[grsec] logging flood

Adi Spivak pchelper at serv.co.il
Sun Aug 7 03:30:05 EDT 2005


hello
i use grsec patch on 2 diffrent slackware linux server.
on one of them, after several days from reboot it begins to flood the 
messages log file with just everything that is happening on the server ( 
both servers are configured the same, and it starts to do it only after 
several days from reboot, this time it was 50 days. )
here is an example taken from a logwatch summery:

 1 Time(s): grsec: exec of /bin/bash (/bin/sh -c /usr/local/clamav/bin/freshclam --quiet -l /var/log/clam-update.log > /dev/null 2>&1 ) by /usr/sbin/crond[crond:4638] uid/euid:0/0 gid/egid:0/0, parent /usr/sbin/crond[crond:95] uid/euid:0/0 gid/egid:0/0
 1 Time(s): grsec: exec of /bin/bash (/bin/sh -c /usr/local/clamav/bin/freshclam --quiet -l /var/log/clam-update.log > /dev/null 2>&1 ) by /usr/sbin/crond[crond:4664] uid/euid:0/0 gid/egid:0/0, parent /usr/sbin/crond[crond:95] uid/euid:0/0 gid/egid:0/0
 1 Time(s): grsec: exec of /bin/bash (/bin/sh -c /usr/local/clamav/bin/freshclam --quiet -l /var/log/clam-update.log > /dev/null 2>&1 ) by /usr/sbin/crond[crond:4701] uid/euid:0/0 gid/egid:0/0, parent /usr/sbin/crond[crond:95] uid/euid:0/0 gid/egid:0/0
 1 Time(s): grsec: exec of /bin/bash (/bin/sh -c /usr/local/clamav/bin/freshclam --quiet -l /var/log/clam-update.log > /dev/null 2>&1 ) by /usr/sbin/crond[crond:4726] uid/euid:0/0 gid/egid:0/0, parent /usr/sbin/crond[crond:95] uid/euid:0/0 gid/egid:0/0

what is cousing it?
how can i stop it without rebooting the server each time?

thanks
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3178 bytes
Desc: S/MIME Cryptographic Signature
Url : http://grsecurity.net/pipermail/grsecurity/attachments/20050807/3b632c66/smime.bin


More information about the grsecurity mailing list