execve("/usr/sbin/useradd", ["useradd", "dummy"], [/* 45 vars */]) = 0 uname({sys="Linux", node="ishii", ...}) = 0 brk(0) = 0x805d000 access("/etc/ld.so.preload", R_OK) = -1 ENOENT (No such file or directory) open("/etc/ld.so.cache", O_RDONLY) = 3 fstat64(3, {st_mode=S_IFREG|0644, st_size=59567, ...}) = 0 mmap2(NULL, 59567, PROT_READ, MAP_PRIVATE, 3, 0) = 0xb7fdc000 close(3) = 0 open("/lib/libcrypt.so.1", O_RDONLY) = 3 read(3, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\0\10\0"..., 512) = 512 fstat64(3, {st_mode=S_IFREG|0755, st_size=22580, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7fdb000 mmap2(NULL, 184636, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0xb7fad000 mprotect(0xb7fb1000, 168252, PROT_NONE) = 0 mmap2(0xb7fb2000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x4) = 0xb7fb2000 mmap2(0xb7fb4000, 155964, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0xb7fb4000 close(3) = 0 open("/lib/libpam.so.0", O_RDONLY) = 3 read(3, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0 \24\0\000"..., 512) = 512 fstat64(3, {st_mode=S_IFREG|0755, st_size=25752, ...}) = 0 mmap2(NULL, 26980, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0xb7fa6000 mmap2(0xb7fac000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x5) = 0xb7fac000 close(3) = 0 open("/lib/libpam_misc.so.0", O_RDONLY) = 3 read(3, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0P\f\0\000"..., 512) = 512 fstat64(3, {st_mode=S_IFREG|0755, st_size=8036, ...}) = 0 mmap2(NULL, 10508, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0xb7fa3000 mmap2(0xb7fa5000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1) = 0xb7fa5000 close(3) = 0 open("/lib/libc.so.6", O_RDONLY) = 3 read(3, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\222P\1"..., 512) = 512 fstat64(3, {st_mode=S_IFREG|0755, st_size=1200848, ...}) = 0 mmap2(NULL, 1129772, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0xb7e8f000 mprotect(0xb7f9c000, 27948, PROT_NONE) = 0 mmap2(0xb7f9d000, 16384, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x10d) = 0xb7f9d000 mmap2(0xb7fa1000, 7468, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0xb7fa1000 close(3) = 0 open("/lib/libdl.so.2", O_RDONLY) = 3 read(3, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\340\v\0"..., 512) = 512 fstat64(3, {st_mode=S_IFREG|0755, st_size=10680, ...}) = 0 mmap2(NULL, 12392, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0xb7e8b000 mmap2(0xb7e8d000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1) = 0xb7e8d000 close(3) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7e8a000 mprotect(0xb7f9d000, 4096, PROT_READ) = 0 set_thread_area({entry_number:-1 -> 6, base_addr:0xb7e8ab50, limit:1048575, seg_32bit:1, contents:0, read_exec_only:0, limit_in_pages:1, seg_not_present:0, useable:1}) = 0 munmap(0xb7fdc000, 59567) = 0 open("/dev/urandom", O_RDONLY) = 3 read(3, "\343\220@$", 4) = 4 close(3) = 0 open("/proc/sys/kernel/ngroups_max", O_RDONLY) = 3 read(3, "65536\n", 31) = 6 close(3) = 0 mmap2(NULL, 266240, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7e49000 access("/etc/shadow", F_OK) = 0 access("/etc/gshadow", F_OK) = 0 brk(0) = 0x805d000 brk(0x807e000) = 0x807e000 open("/etc/default/useradd", O_RDONLY|O_LARGEFILE) = 3 fstat64(3, {st_mode=S_IFREG|0600, st_size=96, ...}) = 0 mmap2(NULL, 131072, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7e29000 read(3, "# useradd defaults file\nGROUP=10"..., 131072) = 96 socket(PF_FILE, SOCK_STREAM, 0) = 4 fcntl64(4, F_GETFL) = 0x2 (flags O_RDWR) fcntl64(4, F_SETFL, O_RDWR|O_NONBLOCK) = 0 connect(4, {sa_family=AF_FILE, path="/var/run/nscd/socket"}, 110) = 0 poll([{fd=4, events=POLLOUT|POLLERR|POLLHUP, revents=POLLOUT}], 1, 5000) = 1 writev(4, [{"\2\0\0\0\f\0\0\0\6\0\0\0", 12}, {"group\0", 6}], 2) = 18 poll([{fd=4, events=POLLIN|POLLERR|POLLHUP, revents=POLLIN|POLLHUP}], 1, 5000) = 1 recvmsg(4, {msg_name(0)=NULL, msg_iov(1)=[{"d\357\377\277`\357", 6}], msg_controllen=0, msg_flags=0}, 0) = 0 close(4) = 0 socket(PF_FILE, SOCK_STREAM, 0) = 4 fcntl64(4, F_GETFL) = 0x2 (flags O_RDWR) fcntl64(4, F_SETFL, O_RDWR|O_NONBLOCK) = 0 connect(4, {sa_family=AF_FILE, path="/var/run/nscd/socket"}, 110) = 0 poll([{fd=4, events=POLLOUT|POLLERR|POLLHUP, revents=POLLOUT}], 1, 5000) = 1 writev(4, [{"\2\0\0\0\3\0\0\0\4\0\0\0", 12}, {"100\0", 4}], 2) = 16 poll([{fd=4, events=POLLIN|POLLERR|POLLHUP, revents=POLLIN|POLLHUP}], 1, 5000) = 1 read(4, "\2\0\0\0\1\0\0\0\6\0\0\0\2\0\0\0d\0\0\0\2\0\0\0", 24) = 24 readv(4, [{"\6\0\0\0\7\0\0\0", 8}, {"users\0x\0", 8}], 2) = 16 read(4, "games\0dolney\0", 13) = 13 close(4) = 0 read(3, "", 131072) = 0 getuid32() = 0 socket(PF_FILE, SOCK_STREAM, 0) = 4 fcntl64(4, F_GETFL) = 0x2 (flags O_RDWR) fcntl64(4, F_SETFL, O_RDWR|O_NONBLOCK) = 0 connect(4, {sa_family=AF_FILE, path="/var/run/nscd/socket"}, 110) = 0 poll([{fd=4, events=POLLOUT|POLLERR|POLLHUP, revents=POLLOUT}], 1, 5000) = 1 writev(4, [{"\2\0\0\0\v\0\0\0\7\0\0\0", 12}, {"passwd\0", 7}], 2) = 19 poll([{fd=4, events=POLLIN|POLLERR|POLLHUP, revents=POLLIN|POLLHUP}], 1, 5000) = 1 recvmsg(4, {msg_name(0)=NULL, msg_iov(1)=[{"p\354\377\277d\354\377", 7}], msg_controllen=0, msg_flags=0}, 0) = 0 close(4) = 0 socket(PF_FILE, SOCK_STREAM, 0) = 4 fcntl64(4, F_GETFL) = 0x2 (flags O_RDWR) fcntl64(4, F_SETFL, O_RDWR|O_NONBLOCK) = 0 connect(4, {sa_family=AF_FILE, path="/var/run/nscd/socket"}, 110) = 0 poll([{fd=4, events=POLLOUT|POLLERR|POLLHUP, revents=POLLOUT}], 1, 5000) = 1 writev(4, [{"\2\0\0\0\1\0\0\0\2\0\0\0", 12}, {"0\0", 2}], 2) = 14 poll([{fd=4, events=POLLIN|POLLERR|POLLHUP, revents=POLLIN|POLLHUP}], 1, 5000) = 1 read(4, "\2\0\0\0\1\0\0\0\5\0\0\0\2\0\0\0\0\0\0\0\0\0\0\0\5\0\0"..., 36) = 36 read(4, "root\0x\0root\0/root\0/bin/bash\0", 28) = 28 close(4) = 0 stat64("/etc/pam.d", {st_mode=S_IFDIR|0755, st_size=872, ...}) = 0 open("/etc/pam.d/useradd", O_RDONLY) = 4 fstat64(4, {st_mode=S_IFREG|0644, st_size=227, ...}) = 0 mmap2(NULL, 131072, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7e09000 read(4, "#%PAM-1.0 \n\nauth sufficien"..., 131072) = 227 open("/lib/security/pam_rootok.so", O_RDONLY) = 5 read(5, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\220\5\0"..., 512) = 512 fstat64(5, {st_mode=S_IFREG|0755, st_size=3864, ...}) = 0 mmap2(NULL, 6404, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 5, 0) = 0xb7e07000 mmap2(0xb7e08000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 5, 0) = 0xb7e08000 close(5) = 0 open("/lib/security/pam_permit.so", O_RDONLY) = 5 read(5, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\220\5\0"..., 512) = 512 fstat64(5, {st_mode=S_IFREG|0755, st_size=3652, ...}) = 0 mmap2(NULL, 6192, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 5, 0) = 0xb7e05000 mmap2(0xb7e06000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 5, 0) = 0xb7e06000 close(5) = 0 open("/lib/security/pam_stack.so", O_RDONLY) = 5 read(5, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0p\n\0\000"..., 512) = 512 fstat64(5, {st_mode=S_IFREG|0755, st_size=9392, ...}) = 0 mmap2(NULL, 11932, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 5, 0) = 0xb7e02000 mmap2(0xb7e04000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 5, 0x1) = 0xb7e04000 close(5) = 0 read(4, "", 131072) = 0 close(4) = 0 munmap(0xb7e09000, 131072) = 0 open("/etc/pam.d/other", O_RDONLY) = 4 fstat64(4, {st_mode=S_IFREG|0644, st_size=198, ...}) = 0 mmap2(NULL, 131072, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7e09000 read(4, "#%PAM-1.0\n\nauth required\t/"..., 131072) = 198 open("/lib/security/pam_deny.so", O_RDONLY) = 5 read(5, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\0\5\0\000"..., 512) = 512 fstat64(5, {st_mode=S_IFREG|0755, st_size=3380, ...}) = 0 mmap2(NULL, 5968, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 5, 0) = 0xb7e00000 mmap2(0xb7e01000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 5, 0) = 0xb7e01000 close(5) = 0 read(4, "", 131072) = 0 close(4) = 0 munmap(0xb7e09000, 131072) = 0 time(NULL) = 1108059723 getuid32() = 0 stat64("/etc/pam.d", {st_mode=S_IFDIR|0755, st_size=872, ...}) = 0 open("/etc/pam.d/system-auth", O_RDONLY) = 4 fstat64(4, {st_mode=S_IFREG|0644, st_size=671, ...}) = 0 mmap2(NULL, 131072, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7e09000 read(4, "#%PAM-1.0\n\nauth required\t/"..., 131072) = 671 open("/lib/security/pam_env.so", O_RDONLY) = 5 read(5, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\340\n\0"..., 512) = 512 fstat64(5, {st_mode=S_IFREG|0755, st_size=9316, ...}) = 0 mmap2(NULL, 11856, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 5, 0) = 0xb7dfd000 mmap2(0xb7dff000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 5, 0x1) = 0xb7dff000 close(5) = 0 open("/lib/security/pam_unix.so", O_RDONLY) = 5 read(5, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\220\"\0"..., 512) = 512 fstat64(5, {st_mode=S_IFREG|0755, st_size=39072, ...}) = 0 mmap2(NULL, 89688, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 5, 0) = 0xb7de7000 mmap2(0xb7df0000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 5, 0x8) = 0xb7df0000 mmap2(0xb7df1000, 48728, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0xb7df1000 close(5) = 0 open("/etc/ld.so.cache", O_RDONLY) = 5 fstat64(5, {st_mode=S_IFREG|0644, st_size=59567, ...}) = 0 mmap2(NULL, 59567, PROT_READ, MAP_PRIVATE, 5, 0) = 0xb7dd8000 close(5) = 0 open("/lib/libnsl.so.1", O_RDONLY) = 5 read(5, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\2004\0"..., 512) = 512 fstat64(5, {st_mode=S_IFREG|0755, st_size=75864, ...}) = 0 mmap2(NULL, 83968, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 5, 0) = 0xb7dc3000 mmap2(0xb7dd4000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 5, 0x10) = 0xb7dd4000 mmap2(0xb7dd6000, 6144, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0xb7dd6000 close(5) = 0 munmap(0xb7dd8000, 59567) = 0 open("/lib/security/pam_cracklib.so", O_RDONLY) = 5 read(5, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0@\37\0\000"..., 512) = 512 fstat64(5, {st_mode=S_IFREG|0755, st_size=36712, ...}) = 0 mmap2(NULL, 64672, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 5, 0) = 0xb7db3000 mmap2(0xb7dbb000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 5, 0x8) = 0xb7dbb000 mmap2(0xb7dbc000, 27808, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0xb7dbc000 close(5) = 0 open("/lib/security/pam_limits.so", O_RDONLY) = 5 read(5, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\200\20"..., 512) = 512 fstat64(5, {st_mode=S_IFREG|0755, st_size=15972, ...}) = 0 mmap2(NULL, 18068, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 5, 0) = 0xb7dae000 mmap2(0xb7db2000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 5, 0x3) = 0xb7db2000 close(5) = 0 read(4, "", 131072) = 0 close(4) = 0 munmap(0xb7e09000, 131072) = 0 open("/etc/pam.d/other", O_RDONLY) = 4 fstat64(4, {st_mode=S_IFREG|0644, st_size=198, ...}) = 0 mmap2(NULL, 131072, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7e09000 read(4, "#%PAM-1.0\n\nauth required\t/"..., 131072) = 198 read(4, "", 131072) = 0 close(4) = 0 munmap(0xb7e09000, 131072) = 0 getuid32() = 0 socket(PF_FILE, SOCK_STREAM, 0) = 4 fcntl64(4, F_GETFL) = 0x2 (flags O_RDWR) fcntl64(4, F_SETFL, O_RDWR|O_NONBLOCK) = 0 connect(4, {sa_family=AF_FILE, path="/var/run/nscd/socket"}, 110) = 0 poll([{fd=4, events=POLLOUT|POLLERR|POLLHUP, revents=POLLOUT}], 1, 5000) = 1 writev(4, [{"\2\0\0\0\0\0\0\0\5\0\0\0", 12}, {"root\0", 5}], 2) = 17 poll([{fd=4, events=POLLIN|POLLERR|POLLHUP, revents=POLLIN|POLLHUP}], 1, 5000) = 1 read(4, "\2\0\0\0\1\0\0\0\5\0\0\0\2\0\0\0\0\0\0\0\0\0\0\0\5\0\0"..., 36) = 36 read(4, "root\0x\0root\0/root\0/bin/bash\0", 28) = 28 close(4) = 0 open("/etc/nsswitch.conf", O_RDONLY) = 4 fstat64(4, {st_mode=S_IFREG|0644, st_size=497, ...}) = 0 mmap2(NULL, 131072, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7e09000 read(4, "# /etc/nsswitch.conf:\n# $Header:"..., 131072) = 497 read(4, "", 131072) = 0 close(4) = 0 munmap(0xb7e09000, 131072) = 0 open("/etc/ld.so.cache", O_RDONLY) = 4 fstat64(4, {st_mode=S_IFREG|0644, st_size=59567, ...}) = 0 mmap2(NULL, 59567, PROT_READ, MAP_PRIVATE, 4, 0) = 0xb7e1a000 close(4) = 0 open("/lib/libnss_compat.so.2", O_RDONLY) = 4 read(4, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\300\20"..., 512) = 512 fstat64(4, {st_mode=S_IFREG|0755, st_size=31072, ...}) = 0 mmap2(NULL, 33392, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0xb7e11000 mprotect(0xb7e17000, 8816, PROT_NONE) = 0 mmap2(0xb7e18000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x6) = 0xb7e18000 close(4) = 0 munmap(0xb7e1a000, 59567) = 0 open("/etc/ld.so.cache", O_RDONLY) = 4 fstat64(4, {st_mode=S_IFREG|0644, st_size=59567, ...}) = 0 mmap2(NULL, 59567, PROT_READ, MAP_PRIVATE, 4, 0) = 0xb7e1a000 close(4) = 0 open("/lib/libnss_nis.so.2", O_RDONLY) = 4 read(4, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0p\34\0\000"..., 512) = 512 fstat64(4, {st_mode=S_IFREG|0755, st_size=35712, ...}) = 0 mmap2(NULL, 37416, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0xb7ddd000 mmap2(0xb7de5000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x7) = 0xb7de5000 close(4) = 0 open("/lib/libnss_files.so.2", O_RDONLY) = 4 read(4, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0@\33\0\000"..., 512) = 512 fstat64(4, {st_mode=S_IFREG|0755, st_size=35508, ...}) = 0 mmap2(NULL, 37512, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0xb7da4000 mmap2(0xb7dac000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x7) = 0xb7dac000 close(4) = 0 munmap(0xb7e1a000, 59567) = 0 open("/etc/shadow", O_RDONLY) = 4 fcntl64(4, F_GETFD) = 0 fcntl64(4, F_SETFD, FD_CLOEXEC) = 0 _llseek(4, 0, [0], SEEK_CUR) = 0 fstat64(4, {st_mode=S_IFREG|0600, st_size=551, ...}) = 0 mmap2(NULL, 551, PROT_READ, MAP_SHARED, 4, 0) = 0xb7e28000 _llseek(4, 551, [551], SEEK_SET) = 0 munmap(0xb7e28000, 551) = 0 close(4) = 0 time(NULL) = 1108059723 socket(PF_FILE, SOCK_STREAM, 0) = 4 fcntl64(4, F_GETFL) = 0x2 (flags O_RDWR) fcntl64(4, F_SETFL, O_RDWR|O_NONBLOCK) = 0 connect(4, {sa_family=AF_FILE, path="/var/run/nscd/socket"}, 110) = 0 poll([{fd=4, events=POLLOUT|POLLERR|POLLHUP, revents=POLLOUT}], 1, 5000) = 1 writev(4, [{"\2\0\0\0\0\0\0\0\6\0\0\0", 12}, {"dummy\0", 6}], 2) = 18 poll([{fd=4, events=POLLIN|POLLERR|POLLHUP, revents=POLLIN|POLLHUP}], 1, 5000) = 1 read(4, "\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\377\377\377\377"..., 36) = 36 close(4) = 0 socket(PF_FILE, SOCK_STREAM, 0) = 4 fcntl64(4, F_GETFL) = 0x2 (flags O_RDWR) fcntl64(4, F_SETFL, O_RDWR|O_NONBLOCK) = 0 connect(4, {sa_family=AF_FILE, path="/var/run/nscd/socket"}, 110) = 0 poll([{fd=4, events=POLLOUT|POLLERR|POLLHUP, revents=POLLOUT}], 1, 5000) = 1 writev(4, [{"\2\0\0\0\2\0\0\0\6\0\0\0", 12}, {"dummy\0", 6}], 2) = 18 poll([{fd=4, events=POLLIN|POLLERR|POLLHUP, revents=POLLIN|POLLHUP}], 1, 5000) = 1 read(4, "\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\377\377\0\0\0"..., 24) = 24 close(4) = 0 open("/etc/.pwd.lock", O_WRONLY|O_CREAT, 0600) = 4 fcntl64(4, F_GETFD) = 0 fcntl64(4, F_SETFD, FD_CLOEXEC) = 0 rt_sigaction(SIGALRM, {0xb7f49294, ~[], 0}, {SIG_DFL}, 8) = 0 rt_sigprocmask(SIG_UNBLOCK, [ALRM], [], 8) = 0 alarm(15) = 0 fcntl64(4, F_SETLKW, {type=F_WRLCK, whence=SEEK_SET, start=0, len=0}) = 0 alarm(0) = 15 rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0 rt_sigaction(SIGALRM, {SIG_DFL}, NULL, 8) = 0 getpid() = 31322 open("/etc/passwd.31322", O_WRONLY|O_CREAT|O_EXCL|O_LARGEFILE, 0600) = 5 write(5, "31322\0", 6) = 6 close(5) = 0 link("/etc/passwd.31322", "/etc/passwd.lock") = -1 EEXIST (File exists) open("/etc/passwd.lock", O_RDWR|O_LARGEFILE) = 5 read(5, "31300\0", 31) = 6 close(5) = 0 kill(31300, SIG_0) = -1 ESRCH (No such process) unlink("/etc/passwd.lock") = 0 link("/etc/passwd.31322", "/etc/passwd.lock") = 0 stat64("/etc/passwd.31322", {st_mode=S_IFREG|0600, st_size=6, ...}) = 0 unlink("/etc/passwd.31322") = 0 open("/etc/passwd", O_RDWR|O_LARGEFILE) = 5 fstat64(5, {st_mode=S_IFREG|0644, st_size=1939, ...}) = 0 mmap2(NULL, 131072, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7d84000 read(5, "root:x:0:0:root:/root:/bin/bash\n"..., 131072) = 1939 read(5, "", 131072) = 0 open("/etc/shadow.31322", O_WRONLY|O_CREAT|O_EXCL|O_LARGEFILE, 0600) = 6 write(6, "31322\0", 6) = 6 close(6) = 0 link("/etc/shadow.31322", "/etc/shadow.lock") = -1 EEXIST (File exists) open("/etc/shadow.lock", O_RDWR|O_LARGEFILE) = 6 read(6, "31300\0", 31) = 6 close(6) = 0 kill(31300, SIG_0) = -1 ESRCH (No such process) unlink("/etc/shadow.lock") = 0 link("/etc/shadow.31322", "/etc/shadow.lock") = 0 stat64("/etc/shadow.31322", {st_mode=S_IFREG|0600, st_size=6, ...}) = 0 unlink("/etc/shadow.31322") = 0 open("/etc/shadow", O_RDWR|O_LARGEFILE) = 6 fstat64(6, {st_mode=S_IFREG|0600, st_size=551, ...}) = 0 mmap2(NULL, 131072, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7d64000 read(6, "root:$1$.0hAIhNV$SgfYPwphfdxRgwB"..., 131072) = 551 read(6, "", 131072) = 0 open("/etc/login.defs", O_RDONLY|O_LARGEFILE) = 7 fstat64(7, {st_mode=S_IFREG|0644, st_size=3253, ...}) = 0 mmap2(NULL, 131072, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7d44000 read(7, "#\n# /etc/login.defs - Configurat"..., 131072) = 3253 read(7, "", 131072) = 0 close(7) = 0 munmap(0xb7d44000, 131072) = 0 open("/etc/passwd", O_RDONLY) = 7 fcntl64(7, F_GETFD) = 0 fcntl64(7, F_SETFD, FD_CLOEXEC) = 0 _llseek(7, 0, [0], SEEK_CUR) = 0 fstat64(7, {st_mode=S_IFREG|0644, st_size=1939, ...}) = 0 mmap2(NULL, 1939, PROT_READ, MAP_SHARED, 7, 0) = 0xb7d63000 _llseek(7, 1939, [1939], SEEK_SET) = 0 fstat64(7, {st_mode=S_IFREG|0644, st_size=1939, ...}) = 0 time(NULL) = 1108059723 time([1108059723]) = 1108059723 open("/etc/localtime", O_RDONLY) = 8 fstat64(8, {st_mode=S_IFREG|0644, st_size=1267, ...}) = 0 fstat64(8, {st_mode=S_IFREG|0644, st_size=1267, ...}) = 0 mmap2(NULL, 131072, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7d43000 read(8, "TZif\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\0\0\4\0"..., 131072) = 1267 close(8) = 0 munmap(0xb7d43000, 131072) = 0 open("/etc/localtime", O_RDONLY) = 8 fstat64(8, {st_mode=S_IFREG|0644, st_size=1267, ...}) = 0 close(8) = 0 open("/etc/localtime", O_RDONLY) = 8 fstat64(8, {st_mode=S_IFREG|0644, st_size=1267, ...}) = 0 close(8) = 0 open("/etc/localtime", O_RDONLY) = 8 fstat64(8, {st_mode=S_IFREG|0644, st_size=1267, ...}) = 0 close(8) = 0 rt_sigaction(SIGPIPE, {0xb7f407ad, [], 0}, {SIG_DFL}, 8) = 0 socket(PF_FILE, SOCK_DGRAM, 0) = 8 fcntl64(8, F_SETFD, FD_CLOEXEC) = 0 connect(8, {sa_family=AF_FILE, path="/dev/log"}, 16) = -1 EPROTOTYPE (Protocol wrong type for socket) close(8) = 0 socket(PF_FILE, SOCK_STREAM, 0) = 8 fcntl64(8, F_SETFD, FD_CLOEXEC) = 0 connect(8, {sa_family=AF_FILE, path="/dev/log"}, 16) = 0 send(8, "<86>Feb 10 13:22:03 useradd[3132"..., 111, 0) = 111 rt_sigaction(SIGPIPE, {SIG_DFL}, NULL, 8) = 0 socket(PF_FILE, SOCK_STREAM, 0) = 9 fcntl64(9, F_GETFL) = 0x2 (flags O_RDWR) fcntl64(9, F_SETFL, O_RDWR|O_NONBLOCK) = 0 connect(9, {sa_family=AF_FILE, path="/var/run/nscd/socket"}, 110) = 0 poll([{fd=9, events=POLLOUT|POLLERR|POLLHUP, revents=POLLOUT}], 1, 5000) = 1 writev(9, [{"\2\0\0\0\1\0\0\0\5\0\0\0", 12}, {"1001\0", 5}], 2) = 17 poll([{fd=9, events=POLLIN|POLLERR|POLLHUP, revents=POLLIN|POLLHUP}], 1, 5000) = 1 read(9, "\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\377\377\377\377"..., 36) = 36 close(9) = 0 open("/var/log/faillog", O_RDWR|O_LARGEFILE) = -1 ENOENT (No such file or directory) open("/var/log/lastlog", O_RDWR|O_LARGEFILE) = 9 _llseek(9, 292292, [292292], SEEK_SET) = 0 write(9, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., 292) = 292 close(9) = 0 socket(PF_FILE, SOCK_STREAM, 0) = 9 connect(9, {sa_family=AF_FILE, path="/var/run/nscd/socket"}, 110) = 0 write(9, "\2\0\0\0\n\0\0\0\7\0\0\0", 12) = 12 write(9, "passwd\0", 7) = -1 EPIPE (Broken pipe) --- SIGPIPE (Broken pipe) @ 0 (0) --- +++ killed by SIGPIPE +++