Security Basics mailing list archives

Re: System Monitor


From: xyberpix <xyberpix () xyberpix com>
Date: Sun, 29 Jan 2006 13:43:16 +0000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Try downloading and running chrootkit, and see if that show anything untowards at all.

xyberpix

Blog: http://blogs.securiteam.com



On 26 Jan 2006, at 17:39, Gabriel Orozco wrote:

Hello Every buddy

I'm checking another computer on the network. thats has an stranger behavior. Let me explain

This is a Linux/Debian computer installed some 9 days ago. Assigned user want to run Moodle on it. But they called me asking why with 40 users the server went to top processor and memory. Hardware is a Sun-Ultra, with 2GB of RAM, and plenty of scsi disk space...

The problem:
when I run "top" I have between 43% to 52% of processor used by "Sys" (System Tasks)
and I cannot identify what is taking these process power.
top does not give anything using the system
nothing is being transfered (checked with iptraf)
no disk usage (using iostat)
no root kits, checked with ckrootkit some minutes ago
no programs listening, checked with netstat

I don't know which tool can help me to find the problem.
I know there should be one and am surfing freshmeat.net, but I can happily accept any help you can give

Thanks in advance

Gabriel Orozco

---------------------------------------------------------------------- -----
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The Norwich University program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Tailor your education to your own professional goals with degree
customizations including Emergency Management, Business Continuity Planning,
Computer Emergency Response Teams, and Digital Investigations.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------- -----

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (Darwin)

iD8DBQFD3MZ12VKEoIQBZwkRAilrAKCuCqy5240s80t6/3TSnMK/k9LewgCgm0G/
8wnnAAYp3nn8Ko9qFNI9mcY=
=70dZ
-----END PGP SIGNATURE-----

---------------------------------------------------------------------------
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The Norwich University program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Tailor your education to your own professional goals with degree customizations including Emergency Management, Business Continuity Planning, Computer Emergency Response Teams, and Digital Investigations.
http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------


Current thread: