offline
- Pridružio: 03 Dec 2003
- Poruke: 677
- Gde živiš: Beograd
|
8266 open("/etc/passwd", O_RDONLY) = 4
8266 fcntl64(4, F_GETFD) = 0
8266 fcntl64(4, F_SETFD, FD_CLOEXEC) = 0
8266 _llseek(4, 0, [0], SEEK_CUR) = 0
8266 fstat64(4, {st_mode=S_IFREG|0600, st_size=5058, ...}) = 0
8266 mmap2(NULL, 5058, PROT_READ, MAP_SHARED, 4, 0) = 0x4001a000
8266 _llseek(4, 5058, [5058], SEEK_SET) = 0
8266 fstat64(4, {st_mode=S_IFREG|0600, st_size=5058, ...}) = 0
8266 munmap(0x4001a000, 5058-) = 0
8266 close(4) = 0
8266 open("/etc/passwd", O_RDONLY) = 4
8266 fcntl64(4, F_GETFD) = 0
8266 fcntl64(4, F_SETFD, FD_CLOEXEC) = 0
8266 _llseek(4, 0, [0], SEEK_CUR) = 0
8266 fstat64(4, {st_mode=S_IFREG|0600, st_size=5058, ...}) = 0
8266 mmap2(NULL, 5058, PROT_READ, MAP_SHARED, 4, 0) = 0x4001a000
8266 _llseek(4, 5058, [5058], SEEK_SET) = 0
8266 fstat64(4, {st_mode=S_IFREG|0600, st_size=5058, ...}) = 0
8266 munmap(0x4001a000, 5058-) = 0
8266 close(4) = 0
Gore vidite 2 ciklusa. U pitanju je useradd komanda koja kada se pokrene, ne izvrshava se do kraja vec se ponasha kao "fork bomb denial of service attack".
Proces mozhe da se ubije. Nema nikakvih error poruka nigde.
tar se ponasha na isti nachin samo shto se pojavljuje /etc/group umesto passwd-a.
tar i useradd binaries su zamenjene novim sa identichnog distroa, ali problem i dalje postoji.
Na toj mashini radi nekoliko servisa bez ikakvih problema. Samo pomenute 2 komande ne rade.
gdb i ltrace nisu dali (bar meni) nikakav kvalitetan info.
Ideje?
|