Gentoo Archives: gentoo-hardened

From: Steve Buzonas <steve.buzonas@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] pax, core2duo, suspicious activity
Date: Thu, 07 Feb 2008 01:09:24
Message-Id: 393d27ee0802061709p7198b128q26c72c7cf464512f@mail.gmail.com
In Reply to: Re: [gentoo-hardened] pax, core2duo, suspicious activity by brant williams
1 On Feb 6, 2008 8:57 AM, brant williams <brant@×××××.net> wrote:
2
3 > -----BEGIN PGP SIGNED MESSAGE-----
4 > Hash: SHA256
5 >
6 >
7 > Hi paxguy =)
8 >
9 > I experienced the same issue after upgrading to
10 > hardened-sources-2.6.23-r4 this past weekend. Previously, I'd been using
11 > hardened-sources-2.6.22-r8 for ~30 days with no discernable problems.
12 > After checking both config files, though, it looks like I may have rushed
13 > through too quickly (sdiff attached).
14 >
15 > I've got a screenshot of the log entry that occurred right before the
16 > crash (png attached), and can provide the System.map and kernel image to
17 > you off-list if that would help.
18 >
19 > Thank you for your efforts.
20 >
21 >
22 > brant williams
23 > FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002
24 >
25 >
26 >
27 > On Wed, 6 Feb 2008, pageexec@××××××××.hu wrote:
28 >
29 > > Date: Wed, 06 Feb 2008 13:49:12 +0200
30 > > From: pageexec@××××××××.hu
31 > > Reply-To: gentoo-hardened@l.g.o
32 > > To: gentoo-hardened@l.g.o
33 > > Subject: Re: [gentoo-hardened] pax, core2duo, suspicious activity
34 > >
35 > > On 6 Feb 2008 at 10:24, wrote:
36 > >
37 > >> SSH session droped, all daemons stopping too. On the monitor a get
38 > >> "Suspicious activity.... bla-bla PaX... bla-bla...
39 > >
40 > > can you post the precise message? even a screenshot would be fine
41 > > (try to boot with a high resolution frame buffer mode to get as much
42 > > info as you can). also i'll need the System.map file and probably
43 > > vmlinux as well.
44 > >
45 > >> When I recompile kernel without PaX, system works normal withouts
46 > >> kernel-panics.
47 > >
48 > > did you determine which PaX feature triggers the problem?
49 > >
50 > > also, would be nice if you could try out the 2.6.24 test patch.
51 > >
52 > > PS: if you enable HIGHMEM64G/PAGEEXEC then PaX will make use of
53 > > the NX bit.
54 > >
55 > > --
56 > > gentoo-hardened@l.g.o mailing list
57 > >
58 > >
59 > -----BEGIN PGP SIGNATURE-----
60 > Version: GnuPG v2.0.7 (GNU/Linux)
61 >
62 > iD8DBQFHqbzkdCBnhE3rYAIRCBqGAKCdKtGnYzyj2SD3AefLY4w+zeQD1wCfZDra
63 > WPNDEB3qSwPK2N4Vfy3spwg=
64 > =kVu0
65 > -----END PGP SIGNATURE-----
66
67
68 What occurs before the crash? Can you do strace? Does emerge-webrsync
69 work?
70
71 --
72 Thank you,
73
74 Steve Buzonas Jr.

Replies

Subject Author
Re: [gentoo-hardened] pax, core2duo, suspicious activity "Алексей Лесовский" <d4@×××××××××.ru>
Re: [gentoo-hardened] pax, core2duo, suspicious activity brant williams <brant@×××××.net>