LinuxQuestions.org
Go Job Hunting at the LQ Job Marketplace
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
LinkBack Search this Thread
Old 07-06-2005, 07:31 PM   #1
space_beyond
LQ Newbie
 
Registered: May 2005
Posts: 13

Rep: Reputation: 0
cannot shutdown properly


I'm a newbie on Linux. We are using Red Hat Linux 9. When we type the command "shutdown -h now" a message appears

Broadcast message from root (tty1) July 6, 2005
The system is going down for system halt NOW! /dev/null
RK_Init: id=0xc036f000, sct[]=0xc030a0f0, FUCK: Can't find kmalloc()!

It then back to the command prompt. If we tpye again the shutdown command the same message appears.

Need help....
 
Old 07-06-2005, 07:40 PM   #2
Krugger
Member
 
Registered: Oct 2004
Posts: 229

Rep: Reputation: 30
Ok, that is a bit weird. You should update the kernel or something like that and get some ACPI support to be able to powerdown completelty.

Have you been playing with the scripts or have you some extreme RBAC settings. The kernel not being able to call kmalloc is ... bizarre.
 
Old 07-06-2005, 07:44 PM   #3
Krugger
Member
 
Registered: Oct 2004
Posts: 229

Rep: Reputation: 30
I was looking around for your weird problem and found out there is a high probability that you have been hacked.

http://redhat.irlp.net/hack_report.html

Kind of sound like your problem.
 
Old 07-06-2005, 07:46 PM   #4
Krugger
Member
 
Registered: Oct 2004
Posts: 229

Rep: Reputation: 30
Get this to check to see if you got rootkits installed

http://www.chkrootkit.org/
 
Old 07-10-2005, 08:11 PM   #5
space_beyond
LQ Newbie
 
Registered: May 2005
Posts: 13

Original Poster
Rep: Reputation: 0
I look on the site you mention, and found a similar messages that had been displaying in our system. What can we do...can you have some idea how to fix this.
Thanks...
 
Old 07-10-2005, 09:50 PM   #6
btmiller
Senior Member
 
Registered: May 2004
Location: In the DC 'burbs
Distribution: Arch, Scientific Linux, Debian, Ubuntu
Posts: 3,988

Rep: Reputation: 261Reputation: 261Reputation: 261
If your system has been compromised, back up user data (NOT programs/libraries -- be very sure about this, i.e. inspect your back-ups for suspicious files), reformat, and reinstall from scratch. Unfortunately, this is the only way to safely deal with a compromised system. Meanwhile, if you have a compromised box, pull it off the network immediately. (i.e. disconnect the network cable) since it is a danger to you and to others.

You probably ought to upgrade to something more recent than RH9. If you're running an unpatched RH9 with lots of services available to the Internet ... well, it's not necessarily surprising that you got cracked.
 
Old 07-13-2005, 05:26 PM   #7
Krugger
Member
 
Registered: Oct 2004
Posts: 229

Rep: Reputation: 30
If you simply want to repair the system and move on get a knoppix CD ( http://www.knoppix.org ) so you can mount your hard drives and copy any relevant data. After that delete the disk and reinstall the system.

If you want to save yourself some trouble copy the server configs. And I would suggest getting an updated version from redhat like the fedora core 4 from http://fedora.redhat.com/download/mirrors.html

Warning: This prevents any diagnostic of the way how the machine was compromised. This usually help you learn how to prevent this in the future. It's up to you and how time critical it is to get things up again.
 
Old 07-15-2005, 12:17 PM   #8
int0x80
Member
 
Registered: Sep 2002
Location: Cincinnati
Distribution: Debian GNU/Linux
Posts: 310

Rep: Reputation: 31
DBAN

For clearing your drive, I recommend DBAN: http://dban.sourceforge.net
This will get rid of everything.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
gnome won't logout or shutdown properly RRolleston Debian 0 12-23-2004 05:33 PM
Help! X in Rh9 won't shutdown/logout properly! benjaminchoate Linux - Software 6 03-04-2004 03:26 PM
Can't shutdown properly hus Linux - Newbie 5 01-01-2004 04:24 AM
Vector Linux 3.2 - just how to shutdown properly ? alloydog Linux - Networking 4 05-30-2003 02:21 PM
Cannot Shutdown/Reboot properly skiu4ia Linux - Newbie 3 05-21-2002 06:03 AM


All times are GMT -5. The time now is 01:40 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration