Koozali.org: home of the SME Server

LOG message

Marjan

LOG message
« on: August 21, 2003, 10:02:26 PM »
I find this in the log file. I don't now what is this. Plese help me and tell me what to do.
I thing that somebody tray to hack my server. Tnx for any answer.



Aug 19 21:17:25 streznik kernel: Unable to handle kernel NULL pointer dereference at virtual address 00000004
Aug 19 21:17:25 streznik kernel:  printing eip:
Aug 19 21:17:25 streznik kernel: c0139867
Aug 19 21:17:25 streznik kernel: *pde = 00000000
Aug 19 21:17:25 streznik kernel: Oops: 0002
Aug 19 21:17:25 streznik kernel: msdos nls_iso8859-1 nls_cp437 loop raid1 raid0 linear sr_mod ide-tape st sg vf
Aug 19 21:17:25 streznik kernel: CPU:    0
Aug 19 21:17:25 streznik kernel: EIP:    0010:[get_empty_filp+23/272]    Tainted: P
Aug 19 21:17:25 streznik kernel: EIP:    0010:[]    Tainted: P
Aug 19 21:17:25 streznik kernel: EFLAGS: 00010212
Aug 19 21:17:25 streznik kernel:
Aug 19 21:17:25 streznik kernel: EIP is at get_empty_filp [kernel] 0x17 (2.4.18-5)
Aug 19 21:17:25 streznik kernel: eax: 00000000   ebx: dc36a8e0   ecx: c19be360   edx: c02ca6f4
Aug 19 21:17:27 streznik kernel: esi: 00000000   edi: ffffffe9   ebp: c19be360   esp: d4fa3c54
Aug 19 21:17:28 streznik kernel: ds: 0018   es: 0018   ss: 0018
Aug 19 21:17:28 streznik kernel: Process sysmon (pid: 20981, stackpage=d4fa3000)
Aug 19 21:17:28 streznik kernel: Stack: 00000000 ffffffe9 c0138599 0000000d e25dbf22 c012298e 00000000 00000000
Aug 19 21:17:28 streznik kernel:        00000000 eee8e2c0 d4fa2000 c0140231 eee906c0 c19be360 00000000 eee906c0
Aug 19 21:17:28 streznik kernel:        c19be360 00000013 d4fa3ca0 00000107 00000009 00000001 d3d948a0 c19e0780
Aug 19 21:17:28 streznik kernel: Call Trace: [dentry_open+25/400] dentry_open [kernel] 0x19
Aug 19 21:17:28 streznik kernel: Call Trace: [] dentry_open [kernel] 0x19
Aug 19 21:17:28 streznik kernel: [in_group_p+30/48] in_group_p [kernel] 0x1e
Aug 19 21:17:28 streznik kernel: [] in_group_p [kernel] 0x1e
Aug 19 21:17:28 streznik kernel: [open_exec+113/176] open_exec [kernel] 0x71
Aug 19 21:17:28 streznik kernel: [] open_exec [kernel] 0x71
Aug 19 21:17:28 streznik kernel: [load_elf_binary+722/2864] load_elf_binary [kernel] 0x2d2
Aug 19 21:17:28 streznik kernel: [] load_elf_binary [kernel] 0x2d2
Aug 19 21:17:28 streznik kernel: [__alloc_pages+114/784] __alloc_pages [kernel] 0x72
Aug 19 21:17:28 streznik kernel: [] __alloc_pages [kernel] 0x72
Aug 19 21:17:28 streznik kernel: [page_add_rmap+88/160] page_add_rmap [kernel] 0x58
Aug 19 21:17:28 streznik kernel: [] page_add_rmap [kernel] 0x58
Aug 19 21:17:28 streznik kernel: [do_generic_file_read+576/1120] do_generic_file_read [kernel] 0x240
Aug 19 21:17:28 streznik kernel: [] do_generic_file_read [kernel] 0x240
Aug 19 21:17:28 streznik kernel: [do_generic_file_read+1108/1120] do_generic_file_read [kernel] 0x454
Aug 19 21:17:28 streznik kernel: [] do_generic_file_read [kernel] 0x454
Aug 19 21:17:28 streznik kernel: [ll_copy_from_user+60/112] ll_copy_from_user [kernel] 0x3c
Aug 19 21:17:28 streznik kernel: [] ll_copy_from_user [kernel] 0x3c
Aug 19 21:17:28 streznik kernel: [load_elf_binary+0/2864] load_elf_binary [kernel] 0x0
Aug 19 21:17:28 streznik kernel: [] load_elf_binary [kernel] 0x0
Aug 19 21:17:28 streznik kernel: [search_binary_handler+101/384] search_binary_handler [kernel] 0x65
Aug 19 21:17:28 streznik kernel: [] search_binary_handler [kernel] 0x65
Aug 19 21:17:28 streznik kernel: [do_execve+384/480] do_execve [kernel] 0x180
Aug 19 21:17:28 streznik kernel: [] do_execve [kernel] 0x180
Aug 19 21:17:28 streznik kernel: [getname+95/160] getname [kernel] 0x5f
Aug 19 21:17:28 streznik kernel: [] getname [kernel] 0x5f
Aug 19 21:17:28 streznik kernel: [sys_execve+48/96] sys_execve [kernel] 0x30
Aug 19 21:17:28 streznik kernel: [] sys_execve [kernel] 0x30
Aug 19 21:17:28 streznik kernel: [system_call+51/64] system_call [kernel] 0x33
Aug 19 21:17:28 streznik kernel: [] system_call [kernel] 0x33
Aug 19 21:17:28 streznik kernel:
Aug 19 21:17:28 streznik kernel:
Aug 19 21:17:28 streznik kernel: Code: 89 50 04 89 02 8b 3d e4 a6 2c c0 4f 89 3d e4 a6 2c c0 31 c0

Matt Quelch

Re: LOG message
« Reply #1 on: August 26, 2003, 07:04:37 PM »
It doesn't look like anyone has hacked your server. You might want to check your RAM as I would guess this could be caused by bad RAM blocks, although someone else probably knows better ;-). Is you server working at all? If not get a Knoppix CD or something and boot with that to do error checking, data recovery, etc.

HTH
Matt

Matt Quelch

Re: LOG message
« Reply #2 on: August 26, 2003, 07:07:37 PM »
It doesn't look like anyone has hacked your server. You might want to check your RAM as I would guess this could be caused by bad RAM blocks, although someone else probably knows better ;-). Is you server working at all? If not get a Knoppix CD or something and boot with that to do error checking, data recovery, etc.

HTH
Matt