Suspicious grsec message on logs

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

Suspicious grsec message on logs

Postby superbock » Thu Mar 24, 2005 12:56 am

Has anyone seen a message like this?

Mar 24 04:13:50 oopslala kernel: grsec: From xx.xx.xx.xx: (default:D:/usr/sbin/httpd) denied send of signal 14 to protected task /usr/sbin/sshd[sshd:30486] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 by /usr/sbin/httpd[httpd:29067] uid/euid:48/48 gid/egid:48/48, parent /usr/sbin/httpd[httpd:2844] uid/euid:0/0 gid/egid:0/0

I'm using 2.4.29 and latest 2.1.4. Can't quite see why httpd would send a 14 to sshd, and i found nothing suspicious about the IP in question, just normal site browsing.

What could this mean? Maybe some weird grsec misunderstanding?!

Any input is appreciated.
superbock
 
Posts: 37
Joined: Sun Mar 31, 2002 6:34 pm

Postby spender » Thu Mar 24, 2005 1:11 am

sig 14 = SIGALRM. I'm not sure why apache would be doing that, but it at least seems rather harmless.

-Brad
spender
 
Posts: 2185
Joined: Wed Feb 20, 2002 8:00 pm

Postby Einon » Thu Jan 19, 2006 6:33 am

Hi!

Is there a way to filter these messages?
My syslog is flooded with them...
Einon
 
Posts: 10
Joined: Tue Mar 22, 2005 6:40 am


Return to grsecurity support

cron