[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-users] DoS?



Few days ago my Raq4i sent me the following message, march 12th, 11:05 am

Memory on the Cobalt server is heavily used.
The Cobalt server needs more memory than it currently has.
Consider adding more DRAM to the server.

Total memory is:	259572 KB
Used memory is:	253904 KB
Free memory is:	5668 KB
Percent used is:	97

This spike last only a few minutes.

The nasty thing is the server still is almost empty and the usual CPU load
is less than 1%.

When checked the log and diagnostic files content generated at the same time
the server sent the alarm email I could find the following lines:

-rw-------   1 root     root       994802 Mar 12 11:05 /var/log/messages
.
.
.
Mar 12 11:05:50 rm1 named[23572]: master zone "69.155.208.in-addr.arpa" (IN)
loaded (serial 2001030123)
Mar 12 11:05:50 rm1 named[23572]: listening on [127.0.0.1].53 (lo)
Mar 12 11:05:50 rm1 named[23572]: listening on [My IP1].53 (eth0)
Mar 12 11:05:50 rm1 named[23572]: listening on [My IP2].53 (eth0:0)
Mar 12 11:05:50 rm1 named[23572]: listening on [My IP3].53 (eth0:1)
Mar 12 11:05:50 rm1 named[23572]: listening on [My IP4].53 (eth0:2)
Mar 12 11:05:50 rm1 named[23572]: Forwarding source address is
[0.0.0.0].1031
Mar 12 11:05:50 rm1 named[23573]: Ready to answer queries.
.
.
root     23476  0.0  0.6  1692  816 ?        S    11:05   0:00
/home/chiliasp/ad
root     23479  0.0  0.6  1692  816 ?        S    11:05   0:00
/home/chiliasp/ad
root     23480  0.0  0.6  1692  816 ?        S    11:05   0:00
/home/chiliasp/ad
root     23485  0.0  4.0  7044 5172 ?        S    11:05   0:00
/home/chiliasp/ad
root     23495  0.0  4.0  7044 5172 ?        S    11:05   0:00
/home/chiliasp/ad
root     23496  0.0  4.0  7044 5172 ?        S    11:05   0:00
/home/chiliasp/ad
root     23573  0.0  1.2  2520 1616 ?        S    11:05   0:00 named
root     23595  0.0  1.0  2596 1348 ?        S    11:06   0:00 sendmail:
accepti
.
.
.
 I hope somebody here could tell me what happened. Dos? Spam?

Thanks a lot

Rodrigo Velasco