LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-01-2004, 09:44 AM   #1
TruckStuff
Member
 
Registered: Apr 2002
Posts: 498

Rep: Reputation: 30
Server crash... reassure me I wasn't hacked


Well after over 6 months of uptime, one of our servers crashed this morning. This is a readhat 9 system running the 2.6.2 kernel with apache, php, sshd, proftpd (all the most current versions). When I checked the server this AM, it had some kernel error on the screen that ended with:
Code:
Unable to handle kernel paging request at virtual address 2e7365d8

printing eip:
  c0114a3f
#pde = 0000000000
It took me a few reboots to finally get the system back up. When I would reboot, it would get the dreaded long-beep-three-short-beeps beep code. At one point when I rebooted, it kernel paniced half way through the boot process with:
Code:
Code: 00 ba 05 00 00 00 8d 7d b4 8d 75 b4 fc 89 d1 f3 ab b8 00 e0
Kernel panic: attempted to kill init!
I even tried booting into the stock kernel to see if that helped, but it didn't. I did some googling for the first message, and it looks to be memory related (which would reinforce the BIOS beep code I heard). So right now I'm thinking hardware failure with the memory.

When I did finally get the system back up, I started checking over logs. No unusual activity in syslog. Only thing in /var/log/secure was these damned brutessh attempts. I performed a tripwire integrity check and it said all was well. All user passwords are good ones (e.g. non-dictionary, alphanumeric). No dead login accounts lying around. Anything else I should check?

Also, I don't know where to find logs of the kernel crashes. /var/log/messages only has normal activity until the final successful reboot, i.e. there aren't any log messages from the failed boot attempts. Same with /var/log/boot.log. Would there be any logs from these attempts?

Any comments/questions are welcome at this point.

Last edited by TruckStuff; 10-01-2004 at 09:50 AM.
 
Old 10-01-2004, 12:17 PM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
It's highly unlikely that someone cracking your system would cause a memory fault that would be persistant after the reboot. Sounds like a hardware failure. Simple test...swap the RAM and see if you still see the error. Memtest86 might be able to diagnose the bad RAM as well.
 
Old 10-01-2004, 01:22 PM   #3
TruckStuff
Member
 
Registered: Apr 2002
Posts: 498

Original Poster
Rep: Reputation: 30
Well that's good to know. I figured I was probably being paranoid.

Turns out, I think its actually a dying CPU fan. The beep codes are actually for the video card (this board won't beep on memory errors, and its been so long since I rebooted this machine that I forgot the video card takes an extra second to initialize for some reason). When I opened up the case to swap out the ram, I noticed one of the CPU fans was spinning slowly and making an awful racket. Swapped out the fan and hopefully that will fix it.

Last edited by TruckStuff; 10-01-2004 at 01:39 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Is my server hacked? kazjol Linux - Security 3 10-10-2004 12:09 PM
Server hacked cpanelskindepot Linux - Security 46 07-05-2004 06:19 PM
Server hacked php4u Linux - Security 1 07-05-2004 11:34 AM
server hacked!?!?! vittibaby Linux - Security 1 03-27-2004 12:31 PM
web server hacked. sarin Linux - Security 12 10-05-2002 03:51 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:12 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration