niXforums Forum Index
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   PreferencesPreferences   Log in to check your private messagesLog in to check your private messages   Log inLog in 
·  nixdoc.net ·  man pages ·  Linux HOWTOs ·  FreeBSD Tips ·  Forums
navigation Forum index » *nix » Tru64 » Tru64 managers mail-list
SUMMARY: Something su-ing fron root to root a lot
Post new topic   Reply to topic Page 1 of 1 [1 Post] View previous topic :: View next topic
Author Message
Tarasyuk Nik
*nix forums beginner


Joined: 05 May 2002
Posts: 4

PostPosted: Sun May 05, 2002 9:13 pm    Post subject: SUMMARY: Something su-ing fron root to root a lot Reply with quote

Hi Managers

A lot of thanks to Denise Dumas, John Ferlan, Oisin McGuinness, Ann Majeske, and Jim Belonis.

These are the suggestions that were given
1. set up audit subsystem
2. remove sialog - it's used only for debugging
3. look at cron jobs and rc3.d scripts, something might have been failing and retrying.
4. check auth.log

The problem was fixed thanks to Dr. Watson who has noticed that
one of very usefull services on remote server 100 miles away doesn't work.

That service was using little server program running on our ill server here.
So we have checked this server program and discovered that
its start-up script has a plain error in it.
Instead of calling the actual executable, it was calling itself over and over again.
The problem come up because we have rebooted server first time in a year.

So good old good luck helped us this time,
I wonder if audit subsystem could have tracked down the guilty service
if having been set up.
If yes, it might be something worth doing.

Good luck to everyone.

Nik Tarasyuk
Software Engineer
Snowy Hydro
Australia



-----Original Message-----
/var on one our servers got filled up.

The culprit was sialog, which was full of "Successful authentication for su from root to root" messages.
We cleaned the log, it started to grow again fast.

We've done reboot, it did NOT help.

CPU's idle time is zero, top shows that no specific process takes CPU time, but
CPU system time is high.

iowait is exremely high, network utilization is low, disk utilization is high.

So, some process does hundreds of su's per second, and it's logged by sialogd.

How to find out which one?

We are running 4.0f kit 4 on ES40.
Back to top
Google

Back to top
Display posts from previous:   
Post new topic   Reply to topic Page 1 of 1 [1 Post] View previous topic :: View next topic
The time now is Fri Jan 09, 2009 9:48 am | All times are GMT
navigation Forum index » *nix » Tru64 » Tru64 managers mail-list
Jump to:  

Similar Topics
Topic Author Forum Replies Last Post
No new posts Root relay issue Johnson, S Postfix 4 Thu Jul 20, 2006 6:50 pm
No new posts Weekly Python Patch/Bug Summary Kurt B. Kaiser python 0 Thu Jul 20, 2006 4:55 am
No new posts root can't change owner wizzywiz Suse 3 Wed Jul 19, 2006 5:55 am
No new posts root kits on linux Spoken4 Suse 10 Sun Jul 16, 2006 3:15 am
No new posts access root privileges through C program yoda.techies@gmail.com security 9 Fri Jul 14, 2006 12:12 pm

MPAA | Debt Consolidation | WoW Gold | Debt Help | Online advertising
Copyright © 2004-2005 DeniX Solutions SRL
 
Other DeniX Solutions sites: Unix/Linux blog |  electronics forum |  medicine forum |  science forum | 
Privacy Policy


Powered by phpBB © 2001, 2005 phpBB Group
[ Time: 0.1345s ][ Queries: 16 (0.0696s) ][ GZIP on - Debug on ]