This is a discussion on Strange activity on my server within the Linux Security forums, part of the System Security and Security Related category; My server have been crashing/slow lately. Today I got the following information from top: $ uname -a Linux XXX 2....
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
My server have been crashing/slow lately. Today I got the following
information from top: $ uname -a Linux XXX 2.6.10-1.770_FC2smp #1 SMP Sat Feb 26 21:54:45 EST 2005 i686 i686 i386 GNU/Linux $ top top - 18:28:33 up 10:06, 1 user, load average: 0.00, 0.00, 0.00 Tasks: 81 total, 1 running, 80 sleeping, 0 stopped, 0 zombie Cpu(s): 0.0% us, 0.0% sy, 0.0% ni, 100.0% id, 0.0% wa, 0.0% hi, 0.0% si Mem: 1034696k total, 1017076k used, 17620k free, 206272k buffers Swap: 2040212k total, 0k used, 2040212k free, 574508k cached PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND 1 root 16 0 2256 460 392 S 0.0 0.0 0:01.25 init 2 root RT 0 0 0 0 S 0.0 0.0 0:00.05 migration/0 3 root 34 19 0 0 0 S 0.0 0.0 0:00.03 ksoftirqd/0 4 root RT 0 0 0 0 S 0.0 0.0 0:00.07 migration/1 5 root 34 19 0 0 0 S 0.0 0.0 0:00.01 ksoftirqd/1 6 root RT 0 0 0 0 S 0.0 0.0 0:00.27 migration/2 7 root 34 19 0 0 0 S 0.0 0.0 0:00.05 ksoftirqd/2 8 root RT 0 0 0 0 S 0.0 0.0 0:00.06 migration/3 9 root 34 19 0 0 0 S 0.0 0.0 0:00.02 ksoftirqd/3 10 root 5 -10 0 0 0 S 0.0 0.0 0:00.53 events/0 11 root 5 -10 0 0 0 S 0.0 0.0 0:00.60 events/1 12 root 5 -10 0 0 0 S 0.0 0.0 0:00.57 events/2 13 root 5 -10 0 0 0 S 0.0 0.0 0:00.45 events/3 14 root 6 -10 0 0 0 S 0.0 0.0 0:00.01 khelper 29 root 15 -10 0 0 0 S 0.0 0.0 0:00.00 kacpid 134 root 5 -10 0 0 0 S 0.0 0.0 0:00.01 kblockd/0 135 root 5 -10 0 0 0 S 0.0 0.0 0:00.05 kblockd/1 136 root 5 -10 0 0 0 S 0.0 0.0 0:00.05 kblockd/2 137 root 5 -10 0 0 0 S 0.0 0.0 0:00.00 kblockd/3 145 root 15 0 0 0 0 S 0.0 0.0 0:00.00 khubd 205 root 15 0 0 0 0 S 0.0 0.0 0:00.00 pdflush 206 root 15 0 0 0 0 S 0.0 0.0 0:00.33 pdflush 208 root 11 -10 0 0 0 S 0.0 0.0 0:00.00 aio/0 207 root 15 0 0 0 0 S 0.0 0.0 0:00.96 kswapd0 209 root 11 -10 0 0 0 S 0.0 0.0 0:00.00 aio/1 210 root 11 -10 0 0 0 S 0.0 0.0 0:00.00 aio/2 211 root 11 -10 0 0 0 S 0.0 0.0 0:00.00 aio/3 303 root 25 0 0 0 0 S 0.0 0.0 0:00.00 kseriod 504 root 22 0 0 0 0 S 0.0 0.0 0:00.00 scsi_eh_0 505 root 15 0 0 0 0 S 0.0 0.0 0:00.00 aacraid 521 root 15 0 0 0 0 S 0.0 0.0 0:00.30 kjournald 684 root 6 -10 2904 304 224 S 0.0 0.0 0:00.04 udevd 1877 root 15 0 0 0 0 S 0.0 0.0 0:00.00 kjournald 1878 root 15 0 0 0 0 S 0.0 0.0 0:00.25 kjournald 3202 root 16 0 1896 600 504 S 0.0 0.1 0:00.10 syslogd 3206 root 16 0 2600 444 380 S 0.0 0.0 0:00.00 klogd 3217 root 16 0 2616 456 384 S 0.0 0.0 0:00.00 irqbalance $ lsmod Module Size Used by parport_pc 29573 0 lp 15405 0 parport 37513 2 parport_pc,lp autofs4 21829 0 tg3 79557 0 ipt_REJECT 10561 1 ipt_state 5953 11 ip_conntrack 45829 1 ipt_state iptable_filter 7617 1 ip_tables 21185 3 ipt_REJECT,ipt_state,iptable_filter ip6table_filter 6721 1 ip6_tables 21825 1 ip6table_filter md5 8001 1 ipv6 240225 26 floppy 56913 0 sg 38881 0 microcode 11489 0 dm_mod 58181 0 joydev 13057 0 ohci_hcd 24277 0 video 19653 0 button 10577 0 battery 13253 0 ac 8773 0 ext3 121929 3 jbd 57561 1 ext3 aacraid 44241 4 sd_mod 19905 5 scsi_mod 116289 3 sg,aacraid,sd_mod $ I don't know what 'migration' is, but it seems very strange that anything on this general server has a real-time priority! I don't recall any kernel code 'migration'. Can anyone enlighten me? I have examined my log files and roon chkrootkit, but have seen nothing about this. (Let me know if any other details would be helpful, I'll post a followup.) -Wayne |