Gentoo Archives: gentoo-hardened

From: brant williams <brant@×××××.net>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] pax, core2duo, suspicious activity
Date: Wed, 06 Feb 2008 14:12:17
Message-Id: Pine.LNX.4.64.0802060810270.29618@nerv.tnarb.net
In Reply to: Re: [gentoo-hardened] pax, core2duo, suspicious activity by brant williams
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA256
3
4
5 Along with a similar post[1] from December, these all seem to be rsync
6 related...
7
8 [1] http://www.nabble.com/PAX%3A-suspicious-general-protection-fault-tt14133006.html
9
10
11 brant williams
12 FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002
13
14
15
16 On Wed, 6 Feb 2008, brant williams wrote:
17
18 > Date: Wed, 6 Feb 2008 07:57:49 -0600 (CST)
19 > From: brant williams <brant@×××××.net>
20 > Reply-To: gentoo-hardened@l.g.o
21 > To: gentoo-hardened@l.g.o
22 > Subject: Re: [gentoo-hardened] pax, core2duo, suspicious activity
23 >
24 > --[PinePGP]--------------------------------------------------[begin]--
25 >
26 > Hi paxguy =)
27 >
28 > I experienced the same issue after upgrading to
29 > hardened-sources-2.6.23-r4 this past weekend. Previously, I'd been using
30 > hardened-sources-2.6.22-r8 for ~30 days with no discernable problems.
31 > After checking both config files, though, it looks like I may have rushed
32 > through too quickly (sdiff attached).
33 >
34 > I've got a screenshot of the log entry that occurred right before the
35 > crash (png attached), and can provide the System.map and kernel image to
36 > you off-list if that would help.
37 >
38 > Thank you for your efforts.
39 >
40 >
41 > brant williams
42 > FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002
43 >
44 >
45 >
46 > On Wed, 6 Feb 2008, pageexec@××××××××.hu wrote:
47 >
48 >> Date: Wed, 06 Feb 2008 13:49:12 +0200
49 >> From: pageexec@××××××××.hu
50 >> Reply-To: gentoo-hardened@l.g.o
51 >> To: gentoo-hardened@l.g.o
52 >> Subject: Re: [gentoo-hardened] pax, core2duo, suspicious activity
53 >>
54 >> On 6 Feb 2008 at 10:24, wrote:
55 >>
56 >> > SSH session droped, all daemons stopping too. On the monitor a get
57 >> > "Suspicious activity.... bla-bla PaX... bla-bla...
58 >>
59 >> can you post the precise message? even a screenshot would be fine
60 >> (try to boot with a high resolution frame buffer mode to get as much
61 >> info as you can). also i'll need the System.map file and probably
62 >> vmlinux as well.
63 >>
64 >> > When I recompile kernel without PaX, system works normal withouts
65 >> > kernel-panics.
66 >>
67 >> did you determine which PaX feature triggers the problem?
68 >>
69 >> also, would be nice if you could try out the 2.6.24 test patch.
70 >>
71 >> PS: if you enable HIGHMEM64G/PAGEEXEC then PaX will make use of
72 >> the NX bit.
73 >>
74 >> --
75 >> gentoo-hardened@l.g.o mailing list
76 >>
77 >>
78 > --[PinePGP]-----------------------------------------------------------
79 > gpg: Signature made Wed Feb 6 07:57:56 2008 CST using DSA key ID 4DEB6002
80 > gpg: Good signature from "brant davin williams (never say anything)
81 > gpg: <brant@×××××.net>"
82 > --[PinePGP]----------------------------------------------------[end]--
83 >
84 >
85 -----BEGIN PGP SIGNATURE-----
86 Version: GnuPG v2.0.7 (GNU/Linux)
87
88 iD8DBQFHqcA2dCBnhE3rYAIRCJRtAJ9jnA4lPu5RAZfDgeWUExCOiBdGLgCgg5lg
89 tnDkLjGvR5TDF6f8GhVzvfM=
90 =hs9a
91 -----END PGP SIGNATURE-----
92 --
93 gentoo-hardened@l.g.o mailing list