LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 12-10-2014, 04:46 AM   #1
perrin4869
Member
 
Registered: Dec 2014
Location: Japan
Distribution: slackware64-current
Posts: 60

Rep: Reputation: Disabled
Load average of 100% in my router when connected to my Linux box


This last 2 weeks I've been having troubles with my router (Buffalo WHR-HP-GN, running DD-WRT v24-sp2 (12/03/14) std - build 25544) stopping to work after a while of having my Linux PC on. I have two PCs connected by wire to it, my PC which is usually running Slackware 14.1, and my roommate's which is usually running Windows 7. We bought another router thinking that the old Buffalo had malfunctioned, only to find out that the problem still persisted whenever my PC was connected to it. Today looking at the status tab of the DD-WRT control panel I noticed that when running Windows, the load average stayed down at around 10%, and when I switched back to Linux, for a while it stayed that way, but after about an hour or two I noticed it had risen to 100%, and the network became useless. I switched back to Windows, and after a few minutes, the load average starting lowering (now at 15%). It actually took quite a while for it to go down from 100%.
I was wondering how I could troubleshoot this problem, now that I know the cause is something in my Linux installation. Thanks!
 
Old 12-10-2014, 04:59 AM   #2
Nemesiz
Member
 
Registered: Oct 2007
Posts: 47

Rep: Reputation: 2
Try to look at your linux network load. Try to catch some packages for analyse.
 
Old 12-11-2014, 12:01 AM   #3
perrin4869
Member
 
Registered: Dec 2014
Location: Japan
Distribution: slackware64-current
Posts: 60

Original Poster
Rep: Reputation: Disabled
Thanks for the reply!
I used "tcpdump -i eth0" over the period of a bit over 30 minutes until the problem started. I got the results on dropbox: https://dl.dropboxusercontent.com/u/...tcpdump.log.xz
At 01:18:40.727546 (or line 528601), there is an obvious change, which is also the time when the connection started failing. I stopped the logging just a minute or so later. For the remaining minute I kept getting these kind of messages: "IP landau.40271 > 115.238.184.107.5021: tcp 64 [bad hdr length 8 - too short, < 20]", where landau is my hostname. I don't really know what to make of all this though. Thanks for the help!
 
Old 12-11-2014, 01:51 PM   #4
rknichols
Senior Member
 
Registered: Aug 2009
Distribution: Rocky Linux
Posts: 4,776

Rep: Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212
That 115.238.x.y address is located in China. I recommend going over to the Linux Security forum and seeing if someone there can help you clean out whatever is sending those packets.
 
Old 12-11-2014, 02:30 PM   #5
Nemesiz
Member
 
Registered: Oct 2007
Posts: 47

Rep: Reputation: 2
Do you use IRC chat ? Or your zombie bot use it. Anyway it look like your linux box become a bot. Try to look at running processes, crontab scripts, temp catalogs. Or run some antivirus or other scanner tools.
 
Old 12-12-2014, 04:58 AM   #6
perrin4869
Member
 
Registered: Dec 2014
Location: Japan
Distribution: slackware64-current
Posts: 60

Original Poster
Rep: Reputation: Disabled
Actually I do use irc. This time the problem was triggered just as I connected to the server if I remember correctly. But that's not always the case. I took a look at the crontab scripts and there was nothing suspicious there. I guess I'll run some antivirus next. I'll also post the question in the security forum as per your suggestion. Thanks for the help!
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Questions re. IP numbers of PCs connected to a fritz.box home router floppy_stuttgart Linux - Newbie 1 02-25-2012 10:45 AM
Linux CPU load average kdelover Linux - Newbie 6 03-02-2011 12:40 PM
How to increase load average on Linux. beckss Linux - Server 5 12-08-2008 08:53 AM
Linux box security when net connected via router and DSL modem ? uncle-c Linux - Security 4 08-19-2008 08:54 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 11:36 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration