store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Fri May 24, 2013 7:54 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 44 posts ]  Go to page 1, 2, 3  Next
Author Message
 Post subject: Thousands of asl-shun.pl processes
Unread postPosted: Wed Aug 10, 2011 2:58 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
I believe this isn't normal:

Code:
# ps x | grep asl-shun\.pl | grep -c add
1331
# ps x | grep asl-shun\.pl | grep -c delete
927


That's over 2000 instances of asl-shun.pl in a process listing. I went and killed them before, but they came back...

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject: Re: Thousands of asl-shun.pl processes
Unread postPosted: Thu Aug 11, 2011 4:58 am 
Offline
Forum Regular
Forum Regular

Joined: Thu Oct 26, 2006 11:56 pm
Posts: 665
Hi Breun,

That is weird.. Does it change hour to hour?

Have you looked in the CP to see if its an attack or something?

Cheers


Top
 Profile  
 
 Post subject: Re: Thousands of asl-shun.pl processes
Unread postPosted: Thu Aug 11, 2011 5:34 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
We see the number of asl-shun.pl processes build up continuously. It seems that all those processes are waiting for a lock. With thousands of them not much seems to go through and in the end the server runs out of memory. As a temporary workaround we configured the following to run hourly:

Code:
killall --quiet --user root --signal KILL asl-shun.pl


But we'd rather have a real solution of course...

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject: Re: Thousands of asl-shun.pl processes
Unread postPosted: Thu Aug 11, 2011 9:50 am 
Offline
New Forum User
New Forum User

Joined: Thu Aug 11, 2011 3:22 am
Posts: 3
Location: Stockholm
We had the same problem, at the same time we had a lot of IPs blocked in iptables, killing the asl-shun.pl processes and changed the $standard_time to 5 min and increasing number of open files seem to have solved it.


Top
 Profile  
 
 Post subject: Re: Thousands of asl-shun.pl processes
Unread postPosted: Thu Aug 11, 2011 2:08 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
What $standard_time are you talking about exactly?

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject: Re: Thousands of asl-shun.pl processes
Unread postPosted: Fri Aug 12, 2011 2:45 pm 
Offline
Forum User
Forum User

Joined: Mon Dec 20, 2004 2:43 am
Posts: 67
Yip, we also have this problem since yesterday.

The logs are also filled with this on various ports and ID's:

clamd[29095]: stream(127.0.0.1@1135): Suspect.Bredozip-zippwd-10 FOUND


Last edited by ryanz on Fri Aug 12, 2011 3:03 pm, edited 1 time in total.

Top
 Profile  
 
 Post subject: Re: Thousands of asl-shun.pl processes
Unread postPosted: Fri Aug 12, 2011 2:49 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3249
Location: Chantilly, VA
Are you restarting ossec-hids? And is this on a VPS or a dedicated system?

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Thousands of asl-shun.pl processes
Unread postPosted: Fri Aug 12, 2011 3:05 pm 
Offline
Forum User
Forum User

Joined: Mon Dec 20, 2004 2:43 am
Posts: 67
We are running this as part of Plesk on Xen VPS's
We have restarted ossec-hids but it keeps happening.

The logs are also filled with this on various ports and ID's:

clamd[29095]: stream(127.0.0.1@1135): Suspect.Bredozip-zippwd-10 FOUND


Top
 Profile  
 
 Post subject: Re: Thousands of asl-shun.pl processes
Unread postPosted: Fri Aug 12, 2011 3:20 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3249
Location: Chantilly, VA
Quote:
We have restarted ossec-hids but it keeps happening.


No, don't do that, thats what causes it. When you restart the HIDS, it has no state anymore and will reload all the shuns. You should never restart the HIDS or need to do so, even ASL won't restart it. Theres no need.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Thousands of asl-shun.pl processes
Unread postPosted: Fri Aug 12, 2011 3:29 pm 
Offline
Forum User
Forum User

Joined: Mon Dec 20, 2004 2:43 am
Posts: 67
Mike,

We've had this problem for 18 hours now and we only restarted ossec-hids in the past 2 hours but there was no change.

The only thing that helped was to kill the processes like Breun indicated almost every hour, and we were forced to reboot at a time today as the servers simply couldn't run with thousands of these asl-shun.pl processes.


Top
 Profile  
 
 Post subject: Re: Thousands of asl-shun.pl processes
Unread postPosted: Fri Aug 12, 2011 3:32 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3249
Location: Chantilly, VA
Can you check to make sure you have all your asl components up to date by running a yum upgrade, followed by an asl -s -f? And what event(s) are triggering the shuns? You can tell by looking at the ASL GUI under blocking, and that will tell you the event ID and signature ID. You can also check the ossec logs which will also tell you this.

Its possible you may be getting hammered with attacks too, so lets see if we can figure out what security events are triggering shuns.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Thousands of asl-shun.pl processes
Unread postPosted: Fri Aug 12, 2011 3:40 pm 
Offline
Forum User
Forum User

Joined: Mon Dec 20, 2004 2:43 am
Posts: 67
That was one of the first things we did this morning.
We ran asl -u and asl -s -f this morning, in fact a few times today.

We've been running ASL 3.0.x for a while and a check shows 3.0.6
ClamAV is updated and we also ran freshclam manually.


Top
 Profile  
 
 Post subject: Re: Thousands of asl-shun.pl processes
Unread postPosted: Fri Aug 12, 2011 3:42 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3249
Location: Chantilly, VA
And yum upgrade, what does that show?

Also, do the shuns complete? (How long lived are these processes)

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Thousands of asl-shun.pl processes
Unread postPosted: Fri Aug 12, 2011 3:52 pm 
Offline
Forum User
Forum User

Joined: Mon Dec 20, 2004 2:43 am
Posts: 67
yum check-update has a few to do but all the asl updates are done regularly.

The only things not updated are the asl kernel updates as we find these give problems with booting and the atomic spamassassin update cause issues with 4psa Spamguardian.

Since the last delete almost a hour ago most asl-shun.pl processes show 0sec with a few 1 to 3 sec.
I must also add that it's now 22h00 here and the servers are running very low access and load so there are much less shuns running compared to during the day when the access is high.


Top
 Profile  
 
 Post subject: Re: Thousands of asl-shun.pl processes
Unread postPosted: Fri Aug 12, 2011 5:34 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3249
Location: Chantilly, VA
What kinds of events are triggering the shuns?

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 44 posts ]  Go to page 1, 2, 3  Next

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Bing [Bot], Google [Bot] and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group