LawsHosting
Verified User
I know this isn't DA related.
Saw a server constantly at 5.0 load, which was the result of ProFTP hogging 95% of cpu. So I killed the processes, then looked at the auth.log and saw tons of these every second:
So, was this a hack attempt or something else? This is the first time this has happed. Some insight would be appreciated.
Saw a server constantly at 5.0 load, which was the result of ProFTP hogging 95% of cpu. So I killed the processes, then looked at the auth.log and saw tons of these every second:
Blocked the IPs and started ProFTP, all okay at the moment, load is back down and cpu temps are back to normal.Nov 9 11:31:28 server3 kernel: grsec: From 188.165.212.60: Illegal instruction occurred at 0804d23c in /usr/sbin/proftpd[proftpd:12262] uid/euid:0/107 gid/egid:110/110, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0
Nov 9 11:31:28 server3 kernel: grsec: From 129.217.228.120: Illegal instruction occurred at 0804d23c in /usr/sbin/proftpd[proftpd:2706] uid/euid:0/107 gid/egid:110/110, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0
N
So, was this a hack attempt or something else? This is the first time this has happed. Some insight would be appreciated.
Last edited: