27 Sep 14:41
what RLIMIT_STACK mean?
From: Alex Efros <powerman@...>
Subject: what RLIMIT_STACK mean?
Newsgroups: gmane.linux.gentoo.hardened
Date: 2008-09-27 12:42:33 GMT
Subject: what RLIMIT_STACK mean?
Newsgroups: gmane.linux.gentoo.hardened
Date: 2008-09-27 12:42:33 GMT
Hi!
Can you please explain to me what these records in my logs mean?
2008-09-27_11:35:55.93144 kern.alert: grsec: From 78.53.3.223: denied
resource overstep by requesting 180883456 for RLIMIT_STACK against limit
8388608 for /bin/cat[cat:10111] uid/euid:81/81 gid/egid:81/81, parent
/usr/sbin/apache2[apache2:21930] uid/euid:81/81 gid/egid:81/81
2008-09-27_12:08:17.12634 kern.alert: grsec: denied resource overstep by
requesting 187367424 for RLIMIT_STACK against limit 8388608 for
/var/qmail/bin/qmail-local[qmail-local:22538] uid/euid:1000/1000
gid/egid:100/100, parent /var/qmail/bin/qmail-local[qmail-local:22535]
uid/euid:1000/1000 gid/egid:100/100
For example, first record may be result of malicious http request sent
from 78.53.3.223 to my apache... but I've no idea why /bin/cat was called
(I don't aware about cgi scripts on my server which will call /bin/cat)
and what went wrong with it. I'm not sure how this guess is correct...
Second is even more strange, because qmail-local was called by
qmail-local, there no "From IP" part in this record, so it looks like some
internal error on my server... but I never notice any troubles with qmail,
mail works ok and there no error in qmail log. Actually, here are records
from qmail log related to same time:
2008-09-27_12:08:17.07092 new msg 662104
2008-09-27_12:08:17.07093 info msg 662104: bytes 2912 from
<gentoo-hardened+bounces-2147-powerman=powerman.asdfgroup.com@...>
qp 22534 uid 201
(Continue reading)
RSS Feed