BB Unix Network Monitor - Message

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

{bb} Proc not supposed to run, still never red



Forgive me if this is already in the mail-archive, but I couldn't find it
with things like "yellow down procs", which is really no wonder. Didn't know
how to describe the problem good enough to find it with ht-dig.


In bb-proctab the syntax is
server : make yellow : make red

I have a proc that is NOT supposed to run, so I use !ftpd of ftpd;0

If I put it in "make yellow" and the proc DOES run, it gives me yellow.
Fine.

If I put it in "make red" and the proc DOES run, it gives me yellow.
Not fine.

Sometimes I also put a slash in front of the process, i.e. smbd (normal
samba) is supposed to run, but /smbd (note the slash) would be some
rootshell put there by a hacker and is NOT supposed to run. I put in
pbb-proctab:
localhost : bla bla2 : !/smbd

Now even if some blackhat started ./smbd in some directory (this is an
actual case), it still only gives me yellow instead of red. I tried it on
the "make yellow" place, it also gives me yellow. It also makes no
difference if I use ! of ;0

Tried it on several redhat versions, bb is bb19e.

Am I doing something wrong, or am I submitting a bug here?

Groeten,
Stefan Elsinga


--
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-=-=-=-=-=-=-=-=-=
To unsubscribe from this list, or to subscribe to the bb-digest list
send e-mail to mailto:majordomo@bb4.com with unsubscribe bb -and/or-
subscribe bb-digest in the BODY of the message.


Home | Main Index | Thread Index