Page 1 of 1

Suspicious grsec message on logs

PostPosted: Thu Mar 24, 2005 12:56 am
by superbock
Has anyone seen a message like this?

Mar 24 04:13:50 oopslala kernel: grsec: From xx.xx.xx.xx: (default:D:/usr/sbin/httpd) denied send of signal 14 to protected task /usr/sbin/sshd[sshd:30486] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /usr/sbin/httpd[httpd:29067] uid/euid:48/48 gid/egid:48/48, parent /usr/sbin/httpd[httpd:2844] uid/euid:0/0 gid/egid:0/0

I'm using 2.4.29 and latest 2.1.4. Can't quite see why httpd would send a 14 to sshd, and i found nothing suspicious about the IP in question, just normal site browsing.

What could this mean? Maybe some weird grsec misunderstanding?!

Any input is appreciated.

PostPosted: Thu Mar 24, 2005 1:11 am
by spender
sig 14 = SIGALRM. I'm not sure why apache would be doing that, but it at least seems rather harmless.

-Brad

PostPosted: Thu Jan 19, 2006 6:33 am
by Einon
Hi!

Is there a way to filter these messages?
My syslog is flooded with them...