OpenVZ Forum


Home » General » Support » Numerous segmentation faults on VE start
Numerous segmentation faults on VE start [message #22227] Tue, 23 October 2007 21:15 Go to next message
sgwestrip is currently offline  sgwestrip
Messages: 4
Registered: March 2007
Junior Member
I am getting these errors when I try to start this VE. I can enter the VE but the network has not started. I have done a vzcfgvalidate and all seems OK there and I am now completely out of ideas. This is the first VE that has ever caused me any persistent problems. Any help would be gratefully received.

[root@virtual2 ~]# vzctl start 211
Starting VE ...
VE is mounted
Adding IP address(es): 10.0.0.101
bash: line 360: 19791 Segmentation fault      mkdir -p ${IFCFG_DIR}
bash: line 291: 19792 Segmentation fault      grep -qE '191.255.255.[0-1]' $file
bash: line 360: 19793 Segmentation fault      grep -q "${FAKEGATEWAYNET}/24 dev ${VENET_DEV}" ${ROUTE} 2>/dev/null
bash: line 61: 19794 Segmentation fault      grep -E "^$name=.*" $file >/dev/null 2>&1
bash: line 61: 19795 Segmentation fault      grep -E "^$name=.*" $file >/dev/null 2>&1
bash: line 344: 19796 Segmentation fault      grep -q 'if \[ "\${DEVICE}" = "lo" \]; then' ${file} 2>/dev/null
bash: line 458: 19798 Segmentation fault      mkdir -p ${IFCFG_DIR}/bak
Execution timeout expired
Got signal 15
Setting CPU units: 50788
Configure meminfo: 620921
Set hostname: sane.m4.net
bash: line 330: 19829 Segmentation fault      grep -q -E "[[:space:]]${val}" ${cfgfile} 2>/dev/null
bash: line 330: 19830 Done                    echo "${val}"
     19831 Segmentation fault      | grep "\." >/dev/null 2>&1
bash: line 152: 19832 Segmentation fault      grep -E "^\<$name\>" $file >/dev/null 2>&1
bash: line 61: 19833 Segmentation fault      grep -E "^$name=.*" $file >/dev/null 2>&1
File resolv.conf was modified
VE start in progress...


Many thanks,
Stephen Westrip
Re: Numerous segmentation faults on VE start [message #22253 is a reply to message #22227] Wed, 24 October 2007 06:39 Go to previous messageGo to next message
rickb is currently offline  rickb
Messages: 368
Registered: October 2006
Senior Member
When I see this, the VE has been compromised and a rootkit yielding non runnable binaries are instaled. check binary md5's against your latest backup and/or template.



-------------
Common Terms I post with: http://wiki.openvz.org/Category:Definitions

UBC. Learn it, love it, live it: http://wiki.openvz.org/Proc/user_beancounters
Re: Numerous segmentation faults on VE start [message #22306 is a reply to message #22253] Wed, 24 October 2007 16:08 Go to previous messageGo to next message
sgwestrip is currently offline  sgwestrip
Messages: 4
Registered: March 2007
Junior Member
Thank you for your reply.

It seems as though this VE was compromised with a rootkit named 'Whatis' and had changed 20 or so binaries in /bin. What is more alarming is that from the VE it had managed to changed the same binaries in /bin on the hardware node. I was surprised that this was even possible from the VE.

Anyway, it is all sorted out now. Thanks for pointing me in the right direction.

Stephen Westrip
Re: Numerous segmentation faults on VE start [message #22309 is a reply to message #22306] Wed, 24 October 2007 16:40 Go to previous message
dev is currently offline  dev
Messages: 1693
Registered: September 2005
Location: Moscow
Senior Member

it is almost impossible to get out of the VE chroot, so most likely you were simply hacked twice in VE and HN.

BTW, recently there was a severe x8664 kernel flaw, it could be used to hack you. So don't forget to upgrade kernel.


http://static.openvz.org/userbars/openvz-developer.png
Previous Topic: *SOLVED* Quotas with cPanel
Next Topic: *SOLVED* command history
Goto Forum:
  


Current Time: Mon Aug 12 17:16:45 GMT 2024

Total time taken to generate the page: 0.02920 seconds