Over the past 2 weeks I've been having some very strange problems with email and internet access via Dan's Guardian
Last week I looked through the qsmtpd log files I found the following which explained why qsmtpd was unresponsive and users could not send out mail
~~~~~~~~~~
@40000000462427c236ce8e44 4082 Too many connections: 40 >= 40. Waiting one second.
@40000000462427c337044444 4082 Too many connections: 40 >= 40. Waiting one second.
@40000000462427c4373ae88c 4082 Too many connections: 40 >= 40. Waiting one second.
etc, etc
~~~~~~~~~~~~~~~~~~~~~
Dan's guardian also started to deny users access to the internet. This is a snip from the Dan's Guardian log file from last week
~~~~~~~~~~~~~~~~
http://rs.update.microsoft.com/odf/v6odf.xml?0704022318 *INFECTED* *DENIED*
> Error connecting to ClamD socket GET 1394 0 Content scanning 1 403 -
> 2007.4.3 8:21:23 - 192.168.1.112
>
http://download.microsoft.com/v6/windowsupdate/redir/wuredir.cab?0704022339> *INFECTED* *DENIED* Error connecting to ClamD socket GET 1454 0 Content
> scanning 1 403 -
> 2007.4.3 8:21:23 - 192.168.1.183
>
http://download.microsoft.com/v6/windowsupdate/redir/wuredir.cab?0704022331> *INFECTED* *DENIED* Error connecting to ClamD socket GET 1454 0 Content
> scanning 1 403 -
> 2007.4.3 8:21:23 - 192.168.1.112
>
http://download27.avast.com/iavs4x/servers.def.stamp *INFECTED* *DENIED*
~~~~~~~~~~~~~~~~~~
Today after about 5 days of peace it started happening again, the problems seemed to have started at 08:30 Tokyo time. I received this email from anonymous:
~~~~~~~~
2007-04-17 08:30:17.882007500 ClamAV update process started at Tue Apr 17 08:30:17 2007
2007-04-17 08:30:18.113659500 WARNING: Your ClamAV installation is OUTDATED!
2007-04-17 08:30:18.113664500 WARNING: Local version: 0.90.1 Recommended version: 0.90.2
2007-04-17 08:30:18.113667500 DON'T PANIC! Read
http://www.clamav.net/support/faq2007-04-17 08:30:18.113670500 main.inc is up to date (version: 43, sigs: 104500, f-level: 14, builder: sven)
2007-04-17 08:30:19.486454500 daily.inc updated (version: 3104, sigs: 5668, f-level: 15, builder: ccordes)
2007-04-17 08:30:19.486467500 WARNING: Your ClamAV installation is OUTDATED!
2007-04-17 08:30:19.486471500 WARNING: Current functionality level = 14, recommended = 15
2007-04-17 08:30:19.486474500 DON'T PANIC! Read
http://www.clamav.net/support/faq2007-04-17 08:30:19.486519500 Database updated (110168 signatures) from db.local.clamav.net (IP: 203.178.137.175)
2007-04-17 08:30:19.486788500 Clamd successfully notified about the update.
2007-04-17 09:30:19.239702500 Received signal: wake up
2007-04-17 09:31:24.255754500 ERROR: Can't lock database directory: /var/clamav
~~~~~~~~~~~~~~~~~
Here's a snip from the freshclam log file
~~~~~~~~~~~~~~~
@400000004623eaf30fe1d19c WARNING: Your ClamAV installation is OUTDATED!
@400000004623eaf30fe1dd54 WARNING: Local version: 0.90.1 Recommended version: 0.90.2
@400000004623eaf30fe1ecf4 DON'T PANIC! Read
http://www.clamav.net/support/faq@400000004623eaf30fe1f8ac main.inc is up to date (version: 43, sigs: 104500, f-level: 14, builder: sven)
@400000004623eaf40bf19054 Downloading daily-3103.cdiff [100%]
Downloading daily-3103.cdiff [100%]
@400000004623eaf40bf19ff4 daily.inc updated (version: 3103, sigs: 5121, f-level: 15, builder: sven)
@400000004623eaf40bf1af94 WARNING: Your ClamAV installation is OUTDATED!
@400000004623eaf40bf1bb4c WARNING: Current functionality level = 14, recommended = 15
@400000004623eaf40bf1caec DON'T PANIC! Read
http://www.clamav.net/support/faq@400000004623eaf40bf1d6a4 Database updated (109621 signatures) from db.local.clamav.net (IP: 203.178.137.175)
@400000004623eaf40c011ccc Clamd successfully notified about the update.
@400000004623f90338e9d10c Received signal: wake up
@400000004623f90338e9e0ac ClamAV update process started at Tue Apr 17 07:30:17 2007
@400000004623f90407c43284 WARNING: Your ClamAV installation is OUTDATED!
@400000004623f90407c44224 WARNING: Local version: 0.90.1 Recommended version: 0.90.2
@400000004623f90407c451c4 DON'T PANIC! Read
http://www.clamav.net/support/faq@400000004623f90407c45d7c main.inc is up to date (version: 43, sigs: 104500, f-level: 14, builder: sven)
@400000004623f90407c46934 daily.inc is up to date (version: 3103, sigs: 5121, f-level: 15, builder: sven)
@400000004624071334924e2c Received signal: wake up
@400000004624071334925dcc ClamAV update process started at Tue Apr 17 08:30:17 2007
@400000004624071406c64e6c WARNING: Your ClamAV installation is OUTDATED!
@400000004624071406c661f4 WARNING: Local version: 0.90.1 Recommended version: 0.90.2
@400000004624071406c66dac DON'T PANIC! Read
http://www.clamav.net/support/faq@400000004624071406c67964 main.inc is up to date (version: 43, sigs: 104500, f-level: 14, builder: sven)
@40000000462407151827e044 Downloading daily-3104.cdiff [ 7%]
Downloading daily-3104.cdiff [ 17%]
Downloading daily-3104.cdiff [ 26%]
Downloading daily-3104.cdiff [ 36%]
Downloading daily-3104.cdiff [ 45%]
Downloading daily-3104.cdiff [ 55%]
Downloading daily-3104.cdiff [ 64%]
Downloading daily-3104.cdiff [ 73%]
Downloading daily-3104.cdiff [ 83%]
Downloading daily-3104.cdiff [ 92%]
Downloading daily-3104.cdiff [100%]
Downloading daily-3104.cdiff [100%]
@40000000462407151cfeb4e4 daily.inc updated (version: 3104, sigs: 5668, f-level: 15, builder: ccordes)
@40000000462407151cfee7ac WARNING: Your ClamAV installation is OUTDATED!
@40000000462407151cfef74c WARNING: Current functionality level = 14, recommended = 15
@40000000462407151cff0304 DON'T PANIC! Read
http://www.clamav.net/support/faq@40000000462407151cffb2cc Database updated (110168 signatures) from db.local.clamav.net (IP: 203.178.137.175)
@40000000462407151d03cd94 Clamd successfully notified about the update.
@40000000462415250e4991e4 Received signal: wake up
@40000000462415660f3e8104 ERROR: Can't lock database directory: /var/clamav
@400000004624237600948d4c Received signal: wake up
@40000000462423b701dcc8a4 ERROR: Can't lock database directory: /var/clamav
@4000000046242eee1edc65f4 ClamAV update process started at Tue Apr 17 11:20:20 2007
@4000000046242f021ef13de4 WARNING: Can't query current.cvd.clamav.net
@4000000046242f021ef14d84 WARNING: Invalid DNS reply. Falling back to HTTP mode.
@4000000046242f022066d684 Reading CVD header (main.cvd): ERROR: Can't get information about db.local.clamav.net: Temporary DNS error
@4000000046242f16208b46a4 main.inc is up to date (version: 43, sigs: 104500, f-level: 14, builder: sven)
@4000000046242f16215d9a64 Reading CVD header (daily.cvd): ERROR: Can't get information about db.local.clamav.net: Temporary DNS error
@4000000046242f2a218002fc daily.inc is up to date (version: 3104, sigs: 5668, f-level: 15, builder: ccordes)
~~~~~~~~~~~~~~~~~~~~~~~
Around about the same time in the message log file I found this
~~~~~~~~~~~~~~~~~~~~~~~~~~
Apr 17 08:31:24 server7 dansguardian: Exception whilst reading ClamD socket: select() on input: timeout
Apr 17 08:31:24 server7 dansguardian: scanFile/Memory returned error: -1
Apr 17 08:31:54 server7 dhcpd: DHCPINFORM from 192.168.1.102 via eth0
Apr 17 08:31:54 server7 dhcpd: DHCPACK to 192.168.1.102
Apr 17 08:31:57 server7 dhcpd: DHCPINFORM from 192.168.1.102 via eth0
Apr 17 08:31:57 server7 dhcpd: DHCPACK to 192.168.1.102
Apr 17 08:31:58 server7 dansguardian: Exception whilst reading ClamD socket: select() on input: timeout
Apr 17 08:31:58 server7 dansguardian: scanFile/Memory returned error: -1
Apr 17 08:32:03 server7 dansguardian: Exception whilst reading ClamD socket: select() on input: timeout
Apr 17 08:32:03 server7 dansguardian: scanFile/Memory returned error: -1
Apr 17 08:32:05 server7 last message repeated 9 times
Apr 17 08:32:06 server7 dhcpd: DHCPDISCOVER from 00:17:31:2e:83:2f via eth0
Apr 17 08:32:07 server7 dhcpd: DHCPOFFER on 192.168.1.167 to 00:17:31:2e:83:2f (desouzac-ele2) via eth0
Apr 17 08:32:07 server7 dhcpd: DHCPREQUEST for 192.168.1.167 (192.168.1.1) from 00:17:31:2e:83:2f (desouzac-ele2) via eth0
Apr 17 08:32:07 server7 dhcpd: DHCPACK on 192.168.1.167 to 00:17:31:2e:83:2f (desouzac-ele2) via eth0
Apr 17 08:32:08 server7 dansguardian: Exception whilst reading ClamD socket: select() on input: timeout
Apr 17 08:32:08 server7 dansguardian: scanFile/Memory returned error: -1
Apr 17 08:32:15 server7 dansguardian: Exception whilst reading ClamD socket: select() on input: timeout
Apr 17 08:32:15 server7 dansguardian: scanFile/Memory returned error: -1
Apr 17 08:33:03 server7 dhcpd: DHCPINFORM from 192.168.1.167 via eth0
~~~~~~~~~~~~~~~~~~~~
I rebooted at about 11:00 and everything seemed to work fine for a while, then the number of instances of SMTP connections started to build up until it maxed out at 40 about an hour and a half later.
I tried starting and stopping qsmtpd but it didn't work, the connections just started building upi again. Is there anything I'm doing wrong (my server is up to date)?
I've just rebooted (again) in the hope that it will be ok this time......
I know this may be a potential bug (
http://bugs.contribs.org/show_bug.cgi?id=2743) but I was wondering if there is anything I can do to keep everyone happy in terms of getting email.