LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 02-23-2011, 12:09 PM   #1
browny_amiga
Member
 
Registered: Dec 2001
Location: /mnt/UNV/Mlkway/Earth/USA/California/Silicon Valley
Distribution: Kubuntu, Debian Buster Stable, Windoze 7
Posts: 684

Rep: Reputation: 56
Smile Help for possessed system, exorcism?


Hi

I have quite an impossible situation:

I got an obnoxious apache webserver that I am trying to reinstall. And after uninstalling it fully (on a Debian 6.0 system), the darn thing is still running.
Kill off the process, it gets restarted.

Ok, lets get the big guns: I go ahead and erase all executables and directories belonging to apache... and...

scary scary, the DARN THING STILL RESTARTS...

HOW?????

In my book that is quite impossible. Where is it restarting from??

I suspect that the new automatic restart daemon is responsible for this. Is there any documentation on how that works?

Cheers

Markus
 
Old 02-23-2011, 12:28 PM   #2
corp769
LQ Guru
 
Registered: Apr 2005
Location: /dev/null
Posts: 5,818

Rep: Reputation: 1007Reputation: 1007Reputation: 1007Reputation: 1007Reputation: 1007Reputation: 1007Reputation: 1007Reputation: 1007
EDIT: Nevermind.

Last edited by corp769; 02-23-2011 at 01:17 PM.
 
Old 02-23-2011, 01:14 PM   #3
browny_amiga
Member
 
Registered: Dec 2001
Location: /mnt/UNV/Mlkway/Earth/USA/California/Silicon Valley
Distribution: Kubuntu, Debian Buster Stable, Windoze 7
Posts: 684

Original Poster
Rep: Reputation: 56
Cool

How can apachectl still be installed if I removed all the executables??

What does actually restart the apache server (or any daemon) automatically when it crashes (or gets killed by signal)?
I know that many people must be having this problem with obnoxious daemons that just won't stay dead after you shoot them in the head ;-)

It is good to finally have auto restart, but this is the dark side of it.

Does Linux cache executables in memory, even after the program has been removed from the harddisk?
 
Old 02-23-2011, 01:25 PM   #4
szboardstretcher
Senior Member
 
Registered: Aug 2006
Location: Detroit, MI
Distribution: GNU/Linux systemd
Posts: 4,278

Rep: Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694
Quote:
whereis httpd
which httpd
cd /; find . -name httpd
any of these return interesting results? like a secondary installation?
 
Old 02-23-2011, 01:29 PM   #5
corp769
LQ Guru
 
Registered: Apr 2005
Location: /dev/null
Posts: 5,818

Rep: Reputation: 1007Reputation: 1007Reputation: 1007Reputation: 1007Reputation: 1007Reputation: 1007Reputation: 1007Reputation: 1007
If your system has locate on it, run updatedb and then do a locate httpd and locate apache. That will find everything for ya... I tend to use it because how fast it is due to indexing.
 
Old 04-04-2011, 01:42 PM   #6
browny_amiga
Member
 
Registered: Dec 2001
Location: /mnt/UNV/Mlkway/Earth/USA/California/Silicon Valley
Distribution: Kubuntu, Debian Buster Stable, Windoze 7
Posts: 684

Original Poster
Rep: Reputation: 56
Question

whereis and which httpd come up empty.
The find command also, there is no apache installed anymore on this system.
updatedb and locate report the same, nothing there.

But there it is, in the task monitor, running. I send it a term or kill signal, the processes stop and then immediately spring up again.
I erased the user that the processes are running at, with the only result that now it is running with UID 1006 instead of the user.

This darn processes got nothing, they cannot exist, they cannot get restarted on the system, yet they do. How can I get rid of them without restarting the whole box? Where are these executables launched from?
Is this maybe a sign of a rootkitted system?
 
Old 04-08-2011, 01:17 AM   #7
chrism01
LQ Guru
 
Registered: Aug 2004
Location: Sydney
Distribution: Rocky 9.2
Posts: 18,359

Rep: Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751
Have you looked at /etc/inittab - respawn cmd http://linux.about.com/od/commands/l...l5_inittab.htm. Unusual, but if a dedicated webserver, it may have been set that way.
Also remember that a Unix file doesn't actually get deleted until all processes that have it open have closed it or died. It's just invisible to 'ls/find/whereis' until then.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
SSH working from System A to System B but not from system B to System A bala150985 Linux - Networking 15 05-23-2009 08:53 AM
LXer: Ubuntu 8.04 Beta -- performing a networking exorcism LXer Syndicated Linux News 0 04-01-2008 02:41 AM
my modem is possessed... (can't connect) dark_prancer Linux - Hardware 1 05-19-2005 11:03 PM
CD Burner possessed by the Dark Spawn of Satan Brane Ded Linux - Hardware 5 12-03-2003 12:33 AM
I think my bash is possessed. Locura Slackware 2 06-30-2003 03:03 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 03:22 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration