Gentoo Archives: gentoo-hardened

From: "Алексей Лесовский" <d4@×××××××××.ru>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] pax, core2duo, suspicious activity
Date: Thu, 07 Feb 2008 04:35:55
Message-Id: 47AA8A0F.1050801@tp.kurgan.ru
In Reply to: Re: [gentoo-hardened] pax, core2duo, suspicious activity by brant williams
1 Hello Brant, yes, I see in console analog message, with your screenshot
2 of emerge.log
3 and with this words "PaX: suspicious general protection fault"
4
5 thanks for configdiffs
6
7
8 brant williams пишет:
9 > -----BEGIN PGP SIGNED MESSAGE-----
10 > Hash: SHA256
11 >
12 >
13 > Hi paxguy =)
14 >
15 > I experienced the same issue after upgrading to
16 > hardened-sources-2.6.23-r4 this past weekend. Previously, I'd been
17 > using hardened-sources-2.6.22-r8 for ~30 days with no discernable
18 > problems. After checking both config files, though, it looks like I
19 > may have rushed through too quickly (sdiff attached).
20 >
21 > I've got a screenshot of the log entry that occurred right before the
22 > crash (png attached), and can provide the System.map and kernel image
23 > to you off-list if that would help.
24 >
25 > Thank you for your efforts.
26 >
27 >
28 > brant williams
29 > FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002
30 >
31 >
32 >
33 > On Wed, 6 Feb 2008, pageexec@××××××××.hu wrote:
34 >
35 >> Date: Wed, 06 Feb 2008 13:49:12 +0200
36 >> From: pageexec@××××××××.hu
37 >> Reply-To: gentoo-hardened@l.g.o
38 >> To: gentoo-hardened@l.g.o
39 >> Subject: Re: [gentoo-hardened] pax, core2duo, suspicious activity
40 >>
41 >> On 6 Feb 2008 at 10:24, wrote:
42 >>
43 >>> SSH session droped, all daemons stopping too. On the monitor a get
44 >>> "Suspicious activity.... bla-bla PaX... bla-bla...
45 >>
46 >> can you post the precise message? even a screenshot would be fine
47 >> (try to boot with a high resolution frame buffer mode to get as much
48 >> info as you can). also i'll need the System.map file and probably
49 >> vmlinux as well.
50 >>
51 >>> When I recompile kernel without PaX, system works normal withouts
52 >>> kernel-panics.
53 >>
54 >> did you determine which PaX feature triggers the problem?
55 >>
56 >> also, would be nice if you could try out the 2.6.24 test patch.
57 >>
58 >> PS: if you enable HIGHMEM64G/PAGEEXEC then PaX will make use of
59 >> the NX bit.
60 >>
61 >> --
62 >> gentoo-hardened@l.g.o mailing list
63 >>
64 >>
65 > -----BEGIN PGP SIGNATURE-----
66 > Version: GnuPG v2.0.7 (GNU/Linux)
67 >
68 > iD8DBQFHqbzkdCBnhE3rYAIRCBqGAKCdKtGnYzyj2SD3AefLY4w+zeQD1wCfZDra
69 > WPNDEB3qSwPK2N4Vfy3spwg=
70 > =kVu0
71 > -----END PGP SIGNATURE-----
72 > ------------------------------------------------------------------------
73 >
74
75 --
76 gentoo-hardened@l.g.o mailing list