Re: Re: Trophie worker processes dying at a high rate: am I alone?

Alain Fauconnet <[email protected]> Mon, 23 Aug 2004 12:58:15 +0700
Newsgroups gmane.comp.security.virus.vtools
Message-ID <[email protected]>
Oops. *intense blush*. Got it. Read below.

On Thu, Aug 19, 2004 at 01:57:13PM +0700, Alain Fauconnet wrote:
> Hello,
> 
> > Recently,   my   previously   solid-as-a-rock   Trophie   has  started
> > misbehaving, worker processes SIGSEGVing at a high  rate.  The  master
> > process was staying up though, so Amavisd-new couldn't detect this and
> > it effectively brought our mail traffic to a standstill.  And  yes  of
> > course, last time it happened on a friday evening...
> > 
> > This caused a bunch of lines like this in the mail log:
> > Aug 13 23:59:59 mail-gate trophie[13034]: SIGNAL [11] caught - cleaning up 
> > and exiting.
> 
> It just happened again at 12:01 local time = 05:01 TU. At that time
> I had VPN 1.958.00 and CPR 1.959.15 installed. 'iscan -v' didn't  show
> any error *but* much to my suprise the exact time it happened  matches
> the last modification time of libvsapi.so!
> That could well explain it, but what the  hell  wrote  to  that  file?
> Certainly not my trend-update.pl script (I've double checked).
> I've  re-downloaded  engine 7.000-1011 and compared it to the existing
> libvsapi.so: md5 checksums match. So what ?!? I'm baffled.
> 
> Thinking  about  it,  I've  recently  chmod'ed libvsapi.so 755 (it was
> 500).   So   'something'  would  be  messing  with  it?  What?  Is  is
> self-modifying code or what?

Well, it was ServerProtect's own pattern update program, whose entry
in root's crontab had been commented out since I've started working on
my own update script, and which I have inadvertently enabled again  at
some point. So the two update mechanisms were running concurrently.

Now  why  does it opens libvsapi.so for r/w, probably also rewrites it
without  changing  a  bit  in  it?  I  will   probably   never   know.
But  it's  almost  certainly  what  was  causing my Trophie dying with
signal 11.

Folks, if you run trend-update.pl on a box with  ServerProtect,  don't
forget to disable the timed calls to:
/opt/TrendMicro/SProtectLinux/SPLX.vsapiapp/splxmain -u

Case closed for me - sorry for the noise on the list.
Greets,
_Alain_