Re: Re: Trophie worker processes dying at a high rate: am I alone?
Alain Fauconnet <[email protected]> Mon, 23 Aug 2004 12:58:15 +0700
| Newsgroups | gmane.comp.security.virus.vtools |
|---|---|
| Message-ID | <[email protected]> |
Oops. *intense blush*. Got it. Read below. On Thu, Aug 19, 2004 at 01:57:13PM +0700, Alain Fauconnet wrote: > Hello, > > > Recently, my previously solid-as-a-rock Trophie has started > > misbehaving, worker processes SIGSEGVing at a high rate. The master > > process was staying up though, so Amavisd-new couldn't detect this and > > it effectively brought our mail traffic to a standstill. And yes of > > course, last time it happened on a friday evening... > > > > This caused a bunch of lines like this in the mail log: > > Aug 13 23:59:59 mail-gate trophie[13034]: SIGNAL [11] caught - cleaning up > > and exiting. > > It just happened again at 12:01 local time = 05:01 TU. At that time > I had VPN 1.958.00 and CPR 1.959.15 installed. 'iscan -v' didn't show > any error *but* much to my suprise the exact time it happened matches > the last modification time of libvsapi.so! > That could well explain it, but what the hell wrote to that file? > Certainly not my trend-update.pl script (I've double checked). > I've re-downloaded engine 7.000-1011 and compared it to the existing > libvsapi.so: md5 checksums match. So what ?!? I'm baffled. > > Thinking about it, I've recently chmod'ed libvsapi.so 755 (it was > 500). So 'something' would be messing with it? What? Is is > self-modifying code or what? Well, it was ServerProtect's own pattern update program, whose entry in root's crontab had been commented out since I've started working on my own update script, and which I have inadvertently enabled again at some point. So the two update mechanisms were running concurrently. Now why does it opens libvsapi.so for r/w, probably also rewrites it without changing a bit in it? I will probably never know. But it's almost certainly what was causing my Trophie dying with signal 11. Folks, if you run trend-update.pl on a box with ServerProtect, don't forget to disable the timed calls to: /opt/TrendMicro/SProtectLinux/SPLX.vsapiapp/splxmain -u Case closed for me - sorry for the noise on the list. Greets, _Alain_