Gentoo Archives: gentoo-hardened

From: brant williams <brant@×××××.net>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] pax, core2duo, suspicious activity
Date: Wed, 06 Feb 2008 13:58:13
Message-Id: Pine.LNX.4.64.0802060718550.29027@nerv.tnarb.net
In Reply to: Re: [gentoo-hardened] pax, core2duo, suspicious activity by pageexec@freemail.hu
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA256
3
4
5 Hi paxguy =)
6
7 I experienced the same issue after upgrading to
8 hardened-sources-2.6.23-r4 this past weekend. Previously, I'd been using
9 hardened-sources-2.6.22-r8 for ~30 days with no discernable problems.
10 After checking both config files, though, it looks like I may have rushed
11 through too quickly (sdiff attached).
12
13 I've got a screenshot of the log entry that occurred right before the
14 crash (png attached), and can provide the System.map and kernel image to
15 you off-list if that would help.
16
17 Thank you for your efforts.
18
19
20 brant williams
21 FCAA CDCA 20BC 3925 D634 F5C4 7420 6784 4DEB 6002
22
23
24
25 On Wed, 6 Feb 2008, pageexec@××××××××.hu wrote:
26
27 > Date: Wed, 06 Feb 2008 13:49:12 +0200
28 > From: pageexec@××××××××.hu
29 > Reply-To: gentoo-hardened@l.g.o
30 > To: gentoo-hardened@l.g.o
31 > Subject: Re: [gentoo-hardened] pax, core2duo, suspicious activity
32 >
33 > On 6 Feb 2008 at 10:24, wrote:
34 >
35 >> SSH session droped, all daemons stopping too. On the monitor a get
36 >> "Suspicious activity.... bla-bla PaX... bla-bla...
37 >
38 > can you post the precise message? even a screenshot would be fine
39 > (try to boot with a high resolution frame buffer mode to get as much
40 > info as you can). also i'll need the System.map file and probably
41 > vmlinux as well.
42 >
43 >> When I recompile kernel without PaX, system works normal withouts
44 >> kernel-panics.
45 >
46 > did you determine which PaX feature triggers the problem?
47 >
48 > also, would be nice if you could try out the 2.6.24 test patch.
49 >
50 > PS: if you enable HIGHMEM64G/PAGEEXEC then PaX will make use of
51 > the NX bit.
52 >
53 > --
54 > gentoo-hardened@l.g.o mailing list
55 >
56 >
57 -----BEGIN PGP SIGNATURE-----
58 Version: GnuPG v2.0.7 (GNU/Linux)
59
60 iD8DBQFHqbzkdCBnhE3rYAIRCBqGAKCdKtGnYzyj2SD3AefLY4w+zeQD1wCfZDra
61 WPNDEB3qSwPK2N4Vfy3spwg=
62 =kVu0
63 -----END PGP SIGNATURE-----

Attachments

File name MIME type
configdiffs.txt text/plain
nervPAXcrash2.png image/png

Replies

Subject Author
Re: [gentoo-hardened] pax, core2duo, suspicious activity brant williams <brant@×××××.net>
Re: [gentoo-hardened] pax, core2duo, suspicious activity pageexec@××××××××.hu
Re: [gentoo-hardened] pax, core2duo, suspicious activity Steve Buzonas <steve.buzonas@×××××.com>
Re: [gentoo-hardened] pax, core2duo, suspicious activity "Алексей Лесовский" <d4@×××××××××.ru>