I've been running Solaris 2.6 servers for years now and haven't done
any patches for at least 4 years because the servers have been totally
stable. In the last week however, in.telnet and in.ftp has died sort
of randomly on all 5 of my servers...and when I reboot telnet and ftp
run for about 10 minutes, then die again sort of randomly. Seems to
be sort of random. All of my 2.6 servers are doing this now and a
reboot fixes the problem for only a short time.
There's nothing in the messages or error logs and each of the 5
systems are running different apps, so nothing common I can think
of.
I probably should mention that I have several other Unix servers
running Solaris 2.7 and 2.8, however none of those have the problem.
It's very suspicious, however nothing malicious has happened.
I've also rebooted and watch the system for a while while running
netstat in another window, but I never see any connections come into
the system or anyone login.
It's really odd because there is simply no trace of what could be
killing telnet and ftp...
Anyone have a clue where I can look for this?
If you have any ideas, please reply and/or write to
tdenham@airnetcom.com.
|
|
0
|
|
|
|
Reply
|
tdenham735 (37)
|
3/1/2007 12:05:54 AM |
|
On Mar 1, 12:05 am, tdenham...@gmail.com wrote:
> I've been running Solaris 2.6 servers for years now and haven't done
> any patches for at least 4 years because the servers have been totally
> stable. In the last week however, in.telnet and in.ftp has died sort
> of randomly on all 5 of my servers...and when I reboot telnet and ftp
> run for about 10 minutes, then die again sort of randomly. Seems to
> be sort of random. All of my 2.6 servers are doing this now and a
> reboot fixes the problem for only a short time.
>
I wonder if something is trying to exploit the Solaris 10 telnet
vulnerability and causing these to die? There is a known worm, I
think. Are there lots of attempted telnet connections?
|
|
0
|
|
|
|
Reply
|
Tim
|
3/1/2007 12:21:47 PM
|
|
On Mar 1, 7:21 am, "Tim Bradshaw" <tfb+goo...@tfeb.org> wrote:
> On Mar 1, 12:05 am, tdenham...@gmail.com wrote:
>
> > I've been running Solaris 2.6 servers for years now and haven't done
> > any patches for at least 4 years because the servers have been totally
> > stable. In the last week however, in.telnet and in.ftp has died sort
> > of randomly on all 5 of my servers...and when I reboot telnet and ftp
> > run for about 10 minutes, then die again sort of randomly. Seems to
> > be sort of random. All of my 2.6 servers are doing this now and a
> > reboot fixes the problem for only a short time.
>
> I wonder if something is trying to exploit the Solaris 10 telnet
> vulnerability and causing these to die? There is a known worm, I
> think. Are there lots of attempted telnet connections?
Running snoop does not show a lot of attempts...the strange thing
is...why only Solaris 2.6??? The others are just fine???
|
|
0
|
|
|
|
Reply
|
tdenham735
|
3/1/2007 1:19:24 PM
|
|
On Mar 1, 1:19 pm, tdenham...@gmail.com wrote:
> Running snoop does not show a lot of attempts...the strange thing
> is...why only Solaris 2.6??? The others are just fine???
Well, I was thinking that may be the 2.6 one dies, but the later ones
(until 10) are immune to even that.
Another thing to do which I just thought of would be to truss the
daemon, though it's often pretty hard to find out what happened from
truss traces, and you'll have the usual `stupid amount of output'
problem. I suspect if you could see that it had just accepted (or
rejected) a connection when it fell over that might be informative.
DTrace is what you really need :-)
--tim
|
|
0
|
|
|
|
Reply
|
Tim
|
3/1/2007 2:15:09 PM
|
|
|
3 Replies
110 Views
(page loaded in 0.141 seconds)
Similiar Articles: Block tcp/25 Services (telnet host 25) - comp.unix.solaris ...... drop the TCP connection on a libwrap denied host (which is the behavior ... comp.lang.awk Block tcp/25 Services (telnet host 25) - comp.unix.solaris ... script for telnet ... Login as root via Telnet - comp.unix.solarisOn Thu, 2 Mar 2006, tonij67@hotmail.com wrote: > That is strange ... Unable to telnet to my machine - comp.unix.solaris I'm unable to ping/ftp/telnet to other machines ... Solaris 10, PuTTY, and vi - comp.unix.solaris... the same Solaris 10 box, TERM=cygwin I get the same behavior ... strange term type in step #2, or (most ... since Solaris 2.5 (1995) that I had to fix on 2.5, 2.5.1, 2.6, 7 ... ftp problem - HPUX 11.11 - comp.sys.hp.hpuxIt doesn't exist in Solaris 8 but does in Solaris ... telnet/ftp problem - comp.sys.hp.hpux... closed by ... The File Transfer Protocol has held up remarkably well ... TCP timeout on Solaris 9? - comp.unix.solaristelnet/ftp session timeout - comp.unix.solaris hi whenever i did ... Query regarding behavior of IKE/IPSec in Solaris-9 ... TCP timeout on Solaris 9? - comp.unix.solaris Strange ... remote X session from Linux to HPUX - comp.sys.hp.hpuxHow exactly do you want the keypad to behavior? Linux provides ... telnet/ftp session timeout - comp.unix.solaris... problem - comp.sys.hp.hpux telnet/ftp session ... comp.unix.solaris - page 23strange multithreaded read() behavior 4 68 (7/9/2003 6:08:46 AM) I ... 7/10/2003 6:37:15 AM) hi this is propably lame but i am newbie in unix. i start ftp service on solaris ... HP-UX 10.20 - comp.sys.hp.hpux> All works ok ... ftp, telnet (after running inetd manually) that's really strange because the startup script(s ... comp.sys.hp.hpux How to change the Locale on Solaris and ... script for telnet on port 25 - comp.lang.awk... ignoring SIGALRM would give useful behavior ... redirecting output from telnet - comp.unix.solaris script for ... on port 25 - comp.lang.awk... when I telnet PUBLIC IP #2 ... Problems with nslookup - comp.unix.solaris... domain DNS Server is Windows 2000, DNS client Solaris 2.8. ... files dns >>... > > as it should look > > Real strange ... Ron Nutter shows you how to use Nslookup and Telnet to ... comp.unix.solaris: ftp / telnet problems: connection refusedRe: Solaris 2.6 in.telnet/ftp strange behavior... Another thing to do which I just thought of would be to truss the ... was in Solaris 6, just to see if telnet or ftp are ... Solaris 2 FAQ - - Home - Universiteit van Amsterdam... owned by ftp. If they are, anonymous users can modify them. In Solaris 2.5 ... Solaris 2.6 and earlier have telnet/rlogin ... default in Solaris. If you're in an unusual ... 7/28/2012 9:02:51 AM
|