1

Тема: Падение системы BSD4.11

логи(auth.log)
Nov 10 09:49:46 jail sshd[10951]: no modules loaded for `sshd' service
Nov 10 09:49:46 jail sshd[10949]: error: PAM: Permission denied
Nov 10 09:49:59 jail sshd[10949]: initauthconf: unable to parse file: /etc/auth.conf
Nov 10 09:49:59 jail sshd[10949]: Accepted password for alexander from 192.168.0.55 port 1054 ssh2
Nov 10 09:50:05 jail sshd[10952]: no modules loaded for `sshd' service
Nov 10 09:50:05 jail sshd[10952]: fatal: PAM: pam_open_session(): Permission denied
Nov 10 09:50:42 jail sshd[10958]: no modules loaded for `sshd' service
Nov 10 09:50:42 jail sshd[10956]: error: PAM: Permission denied
Nov 10 09:50:47 jail sshd[10956]: initauthconf: unable to parse file: /etc/auth.conf
Nov 10 09:50:47 jail sshd[10956]: Accepted password for alexander from 192.168.0.55 port 1061 ssh2
Nov 10 09:50:50 jail sshd[10959]: no modules loaded for `sshd' service
Nov 10 09:50:50 jail sshd[10959]: fatal: PAM: pam_open_session(): Permission denied
Nov 10 09:52:30 jail sshd[10962]: no modules loaded for `sshd' service
Nov 10 09:52:30 jail sshd[10960]: error: PAM: Permission denied
Nov 10 09:52:40 jail sshd[10960]: initauthconf: unable to parse file: /etc/auth.conf
Nov 10 09:52:40 jail sshd[10960]: Accepted password for alexander from 192.168.0.55 port 1062 ssh2
Nov 10 09:52:40 jail sshd[10963]: no modules loaded for `sshd' service
Nov 10 09:52:40 jail sshd[10963]: fatal: PAM: pam_open_session(): Permission denied
Nov 10 09:54:18 jail login: no modules loaded for `login' service
Nov 10 09:54:18 jail login: pam_authenticate: Permission denied
Nov 10 09:54:31 jail login: initauthconf: unable to parse file: /etc/auth.conf
Nov 10 09:54:31 jail login: LOGIN root REFUSED (NOROOT) ON TTY ttyv3
Nov 10 09:54:40 jail login: 1 LOGIN FAILURE ON ttyv3
Nov 10 09:54:40 jail login: 1 LOGIN FAILURE ON ttyv3, root
Nov 10 09:54:40 jail login: no modules loaded for `login' service
Nov 10 09:54:40 jail login: pam_authenticate: Permission denied
Nov 10 09:54:46 jail login: login on ttyv3 as alexander
Nov 10 09:55:22 jail su: alexander to root on /dev/ttyv3
Nov 10 10:03:34 jail shutdown: reboot by alexander:

потом dmesg

iir0: General error on Host Drive 0
iir0: General error on Host Drive 0
iir0: General error on Host Drive 0
iir0: Host Drive 0 not ready
iir0: Host Drive 0 not ready
iir0: General error on Host Drive 0

и так тысячи раз еще !!!!!!!  ...

вот лог после reboot..

Rebooting...
cpu_reset called on cpu#0
cpu_reset: Stopping other CPUs
Copyright (c) 1992-2005 The FreeBSD Project.
Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
    The Regents of the University of California. All rights reserved.
FreeBSD 4.11-RELEASE #0: Fri Apr  8 11:59:29 MSD 2005
    [email protected]:/usr/src/sys/compile/JAIL_NEW
Timecounter "i8254"  frequency 1193182 Hz
CPU: Intel(R) Xeon(TM) CPU 2.80GHz (2791.78-MHz 686-class CPU)
  Origin = "GenuineIntel"  Id = 0xf27  Stepping = 7
  Features=0xbfebfbff<FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CLFLUSH,DTS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE>
  Hyperthreading: 2 logical CPUs
real memory  = 4026466304 (3932096K bytes)
avail memory = 3920482304 (3828596K bytes)
Programming 24 pins in IOAPIC #0
IOAPIC #0 intpin 2 -> irq 0
Programming 24 pins in IOAPIC #1
Programming 24 pins in IOAPIC #2
FreeBSD/SMP: Multiprocessor motherboard: 4 CPUs
cpu0 (BSP): apic id:  0, version: 0x00050014, at 0xfee00000
cpu1 (AP):  apic id:  1, version: 0x00050014, at 0xfee00000
cpu2 (AP):  apic id:  6, version: 0x00050014, at 0xfee00000
cpu3 (AP):  apic id:  7, version: 0x00050014, at 0xfee00000
io0 (APIC): apic id:  8, version: 0x00178020, at 0xfec00000
io1 (APIC): apic id:  9, version: 0x00178020, at 0xfec81000
io2 (APIC): apic id: 10, version: 0x00178020, at 0xfec81400
Preloaded elf kernel "kernel" at 0xc0571000.
Warning: Pentium 4 CPU: PSE disabled
Pentium Pro MTRR support enabled
md0: Malloc disk
Using $PIR table, 19 entries at 0xc00f3070
npx0: <math processor> on motherboard
npx0: INT 16 interface
pcib0: <Host to PCI bridge> on motherboard
IOAPIC #0 intpin 16 -> irq 2
IOAPIC #0 intpin 19 -> irq 16
pci0: <PCI bus> on pcib0
pci0: <unknown card> (vendor=0x8086, dev=0x2541) at 0.1
pcib1: <PCI to PCI bridge (vendor=8086 device=2545)> at device 3.0 on pci0
pci2: <PCI bus> on pcib1
pci2: <unknown card> (vendor=0x8086, dev=0x1461) at 28.0
pcib2: <PCI to PCI bridge (vendor=8086 device=1460)> at device 29.0 on pci2
IOAPIC #2 intpin 0 -> irq 18
IOAPIC #2 intpin 3 -> irq 19
pci4: <PCI bus> on pcib2
em0: <Intel(R) PRO/1000 Network Connection, Version - 1.7.42> port 0x3040-0x307f mem 0xfea80000-0xfea9ffff irq 18 at device 8.0 on pci4
em0:  Speed:N/A  Duplex:N/A
em1: <Intel(R) PRO/1000 Network Connection, Version - 1.7.42> port 0x3000-0x303f mem 0xfeaa0000-0xfeabffff irq 19 at device 8.1 on pci4
em1:  Speed:N/A  Duplex:N/A
pci2: <unknown card> (vendor=0x8086, dev=0x1461) at 30.0
pcib3: <PCI to PCI bridge (vendor=8086 device=1460)> at device 31.0 on pci2
IOAPIC #1 intpin 6 -> irq 20
IOAPIC #1 intpin 7 -> irq 21
IOAPIC #1 intpin 0 -> irq 22
pci3: <PCI bus> on pcib3
em2: <Intel(R) PRO/1000 Network Connection, Version - 1.7.42> port 0x2040-0x207f mem 0xfe9a0000-0xfe9bffff irq 20 at device 7.0 on pci3
em2:  Speed:N/A  Duplex:N/A
em3: <Intel(R) PRO/1000 Network Connection, Version - 1.7.42> port 0x2000-0x203f mem 0xfe9c0000-0xfe9dffff irq 21 at device 7.1 on pci3
em3:  Speed:N/A  Duplex:N/A
iir0: <Intel Integrated RAID Controller> mem 0xfc7f0000-0xfc7f3fff irq 22 at device 8.0 on pci3
pci0: <unknown card> (vendor=0x8086, dev=0x2546) at 3.1
uhci0: <Intel 82801CA/CAM (ICH3) USB controller USB-A> port 0x4020-0x403f irq 2 at device 29.0 on pci0
usb0: <Intel 82801CA/CAM (ICH3) USB controller USB-A> on uhci0
usb0: USB revision 1.0
uhub0: Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1
uhub0: 2 ports with 2 removable, self powered
uhci1: <Intel 82801CA/CAM (ICH3) USB controller USB-B> port 0x4000-0x401f irq 16 at device 29.1 on pci0
usb1: <Intel 82801CA/CAM (ICH3) USB controller USB-B> on uhci1
usb1: USB revision 1.0
uhub1: Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1
uhub1: 2 ports with 2 removable, self powered
pcib4: <Intel 82801BA/BAM (ICH2) Hub to PCI bridge> at device 30.0 on pci0
pci1: <PCI bus> on pcib4
pci1: <ATI Mach64-GR graphics accelerator> at 12.0 irq 17
isab0: <PCI to ISA bridge (vendor=8086 device=2480)> at device 31.0 on pci0
isa0: <ISA bus> on isab0
atapci0: <Intel ICH3 ATA100 controller> port 0x3a0-0x3af,0-0x3,0-0x7,0-0x3,0-0x7 irq 0 at device 31.1 on pci0
ata0: at 0x1f0 irq 14 on atapci0
ata1: at 0x170 irq 15 on atapci0
pci0: <unknown card> (vendor=0x8086, dev=0x2483) at 31.3 irq 17
orm0: <Option ROMs> at iomem 0xc0000-0xc7fff,0xcd800-0xcefff,0xcf000-0xd07ff on isa0
pmtimer0 on isa0
fdc0: <NEC 72065B or clone> at port 0x3f0-0x3f5,0x3f7 irq 6 drq 2 on isa0
fdc0: FIFO enabled, 8 bytes threshold
fd0: <1440-KB 3.5" drive> on fdc0 drive 0
atkbdc0: <Keyboard controller (i8042)> at port 0x60,0x64 on isa0
atkbd0: <AT Keyboard> flags 0x1 irq 1 on atkbdc0
kbd0 at atkbd0
psm0: <PS/2 Mouse> irq 12 on atkbdc0
psm0: model IntelliMouse Explorer, device ID 4
vga0: <Generic ISA VGA> at port 0x3c0-0x3df iomem 0xa0000-0xbffff on isa0
sc0: <System console> at flags 0x100 on isa0
sc0: VGA <16 virtual consoles, flags=0x300>
sio0 at port 0x3f8-0x3ff irq 4 flags 0x10 on isa0
sio0: type 16550A
sio1 at port 0x2f8-0x2ff irq 3 on isa0
sio1: type 16550A
ppc0: parallel port not found.
APIC_IO: Testing 8254 interrupt delivery
APIC_IO: routing 8254 via IOAPIC #0 intpin 2
IP packet filtering initialized, divert enabled, rule-based forwarding enabled, default to accept, logging limited to 100 packets/entry by default
SMP: AP CPU #1 Launched!
SMP: AP CPU #2 Launched!
SMP: AP CPU #3 Launched!
acd0: CDROM <SAMSUNG CD-ROM SN-124> at ata1-master PIO4
Waiting 15 seconds for SCSI devices to settle
pass0 at iir0 bus 0 target 6 lun 0
pass0: <ESG-SHV SCA HSBP M19 0.07> Fixed Processor SCSI-2 device
da0 at iir0 bus 1 target 0 lun 0
da0: <IIR Host Drive   #00 > Fixed Direct Access SCSI-2 device
da0: Tagged Queueing Enabled
da0: 17461MB (35760690 512 byte sectors: 255H 63S/T 2226C)
da1 at iir0 bus 1 target 1 lun 0
da1: <IIR Host Drive   #01 > Fixed Direct Access SCSI-2 device
da1: Tagged Queueing Enabled
da1: 17461MB (35760690 512 byte sectors: 255H 63S/T 2226C)
Mounting root from ufs:/dev/da0s1a
em2: Link is up 100 Mbps Full Duplex
em3: Link is up 100 Mbps Full Duplex

Я понимаю, что много напихал и понимаю, что причина в диске скази(мне так кажется), но в утилитах сказевых я проверял их - там все ОК, диски нормальные!
Помогите разобраться.

2

Re: Падение системы BSD4.11

система перестала пускать меня по ssh, я полез в логи (там написано...) увидел всю эту хрень...сделал ребут, она после перезагрузки отказалась делать fsck сама - я руками сделал. Она гавкала на неправильный софтапдейт(я ничего НЕ делал!) и на плохие файлы в каталоге squid, предлагая их удалять, я с ней соглашался...она загрузилась...но ПРИЧИНЫ я так и не понял этого сбоя....
а началось все с того, что в логах она мне прислала вот это"iir0: Host Drive 0 not ready
iir0: General error on Host Drive 0"....я и полез....   ПРИЧЕМ, она гавкала и на HostDrive1...не только HostDrive0...просто на этом закончила....

3

Re: Падение системы BSD4.11

вот еще в логах...

Nov 10 03:03:16 jail /kernel: iir0: General error on Host Drive 1
Nov 10 03:03:45 jail last message repeated 26 times
Nov 10 03:05:46 jail last message repeated 115 times
Nov 10 03:15:46 jail last message repeated 597 times
Nov 10 03:25:46 jail last message repeated 596 times
те - ночью еще началось...  :-(

4

Re: Падение системы BSD4.11

а у тебя случаем райд не помер?
потом ругается на jail, проверь права доступа

5

Re: Падение системы BSD4.11

jail - это имя моего хоста....
а рейда у меня нет - просто два винта. На них разные разделы....я так разнес. Все работало вот уже год...с новым ядром меньше чуток и вот....  :-(

6

Re: Падение системы BSD4.11

iir0: <Intel Integrated RAID Controller> mem 0xfc7f0000-0xfc7f3fff irq 22 at device 8.0 on pci3

Он не читает(пишет что не может) девайс

iir0: General error on Host Drive 0
iir0: General error on Host Drive 0
iir0: General error on Host Drive 0
iir0: Host Drive 0 not ready
iir0: Host Drive 0 not ready

Значит делаем вывод - или помер рейд контроллер, или его включили как то не правильно.

7

Re: Падение системы BSD4.11

спасибо Саня, что ткнул файсом...правда... и остальным спасибо за помощь и поддержку! Буду дальше решать вопросы. Но уже ЗНАЧИТЕЛЬНО легче!  :-) Есть что руководству доложить внятно :-)

8

Re: Падение системы BSD4.11

Я прочел, что есть атаки, направленные на драйверы....совсем хацкеры ох...ли что ли??  :-((