Phylum

ssh debugging

Dec 28th, 2012
95
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. ## THIS IS PART OF A MUCH LARGER THREAD - PLEASE START HERE
  2. ## http://pastebin.com/KWZBSD4C
  3.  
  4. ## /var/log/messages
  5. Dec 28 06:50:18 daniel shutdown[4514]: shutting down for system halt
  6. Dec 28 06:50:18 daniel init: Switching to runlevel: 0
  7. Dec 28 06:50:26 daniel /etc/rc0.d/K87named: succeeded
  8. Dec 28 06:50:27 daniel auditd[1995]: The audit daemon is exiting.
  9. Dec 28 06:50:27 daniel kernel: [565270.177641] audit(1356695427.044:31): audit_pid=0 old=1995 by auid=4294967295 subj=kernel
  10. Dec 28 06:50:27 daniel kernel: Kernel logging (proc) stopped.
  11. Dec 28 06:50:27 daniel kernel: Kernel log daemon terminating.
  12. Dec 28 06:50:28 daniel exiting on signal 15
  13. Dec 28 07:19:27 daniel syslogd 1.4.1: restart.
  14. Dec 28 07:19:27 daniel kernel: klogd 1.4.1, log source = /proc/kmsg started.
  15. Dec 28 07:19:27 daniel kernel: [ 0.000000] Bootdata ok (command line is root=/dev/sda1 ro 4)
  16. Dec 28 07:19:27 daniel kernel: [ 0.000000] Linux version 2.6.18-xenU-ec2-v1.2 (root@domU-12-31-39-06-0D-E1) (gcc version 4.1.2 20070626 (Red Hat 4.1.2-13)) #2 SMP Wed Aug 19 12:57:15 UTC 2009
  17. Dec 28 07:19:27 daniel kernel: [ 0.000000] BIOS-provided physical RAM map:
  18. Dec 28 07:19:27 daniel kernel: [ 0.000000] Xen: 0000000000000000 - 000000006ac00000 (usable)
  19. Dec 28 07:19:27 daniel kernel: [8095159.065569] Built 1 zonelists. Total pages: 437248
  20. Dec 28 07:19:27 daniel kernel: [8095159.065574] Kernel command line: root=/dev/sda1 ro 4
  21. Dec 28 07:19:27 daniel kernel: [8095159.066173] Initializing CPU#0
  22. Dec 28 07:19:27 daniel kernel: [8095159.066287] PID hash table entries: 4096 (order: 12, 32768 bytes)
  23. Dec 28 07:19:27 daniel kernel: [8095159.066315] Xen reported: 1999.975 MHz processor.
  24. Dec 28 07:19:27 daniel kernel: [8095159.066330] Console: colour dummy device 80x25
  25. Dec 28 07:19:27 daniel kernel: [8095159.066746] Dentry cache hash table entries: 262144 (order: 9, 2097152 bytes)
  26. Dec 28 07:19:27 daniel kernel: [8095159.067352] Inode-cache hash table entries: 131072 (order: 8, 1048576 bytes)
  27. Dec 28 07:19:27 daniel kernel: [8095159.067576] Software IO TLB disabled
  28. Dec 28 07:19:27 daniel kernel: [8095159.075458] Memory: 1699320k/1748992k available (2235k kernel code, 40768k reserved, 782k data, 140k init)
  29. Dec 28 07:19:27 daniel kernel: [8095159.124357] Calibrating delay using timer specific routine.. 4003.82 BogoMIPS (lpj=2001913)
  30. Dec 28 07:19:27 daniel kernel: [8095159.124411] Security Framework v1.0.0 initialized
  31. Dec 28 07:19:27 daniel kernel: [8095159.124418] SELinux: Initializing.
  32. Dec 28 07:19:27 daniel kernel: [8095159.124434] SELinux: Starting in permissive mode
  33. Dec 28 07:19:27 daniel kernel: [8095159.124450] Mount-cache hash table entries: 256
  34. Dec 28 07:19:27 daniel kernel: [8095159.124562] CPU: L1 I cache: 32K, L1 D cache: 32K
  35. Dec 28 07:19:27 daniel kernel: [8095159.124568] CPU: L2 cache: 256K
  36. Dec 28 07:19:27 daniel kernel: [8095159.124571] CPU: L3 cache: 12288K
  37. Dec 28 07:19:27 daniel kernel: [8095159.124576] CPU: Unsupported number of the siblings 32<6>SMP alternatives: switching to UP code
  38. Dec 28 07:19:27 daniel kernel: [8095159.124762] Freeing SMP alternatives: 28k freed
  39. Dec 28 07:19:27 daniel kernel: [8095159.124835] Brought up 1 CPUs
  40. Dec 28 07:19:27 daniel kernel: [8095159.124841] migration_cost=0
  41. Dec 28 07:19:27 daniel kernel: [8095159.124922] checking if image is initramfs... it is
  42. Dec 28 07:19:27 daniel kernel: [8095159.126795] Freeing initrd memory: 3052k freed
  43. Dec 28 07:19:27 daniel kernel: [8095159.127549] NET: Registered protocol family 16
  44. Dec 28 07:19:27 daniel kernel: [8095159.128692] Brought up 1 CPUs
  45. Dec 28 07:19:27 daniel kernel: [8095159.128985] xen_mem: Initialising balloon driver.
  46. Dec 28 07:19:27 daniel kernel: [8095159.130859] NET: Registered protocol family 2
  47. Dec 28 07:19:27 daniel kernel: [8095159.139747] IP route cache hash table entries: 65536 (order: 7, 524288 bytes)
  48. Dec 28 07:19:27 daniel kernel: [8095159.139868] TCP established hash table entries: 262144 (order: 10, 4194304 bytes)
  49. Dec 28 07:19:27 daniel kernel: [8095159.141161] TCP bind hash table entries: 65536 (order: 8, 1048576 bytes)
  50. Dec 28 07:19:27 daniel kernel: [8095159.141475] TCP: Hash tables configured (established 262144 bind 65536)
  51. Dec 28 07:19:27 daniel kernel: [8095159.141481] TCP reno registered
  52. Dec 28 07:19:27 daniel kernel: [8095159.142058] audit: initializing netlink socket (disabled)
  53. Dec 28 07:19:27 daniel kernel: [8095159.142073] audit(1356697138.441:1): initialized
  54. Dec 28 07:19:27 daniel kernel: [8095159.142164] VFS: Disk quotas dquot_6.5.1
  55. Dec 28 07:19:27 daniel kernel: [8095159.142178] Dquot-cache hash table entries: 512 (order 0, 4096 bytes)
  56. Dec 28 07:19:27 daniel kernel: [8095159.142243] SELinux: Registering netfilter hooks
  57. Dec 28 07:19:27 daniel kernel: [8095159.145741] Initializing Cryptographic API
  58. Dec 28 07:19:27 daniel kernel: [8095159.145747] io scheduler noop registered (default)
  59. Dec 28 07:19:27 daniel kernel: [8095159.145756] io scheduler anticipatory registered
  60. Dec 28 07:19:27 daniel kernel: [8095159.145762] io scheduler deadline registered
  61. Dec 28 07:19:27 daniel kernel: [8095159.145770] io scheduler cfq registered
  62. Dec 28 07:19:27 daniel kernel: [8095159.160658] rtc: IRQ 8 is not free.
  63. Dec 28 07:19:27 daniel kernel: [8095159.161076] RAMDISK driver initialized: 16 RAM disks of 16384K size 1024 blocksize
  64. Dec 28 07:19:27 daniel kernel: [8095159.163949] Xen virtual console successfully installed as tty1
  65. Dec 28 07:19:27 daniel kernel: [8095159.163983] Event-channel device installed.
  66. Dec 28 07:19:27 daniel kernel: [8095159.206529] netfront: Initialising virtual ethernet driver.
  67. Dec 28 07:19:27 daniel kernel: [8095159.211285] i8042.c: No controller found.
  68. Dec 28 07:19:27 daniel kernel: [8095159.211326] mice: PS/2 mouse device common for all mice
  69. Dec 28 07:19:27 daniel kernel: [8095159.211332] md: md driver 0.90.3 MAX_MD_DEVS=256, MD_SB_DISKS=27
  70. Dec 28 07:19:27 daniel kernel: [8095159.211335] md: bitmap version 4.39
  71. Dec 28 07:19:27 daniel kernel: [8095159.211395] TCP bic registered
  72. Dec 28 07:19:27 daniel kernel: [8095159.211399] Initializing IPsec netlink socket
  73. Dec 28 07:19:27 daniel kernel: [8095159.211412] NET: Registered protocol family 1
  74. Dec 28 07:19:27 daniel kernel: [8095159.211418] NET: Registered protocol family 17
  75. Dec 28 07:19:27 daniel kernel: [8095159.217298] xen-vbd: registered block device major 8
  76. Dec 28 07:19:27 daniel kernel: [8095159.218686] sdh: sdh1
  77. Dec 28 07:19:27 daniel kernel: [8095159.220229] sdg: sdg1
  78. Dec 28 07:19:27 daniel kernel: [8095159.234858] netfront: device eth0 has copying receive path.
  79. Dec 28 07:19:27 daniel kernel: [8095159.258472] netfront: device eth1 has copying receive path.
  80. Dec 28 07:19:27 daniel kernel: [8095159.310736] XENBUS: Device with no driver: device/console/0
  81. Dec 28 07:19:27 daniel kernel: [8095159.310780] Freeing unused kernel memory: 140k freed
  82. Dec 28 07:19:27 daniel kernel: [8095159.620312] SCSI subsystem initialized
  83. Dec 28 07:19:27 daniel kernel: [8095159.670069] register_blkdev: cannot get major 8 for sd
  84. Dec 28 07:19:27 daniel kernel: [8095160.142630] kjournald starting. Commit interval 5 seconds
  85. Dec 28 07:19:27 daniel kernel: [8095160.142647] EXT3-fs: mounted filesystem with ordered data mode.
  86. Dec 28 07:19:27 daniel kernel: [8095165.721164] selinux_register_security: Registering secondary module capability
  87. Dec 28 07:19:27 daniel kernel: [8095165.721168] Capability LSM initialized as secondary
  88. Dec 28 07:19:27 daniel kernel: [8095165.745466] Floppy drive(s): fd0 is unknown type 15 (usb?), fd1 is unknown type 15 (usb?)
  89. Dec 28 07:19:27 daniel kernel: [8095165.745473] Failed to obtain physical IRQ 6
  90. Dec 28 07:19:27 daniel kernel: [8095168.755767] floppy0: no floppy controllers found
  91. Dec 28 07:19:27 daniel kernel: [8095168.964806] md: Autodetecting RAID arrays.
  92. Dec 28 07:19:27 daniel kernel: [8095168.964810] md: autorun ...
  93. Dec 28 07:19:27 daniel kernel: [8095168.964811] md: ... autorun DONE.
  94. Dec 28 07:19:27 daniel kernel: [8095168.977786] device-mapper: ioctl: 4.7.0-ioctl (2006-06-24) initialised: dm-devel@redhat.com
  95. Dec 28 07:19:27 daniel kernel: [8095169.049879] device-mapper: multipath: version 1.0.4 loaded
  96. Dec 28 07:19:27 daniel kernel: [8095169.776333] EXT3 FS on sda1, internal journal
  97. Dec 28 07:19:27 daniel kernel: [8095169.820731] kjournald starting. Commit interval 5 seconds
  98. Dec 28 07:19:27 daniel kernel: [8095169.821366] EXT3 FS on sdg1, internal journal
  99. Dec 28 07:19:27 daniel kernel: [8095169.821371] EXT3-fs: mounted filesystem with ordered data mode.
  100. Dec 28 07:19:27 daniel kernel: [8095169.834112] kjournald starting. Commit interval 5 seconds
  101. Dec 28 07:19:27 daniel kernel: [8095169.834811] EXT3 FS on sdh1, internal journal
  102. Dec 28 07:19:27 daniel kernel: [8095169.834815] EXT3-fs: mounted filesystem with ordered data mode.
  103. Dec 28 07:19:27 daniel kernel: [8095177.923181] loop: loaded (max 8 devices)
  104. Dec 28 07:19:27 daniel kernel: [8095178.298171] kjournald starting. Commit interval 5 seconds
  105. Dec 28 07:19:27 daniel kernel: [8095178.298213] EXT3 FS on loop0, internal journal
  106. Dec 28 07:19:27 daniel kernel: [8095178.298217] EXT3-fs: mounted filesystem with ordered data mode.
  107. Dec 28 07:19:27 daniel kernel: [8095178.422205] Loading iSCSI transport class v1.1-646.<5>iscsi: registered transport (tcp)
  108. Dec 28 07:19:27 daniel kernel: [8095178.741857] ip_tables: (C) 2000-2006 Netfilter Core Team
  109. Dec 28 07:19:27 daniel kernel: [8095178.762355] Netfilter messages via NETLINK v0.30.
  110. Dec 28 07:19:27 daniel kernel: [8095178.774321] ip_conntrack version 2.4 (8192 buckets, 65536 max) - 304 bytes per conntrack
  111. Dec 28 07:19:27 daniel kernel: [8095187.821764] audit(1356697167.122:2): audit_pid=2002 old=0 by auid=4294967295 subj=kernel
  112. Dec 28 07:19:59 daniel init: no more processes left in this runlevel
  113. Dec 28 08:14:50 daniel kernel: [8098510.866365] sshd[10962]: segfault at 00005554fd4d68a0 rip 00005554fd4d68a0 rsp 00007fffb05cd1e8 error 14
  114. Dec 28 08:18:26 daniel kernel: [8098727.426555] sshd[9595]: segfault at 0000555597c2c8a0 rip 0000555597c2c8a0 rsp 00007fff15e79b18 error 14
  115. Dec 28 09:05:53 daniel sshd[18292]: Server listening on 0.0.0.0 port 22.
  116. Dec 28 09:06:05 daniel kernel: [8101586.123735] sshd[18337]: segfault at 00005555c6a838a0 rip 00005555c6a838a0 rsp 00007fffe7021408 error 14
  117. Dec 28 10:04:19 daniel kernel: [8105080.190032] sshd[26161]: segfault at 00005554fd2418a0 rip 00005554fd2418a0 rsp 00007fffb0861c48 error 14
  118. Dec 28 10:05:51 daniel kernel: [8105171.946037] sshd[26176]: segfault at 000055557c5568a0 rip 000055557c5568a0 rsp 00007fff3154f1e8 error 14
  119. Dec 28 11:56:24 daniel kernel: [8111805.096347] sshd[3013]: segfault at 00005554d596d8a0 rip 00005554d596d8a0 rsp 00007fffd8135dc8 error 14
  120. Dec 28 11:57:50 daniel sshd[10747]: Did not receive identification string from 119.18.144.31
  121. Dec 28 12:05:32 daniel kernel: [8112353.069199] sshd[11574]: segfault at 00005555cf2378a0 rip 00005555cf2378a0 rsp 00007fffde86c508 error 14
  122. Dec 28 12:05:43 daniel kernel: [8112364.144714] sshd[12164]: segfault at 00005554dadf38a0 rip 00005554dadf38a0 rsp 00007fffd2cb0098 error 14
  123. Dec 28 12:05:45 daniel kernel: [8112365.967406] sshd[12167]: segfault at 000055551db278a0 rip 000055551db278a0 rsp 00007fff8ff7e368 error 14
  124. Dec 28 12:05:46 daniel kernel: [8112367.542307] sshd[12170]: segfault at 000055556a77b8a0 rip 000055556a77b8a0 rsp 00007fff43329708 error 14
  125. #EOF
  126.  
  127. ## `sshd -dddDp 19999` results
  128. Server listening on 0.0.0.0 port 19999.
  129. debug3: fd 4 is not O_NONBLOCK
  130. debug1: Server will not fork when running in debugging mode.
  131. debug3: send_rexec_state: entering fd = 7 config len 619
  132. debug3: ssh_msg_send: type 0
  133. debug3: send_rexec_state: done
  134. debug1: rexec start in 4 out 4 newsock 4 pipe -1 sock 7
  135. debug1: inetd sockets after dupping: 3, 3
  136. Connection from 10.0.0.74 port 37821
  137. debug2: load_server_config: filename /etc/ssh/sshd_config
  138. debug2: load_server_config: done config len = 619
  139. debug2: parse_server_config: config /etc/ssh/sshd_config len 619
  140. debug1: sshd version OpenSSH_4.3p2
  141. debug3: Not a RSA1 key file /etc/ssh/ssh_host_rsa_key.
  142. debug1: read PEM private key done: type RSA
  143. debug1: private host key: #0 type 1 RSA
  144. debug3: Not a RSA1 key file /etc/ssh/ssh_host_dsa_key.
  145. debug1: read PEM private key done: type DSA
  146. debug1: private host key: #1 type 2 DSA
  147. debug1: rexec_argv[0]='/usr/sbin/sshd'
  148. debug1: rexec_argv[1]='-dddDp'
  149. debug1: rexec_argv[2]='19999'
  150. debug2: fd 3 setting O_NONBLOCK
  151. debug1: Bind to port 19999 on 0.0.0.0.
  152. Server listening on 0.0.0.0 port 19999.
  153. debug3: fd 4 is not O_NONBLOCK
  154. debug1: Server will not fork when running in debugging mode.
  155. debug3: send_rexec_state: entering fd = 7 config len 619
  156. debug3: ssh_msg_send: type 0
  157. debug3: send_rexec_state: done
  158. debug1: rexec start in 4 out 4 newsock 4 pipe -1 sock 7
  159. debug1: inetd sockets after dupping: 3, 3
  160. Connection from 10.0.0.74 port 37823
  161. #EOF
  162.  
  163. ## /var/log/secure
  164. Dec 28 07:19:27 daniel sshd[2096]: debug2: fd 3 setting O_NONBLOCK
  165. Dec 28 07:19:27 daniel sshd[2096]: debug1: Bind to port 22 on 0.0.0.0.
  166. Dec 28 07:19:27 daniel sshd[2096]: Server listening on 0.0.0.0 port 22.
  167. Dec 28 08:14:50 daniel sshd[2096]: debug3: fd 4 is not O_NONBLOCK
  168. Dec 28 08:14:50 daniel sshd[10962]: debug1: rexec start in 4 out 4 newsock 4 pipe 6 sock 7
  169. Dec 28 08:14:50 daniel sshd[2096]: debug1: Forked child 10962.
  170. Dec 28 08:14:50 daniel sshd[2096]: debug3: send_rexec_state: entering fd = 7 config len 619
  171. Dec 28 08:14:50 daniel sshd[2096]: debug3: ssh_msg_send: type 0
  172. Dec 28 08:14:50 daniel sshd[2096]: debug3: send_rexec_state: done
  173. Dec 28 08:14:50 daniel sshd[10962]: debug1: inetd sockets after dupping: 3, 3
  174. Dec 28 08:14:50 daniel sshd[10962]: Connection from my.ip.add.ress port 21561
  175. Dec 28 09:05:53 daniel sshd[2096]: Received signal 15; terminating.
RAW Paste Data