read(4, "230\tPASSV\t2\t********\tuser=*****\ts"..., 520) = 149 stat64("/etc/pam.d", {st_mode=S_IFDIR|0755, st_size=1168, ...}) = 0 open("/etc/pam.d/pop3", O_RDONLY|O_LARGEFILE) = 10 fstat64(10, {st_mode=S_IFREG|0644, st_size=362, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x4fc14000 read(10, "# Provided by mailbase (dont remo"..., 4096) = 362 open("/lib/security/pam_nologin.so", O_RDONLY) = 11 read(11, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\340\6\0\0004\0\0\0\254"..., 512) = 512 fstat64(11, {st_mode=S_IFREG|0755, st_size=5188, ...}) = 0 mmap2(NULL, 8204, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 11, 0) = 0x4fc11000 mmap2(0x4fc12000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 11, 0) = 0x4fc12000 close(11) = 0 mprotect(0x4fc12000, 4096, PROT_READ) = 0 open("/etc/pam.d/system-auth", O_RDONLY|O_LARGEFILE) = 11 fstat64(11, {st_mode=S_IFREG|0644, st_size=465, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x4fc10000 read(11, "auth\t\trequired\tpam_env.so \nauth\t\t"..., 4096) = 465 open("/lib/security/pam_env.so", O_RDONLY) = 12 read(12, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\300\10\0\0004\0\0\0\260"..., 512) = 512 fstat64(12, {st_mode=S_IFREG|0755, st_size=13384, ...}) = 0 mmap2(NULL, 16400, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 12, 0) = 0x4f614000 mmap2(0x4f617000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 12, 0x2) = 0x4f617000 close(12) = 0 mprotect(0x4f617000, 4096, PROT_READ) = 0 open("/lib/security/pam_ssh.so", O_RDONLY) = 12 read(12, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\240:\0\0004\0\0\0\4"..., 512) = 512 fstat64(12, {st_mode=S_IFREG|0755, st_size=79772, ...}) = 0 mmap2(NULL, 83044, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 12, 0) = 0x4f5ff000 mmap2(0x4f612000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 12, 0x12) = 0x4f612000 close(12) = 0 mprotect(0x4f612000, 4096, PROT_READ) = 0 open("/lib/security/pam_unix.so", O_RDONLY) = 12 read(12, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0@\36\0\0004\0\0\0t"..., 512) = 512 fstat64(12, {st_mode=S_IFREG|0755, st_size=50484, ...}) = 0 mmap2(NULL, 98592, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 12, 0) = 0x4f5e6000 mmap2(0x4f5f1000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 12, 0xb) = 0x4f5f1000 mmap2(0x4f5f3000, 45344, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x4f5f3000 close(12) = 0 mprotect(0x4f5f1000, 4096, PROT_READ) = 0 read(11, ""..., 4096) = 0 close(11) = 0 munmap(0x4fc10000, 4096) = 0 open("/etc/pam.d/system-auth", O_RDONLY|O_LARGEFILE) = 11 fstat64(11, {st_mode=S_IFREG|0644, st_size=465, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x4fc10000 read(11, "auth\t\trequired\tpam_env.so \nauth\t\t"..., 4096) = 465 read(11, ""..., 4096) = 0 close(11) = 0 munmap(0x4fc10000, 4096) = 0 open("/etc/pam.d/system-auth", O_RDONLY|O_LARGEFILE) = 11 fstat64(11, {st_mode=S_IFREG|0644, st_size=465, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x4fc10000 read(11, "auth\t\trequired\tpam_env.so \nauth\t\t"..., 4096) = 465 open("/lib/security/pam_limits.so", O_RDONLY) = 12 read(12, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\0\r\0\0004\0\0\0\310"..., 512) = 512 fstat64(12, {st_mode=S_IFREG|0755, st_size=13408, ...}) = 0 mmap2(NULL, 16424, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 12, 0) = 0x4f5e1000 mmap2(0x4f5e4000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 12, 0x2) = 0x4f5e4000 close(12) = 0 mprotect(0x4f5e4000, 4096, PROT_READ) = 0 open("/lib/security/pam_permit.so", O_RDONLY) = 12 read(12, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\20\5\0\0004\0\0\0\254"..., 512) = 512 fstat64(12, {st_mode=S_IFREG|0755, st_size=5188, ...}) = 0 mmap2(NULL, 8204, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 12, 0) = 0x4fc0d000 mmap2(0x4fc0e000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 12, 0) = 0x4fc0e000 close(12) = 0 mprotect(0x4fc0e000, 4096, PROT_READ) = 0 read(11, ""..., 4096) = 0 close(11) = 0 munmap(0x4fc10000, 4096) = 0 read(10, ""..., 4096) = 0 close(10) = 0 munmap(0x4fc14000, 4096) = 0 open("/etc/pam.d/other", O_RDONLY|O_LARGEFILE) = 10 fstat64(10, {st_mode=S_IFREG|0644, st_size=128, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x4fc14000 read(10, "auth required\tpam_deny.so\na"..., 4096) = 128 open("/lib/security/pam_deny.so", O_RDONLY) = 11 read(11, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0p\4\0\0004\0\0\0\254"..., 512) = 512 fstat64(11, {st_mode=S_IFREG|0755, st_size=5188, ...}) = 0 mmap2(NULL, 8204, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 11, 0) = 0x4f5de000 mmap2(0x4f5df000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 11, 0) = 0x4f5df000 close(11) = 0 mprotect(0x4f5df000, 4096, PROT_READ) = 0 read(10, ""..., 4096) = 0 close(10) = 0 munmap(0x4fc14000, 4096) = 0 time(NULL) = 1245575268 open("/etc/nologin", O_RDONLY|O_LARGEFILE) = -1 ENOENT (No such file or directory) socket(PF_FILE, SOCK_STREAM, 0) = 10 fcntl64(10, F_SETFL, O_RDWR|O_NONBLOCK) = 0 connect(10, {sa_family=AF_FILE, path="/var/run/nscd/socket"...}, 110) = 0 send(10, "\2\0\0\0\0\0\0\0\6\0\0\0*****\0"..., 18, MSG_NOSIGNAL) = 18 poll([{fd=10, events=POLLIN|POLLERR|POLLHUP}], 1, 5000) = 1 ([{fd=10, revents=POLLIN|POLLHUP}]) read(10, "\2\0\0\0\1\0\0\0\6\0\0\0\2\0\0\0\350\3\0\0\371\3\0\0\v\0\0\0\f\0\0\0\n"..., 36) = 36 read(10, "*****\0x\0Kai Krakow\0/home/*****\0/b"..., 41) = 41 close(10) = 0 geteuid32() = 0 mmap2(NULL, 266240, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x4f59d000 geteuid32() = 0 getegid32() = 0 getgroups32(65536, [0]) = 1 open("/proc/sys/kernel/ngroups_max", O_RDONLY) = 10 read(10, "65536\n"..., 31) = 6 close(10) = 0 socket(PF_FILE, SOCK_STREAM, 0) = 10 fcntl64(10, F_SETFL, O_RDWR|O_NONBLOCK) = 0 connect(10, {sa_family=AF_FILE, path="/var/run/nscd/socket"...}, 110) = 0 send(10, "\2\0\0\0\17\0\0\0\6\0\0\0*****\0"..., 18, MSG_NOSIGNAL) = 18 poll([{fd=10, events=POLLIN|POLLERR|POLLHUP}], 1, 5000) = 1 ([{fd=10, revents=POLLIN|POLLHUP}]) read(10, "\2\0\0\0\1\0\0\0\n\0\0\0"..., 12) = 12 read(10, "\371\3\0\0\5\0\0\0\n\0\0\0\20\0\0\0d\0\0\0\372\0\0\0\355\3\0\0\361\3\0\0\364"..., 40) = 40 close(10) = 0 setgroups32(10, [1017, 5, 10, 16, 100, 250, 1005, 1009, 1012, 1016]) = 0 setresgid32(-1, 1017, -1) = 0 setresuid32(-1, 1000, -1) = 0 open("/home/*****/.ssh/id_dsa", O_RDONLY) = -1 ENOENT (No such file or directory) open("/home/*****/.ssh/id_dsa", O_RDONLY) = -1 ENOENT (No such file or directory) open("/home/*****/.ssh/id_rsa", O_RDONLY) = 10 fstat64(10, {st_mode=S_IFREG|0600, st_size=1675, ...}) = 0 getuid32() = 0 fstat64(10, {st_mode=S_IFREG|0600, st_size=1675, ...}) = 0 read(10, "-----BEGIN RSA PRIVATE KEY-----\nM"..., 1675) = 1675 --- SIGSEGV (Segmentation fault) @ 0 (0) ---