Gentoo Archives: gentoo-hardened

From: "Алексей Лесовский" <d4@×××××××××.ru>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] pax, core2duo, suspicious activity
Date: Thu, 07 Feb 2008 04:42:00
Message-Id: 47AA8B7C.7020704@tp.kurgan.ru
In Reply to: Re: [gentoo-hardened] pax, core2duo, suspicious activity by Steve Buzonas
1 system crashes unexpectedly, and can go down at any time.
2 strace can't do, i don't know what is this.
3 and webrsync fail too
4
5 Steve Buzonas пишет:
6 >
7 >
8 > On Feb 6, 2008 8:57 AM, brant williams <brant@×××××.net
9 > <mailto:brant@×××××.net>> wrote:
10 >
11 > -----BEGIN PGP SIGNED MESSAGE-----
12 > Hash: SHA256
13 >
14 >
15 > Hi paxguy =)
16 >
17 > I experienced the same issue after upgrading to
18 > hardened-sources-2.6.23-r4 this past weekend. Previously, I'd
19 > been using
20 > hardened-sources-2.6.22-r8 for ~30 days with no discernable problems.
21 > After checking both config files, though, it looks like I may have
22 > rushed
23 > through too quickly (sdiff attached).
24 >
25 > I've got a screenshot of the log entry that occurred right before the
26 > crash (png attached), and can provide the System.map and kernel
27 > image to
28 > you off-list if that would help.
29 >
30 > Thank you for your efforts.
31 >
32 >
33 > brant williams
34 > FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002
35 >
36 >
37 >
38 > On Wed, 6 Feb 2008, pageexec@××××××××.hu
39 > <mailto:pageexec@××××××××.hu> wrote:
40 >
41 > > Date: Wed, 06 Feb 2008 13:49:12 +0200
42 > > From: pageexec@××××××××.hu <mailto:pageexec@××××××××.hu>
43 > > Reply-To: gentoo-hardened@l.g.o
44 > <mailto:gentoo-hardened@l.g.o>
45 > > To: gentoo-hardened@l.g.o
46 > <mailto:gentoo-hardened@l.g.o>
47 > > Subject: Re: [gentoo-hardened] pax, core2duo, suspicious activity
48 > >
49 > > On 6 Feb 2008 at 10:24, wrote:
50 > >
51 > >> SSH session droped, all daemons stopping too. On the monitor a get
52 > >> "Suspicious activity.... bla-bla PaX... bla-bla...
53 > >
54 > > can you post the precise message? even a screenshot would be fine
55 > > (try to boot with a high resolution frame buffer mode to get as much
56 > > info as you can). also i'll need the System.map file and probably
57 > > vmlinux as well.
58 > >
59 > >> When I recompile kernel without PaX, system works normal withouts
60 > >> kernel-panics.
61 > >
62 > > did you determine which PaX feature triggers the problem?
63 > >
64 > > also, would be nice if you could try out the 2.6.24 test patch.
65 > >
66 > > PS: if you enable HIGHMEM64G/PAGEEXEC then PaX will make use of
67 > > the NX bit.
68 > >
69 > > --
70 > > gentoo-hardened@l.g.o
71 > <mailto:gentoo-hardened@l.g.o> mailing list
72 > >
73 > >
74 > -----BEGIN PGP SIGNATURE-----
75 > Version: GnuPG v2.0.7 (GNU/Linux)
76 >
77 > iD8DBQFHqbzkdCBnhE3rYAIRCBqGAKCdKtGnYzyj2SD3AefLY4w+zeQD1wCfZDra
78 > WPNDEB3qSwPK2N4Vfy3spwg=
79 > =kVu0
80 > -----END PGP SIGNATURE-----
81 >
82 >
83 > What occurs before the crash? Can you do strace? Does
84 > emerge-webrsync work?
85 >
86 > --
87 > Thank you,
88 >
89 > Steve Buzonas Jr.
90
91 --
92 gentoo-hardened@l.g.o mailing list