[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: polchat




Dzięki za konkrety.


> 3. strace polchatd wypluł to
fcntl64(0, F_GETFD)                     = 0
fcntl64(1, F_GETFD)                     = 0
fcntl64(2, F_GETFD)                     = 0
uname({sys="Linux", node="", ...}) = 0
geteuid32()                             = 0
getuid32()                              = 0
getegid32()                             = 0
getgid32()                              = 0
brk(0)                                  = 0x82c5b50
brk(0x82c5b70)                          = 0x82c5b70
brk(0x82c6000)                          = 0x82c6000
brk(0x82c8000)                          = 0x82c8000
brk(0x82c9000)                          = 0x82c9000
getrlimit(RLIMIT_NOFILE, {rlim_cur=1024, rlim_max=1024}) = 0
brk(0x82cc000)                          = 0x82cc000
brk(0x82ce000)                          = 0x82ce000
dup(1)                                  = 3
dup(2)                                  = 4
brk(0x82d0000)                          = 0x82d0000
getcwd("polchat-server-2.0/sbin", 4095) = 52
open("/polchat-server-2.0/sbin/../conf/polchatd.conf", O_RDONLY) = 5
fstat64(5, {st_mode=S_IFREG|0644, st_size=7226, ...}) = 0
old_mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x40000000
read(5, "# it is safe (even advised!) not"..., 4096) = 4096
read(5, "?\n# (say no for rooms with large"..., 4096) = 3130
brk(0x82d1000)                          = 0x82d1000
read(5, "", 4096)                       = 0
close(5)                                = 0
munmap(0x40000000, 4096)                = 0
fork()                                  = 25416
--- SIGCHLD (Child exited) @ 0 (0) ---
_exit(0)                                = ?


strace -f polchatd wypluł dużo więcej m.in. to:
fork(Process 7015 attached (waiting for parent)
Process 7015 resumed (parent 20997 ready)
)                                  = 7015
[pid  7015] --- SIGSTOP (Stopped (signal)) @ 0 (0) ---
[pid 20997] _exit(0)                    = ?
[pid  7015] setsid()                    = 7015
chdir("/")                              = 0

[...]

--- SIGSEGV (Segmentation fault) @ 0 (0) ---
Process 7015 detached


> /var/log/syslog
Jun 9 07:47:57 ns20745 kernel: grsec: From IP: signal 11 sent to /sbin/polchatd[polchatd:6080] uid/euid:0/0 gid/egid:0/0, parent /sbin/polchatd[polchatd:7786] uid/euid:0/0 gid/egid:0/0



Reply to: