BB Unix Network Monitor - Message
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
{bb} Proc not supposed to run, still never red
- To: <bb@bb4.com>
- Subject: {bb} Proc not supposed to run, still never red
- From: "Stefan Elsinga" <s.y.elsinga@fac.nhl.nl>
- Date: Mon, 21 Jun 2004 19:35:18 +0200
- Content-transfer-encoding: 7bit
- Content-type: text/plain; charset="Windows-1252"
- Organization: Noordelijke Hogeschool Leeuwarden
- Reply-to: bb@bb4.com
- Sender: owner-bb@bb4.com
Forgive me if this is already in the mail-archive, but I couldn't find it
with things like "yellow down procs", which is really no wonder. Didn't know
how to describe the problem good enough to find it with ht-dig.
In bb-proctab the syntax is
server : make yellow : make red
I have a proc that is NOT supposed to run, so I use !ftpd of ftpd;0
If I put it in "make yellow" and the proc DOES run, it gives me yellow.
Fine.
If I put it in "make red" and the proc DOES run, it gives me yellow.
Not fine.
Sometimes I also put a slash in front of the process, i.e. smbd (normal
samba) is supposed to run, but /smbd (note the slash) would be some
rootshell put there by a hacker and is NOT supposed to run. I put in
pbb-proctab:
localhost : bla bla2 : !/smbd
Now even if some blackhat started ./smbd in some directory (this is an
actual case), it still only gives me yellow instead of red. I tried it on
the "make yellow" place, it also gives me yellow. It also makes no
difference if I use ! of ;0
Tried it on several redhat versions, bb is bb19e.
Am I doing something wrong, or am I submitting a bug here?
Groeten,
Stefan Elsinga
--
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-=-=-=-=-=-=-=-=-=
To unsubscribe from this list, or to subscribe to the bb-digest list
send e-mail to mailto:majordomo@bb4.com with unsubscribe bb -and/or-
subscribe bb-digest in the BODY of the message.
Home |
Main Index |
Thread Index