OOPS (may be an attack)

Catalin BOIE (util@deuroconsult.ro)
Wed, 24 Mar 1999 12:59:50 +0200 (EET)


Hi, guys!

Today I got an oops:

Options used: -V (default)
-o /lib/modules/2.2.3/ (default)
-k /proc/ksyms (default)
-l /proc/modules (default)
-m /boot/System.map-2.2.3 (specified)
-c 1 (default)

Call trace: [<c010addd>] [<c0118ea1>] [<c01091a7>] [<c01103c6>] [<c0108d4d>] [<c0183698>] [<c010b15f>] [<c0108cd0>]

Trace: c010addd <synchronize_bh+39/4c>
Trace: c0118ea1 <do_exit+65/2ac>
Trace: c01091a7 <die+53/54>
Trace: c01103c6 <do_page_fault+2d2/324>
Trace: c0108d4d <error_code+2d/40>
Trace: c0183698 <scrup+74/10c>
Trace: c010b15f <do_IRQ+1b/54>
Trace: c0108cd0 <ret_from_intr+0/20>

In that moment the RX led from our gateway (Viper ADSL (offtopic: what do
you think about this product?)) was continuosly led. I run a tcpdump on
other machine on the same segment and I saw many packets came from
209.1.224.16 with fragmentation around 700.

9 warnings issued. Results may not be reliable.

I have a:
- dual Pentium II AGP/PCI/333 MHz
- mo Intel i82440LX
- 196 MB Ram
- 1 x AIC-7880
- 2 x 3C905b
- 1 x Cyclom YeP
- 1 ESS1869 Sound Card

Kernel is 2.2.3.

I think is a new attack (floot etc.).
I hope (pray) that you find the problem!

Thanks!
************************************
Catalin(ux) BOIE
System Administrator at Deuroconsult
catab@deuroconsult.ro
http://www2.deuroconsult.ro/~catab

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/