler Member

    Thank you.
     
  12. Gerd

    Gerd New Member HowtoForge Supporter

    Hi buhler,
    no, unfortunately I have not found out what causes these files.
    I have updated the server to bullseye since then, but the files still appear with every reboot.
    I was very worried whether this could be a sign of compromise, but in the meantime i have calmed down (for no objective reason).
    It would be great if we could find out the cause, i also will start a new attempt of investigation.
    Yours gerd
     
  13. buhler

    buhler Member

    Thanks for the feedback.
    I've gone through everything on my server.
    This is a really strange situation.
     

Share This Page