store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Sun May 19, 2013 11:51 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 5 posts ] 
Author Message
 Post subject: FW_TOR = on
Unread postPosted: Sun Aug 05, 2012 10:04 am 
Offline
Forum User
Forum User

Joined: Wed Jul 04, 2012 7:44 am
Posts: 13
Location: Costa Rica
Hello,

I'm new to ASL so I'm trying to learn and fine tune ASL as quick as possible.

I turned FW_TOR to 'on' on the ASL configuration and some of the websites using MySQL stopped working.
I started getting this message in the "Security Events" window.

iwx1 suhosin[8877]: ALERT - linked list corrupt on efree() - heap corruption detected (attacker `201.199.xx.xx`, file `/home/crphotos/mydomain.com/html/new/gallery3/index.php`)

IP '201.199.xx.xx' is from my local PC

What does the TOR list have to do with this?
Why does it affect MySQL connections?
I thought suhosin was not part of ASL

If somebody can shed some light on this, it would be very much appreciated

Thanks,

Rodrigo
CRServers.com


Top
 Profile  
 
 Post subject: Re: FW_TOR = on
Unread postPosted: Sun Aug 05, 2012 12:12 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3243
Location: Chantilly, VA
Suhosin is not part of Asl and is not installed by Asl.

FW_TOR just adds firewall rules to block TOR exit nodes, it does not do anything else. That suhosin alert is something unrelated to Asl, but suhosin is blocking your ip so that's definitely causing you problems.

FW_TOR also has nothing to do with MySQL.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: FW_TOR = on
Unread postPosted: Sun Aug 05, 2012 12:24 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1844
I don't know how many IPs get added when you enable that, but it might be more than your system can handle, and causing something strange to happen that suhosin doesn't like?

Maybe take a look at iptables -v -n -L | less to see if anything loks odd or if there are any errors when you do a service iptables status

You can enable suhosin's log only mode on in /etc/php.d/suhosin.conf. The logs will still appear, but nothing will be blocked by suhosin itself (but ASL - ossec may blacklist the "attacking" IP).

Maybe suhosin was installed accidentally, for example if you did a yum install php php-* as php-suhosin is in the ART repo.

Faris.

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: FW_TOR = on
Unread postPosted: Sun Aug 05, 2012 1:07 pm 
Offline
Forum User
Forum User

Joined: Wed Jul 04, 2012 7:44 am
Posts: 13
Location: Costa Rica
Hello,

I have never installed suhosin voluntarily.

But indeed there is suhosin in my system:

[root@iwx1 ~]# rpm -qa | grep suhosin
php-xmlrpc-5.2.17-rhe5x.iworx.js.suhosin.fpm.200
php-gd-5.2.17-rhe5x.iworx.js.suhosin.fpm.200
php-mcrypt-5.2.17-rhe5x.iworx.js.suhosin.fpm.200
php-pdo-5.2.17-rhe5x.iworx.js.suhosin.fpm.200
php-5.2.17-rhe5x.iworx.js.suhosin.fpm.200
php-soap-5.2.17-rhe5x.iworx.js.suhosin.fpm.200
php-cli-5.2.17-rhe5x.iworx.js.suhosin.fpm.200
php-devel-5.2.17-rhe5x.iworx.js.suhosin.fpm.200
php-imap-5.2.17-rhe5x.iworx.js.suhosin.fpm.200
php-xml-5.2.17-rhe5x.iworx.js.suhosin.fpm.200
php-mysql-5.2.17-rhe5x.iworx.js.suhosin.fpm.200
php-mbstring-5.2.17-rhe5x.iworx.js.suhosin.fpm.200
php-common-5.2.17-rhe5x.iworx.js.suhosin.fpm.200

I wonder if this gets installed by Interworx. I will ask them.

Anyway, what does enabling TOR node blockage in ASL have to do with MySQL not connecting or suhosin?
After turning TOR blockage off again, the event disappeared, and MySQL conections started working again.

Regards,

Rodrigo


Last edited by CRServers on Sun Aug 05, 2012 1:31 pm, edited 1 time in total.

Top
 Profile  
 
 Post subject: Re: FW_TOR = on
Unread postPosted: Sun Aug 05, 2012 1:15 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3243
Location: Chantilly, VA
Quote:
Anyway, what does enabling TOR node blockage in ASL have to do with MySQL not connecting or suhosin?


Nothing, it does not install, configure or do anything with suhosin (suhosin is not part of Asl, Asl does not install it, and can not do so), and has nothing to do with MySQL either. Blocking TOR nodes just adds external firewall rules to block TOR exit nodes.

I recommend you remove suhosin from your system to see if that resolves this for you.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 5 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Google [Bot] and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group