mikeshinn wrote:Any other modules, BTW, that you like us to force load? I've also added in IPv6 and all its modules, Netbios and FUSE.
This would be nice
Code: Select all
Apr 10 08:28:44 server modprobe: FATAL: Error inserting cifs (/lib/modules/2.6.27.7-9.art.x86_64/kernel/fs/cifs/cifs.ko): Operation not permitted
But back on topic, if I set APF to not run in monolithic mode, and turn off kmod loading then I see this in messages
Code: Select all
Apr 10 08:27:09 ehost-services201 kernel: grsec: From 10.11.252.17: denied modification of module state by /sbin/modprobe[modprobe:5096] uid/euid:0/0 gid/egid:0/0, parent /etc/rc.d/init.d/iptables[iptables:5057] uid/euid:0/0 gid/egid:0/0
Apr 10 08:28:44 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:5537] uid/euid:0/0 gid/egid:0/0, parent /[khelper:5536] uid/euid:0/0 gid/egid:0/0
So apf cant start - however if I run it in monolithic mode and then try and start apf i see this
Code: Select all
Apr 10 08:31:24 ehost-services201 modprobe: FATAL: Error inserting xt_TCPMSS (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_TCPMSS.ko): Operation not permitted
Apr 10 08:31:24 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:6624] uid/euid:0/0 gid/egid:0/0, parent /[khelper:6623] uid/euid:0/0 gid/egid:0/0
Apr 10 08:31:24 ehost-services201 modprobe: FATAL: Error inserting iptable_mangle (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/ipv4/netfilter/iptable_mangle.ko): Operation not permitted
Apr 10 08:31:24 ehost-services201 modprobe: FATAL: Error inserting iptable_mangle (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/ipv4/netfilter/iptable_mangle.ko): Operation not permitted
Apr 10 08:31:24 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:6631] uid/euid:0/0 gid/egid:0/0, parent /[khelper:6630] uid/euid:0/0 gid/egid:0/0
Apr 10 08:31:24 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:6641] uid/euid:0/0 gid/egid:0/0, parent /[khelper:6640] uid/euid:0/0 gid/egid:0/0
Apr 10 08:31:24 ehost-services201 modprobe: FATAL: Error inserting iptable_mangle (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/ipv4/netfilter/iptable_mangle.ko): Operation not permitted
Apr 10 08:31:24 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:6648] uid/euid:0/0 gid/egid:0/0, parent /[khelper:6647] uid/euid:0/0 gid/egid:0/0
Apr 10 08:31:24 ehost-services201 modprobe: FATAL: Error inserting iptable_mangle (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/ipv4/netfilter/iptable_mangle.ko): Operation not permitted
Apr 10 08:31:25 ehost-services201 modprobe: FATAL: Error inserting iptable_mangle (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/ipv4/netfilter/iptable_mangle.ko): Operation not permitted
Apr 10 08:31:25 ehost-services201 modprobe: FATAL: Error inserting iptable_mangle (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/ipv4/netfilter/iptable_mangle.ko): Operation not permitted
Apr 10 08:31:28 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:31:35 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:7567] uid/euid:0/0 gid/egid:0/0, parent /[khelper:7566] uid/euid:0/0 gid/egid:0/0
Apr 10 08:31:35 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:31:35 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:7572] uid/euid:0/0 gid/egid:0/0, parent /[khelper:7571] uid/euid:0/0 gid/egid:0/0
Apr 10 08:31:35 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:31:35 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:7575] uid/euid:0/0 gid/egid:0/0, parent /[khelper:7574] uid/euid:0/0 gid/egid:0/0
Apr 10 08:31:35 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:31:35 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:7580] uid/euid:0/0 gid/egid:0/0, parent /[khelper:7579] uid/euid:0/0 gid/egid:0/0
Apr 10 08:31:35 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:31:35 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:7583] uid/euid:0/0 gid/egid:0/0, parent /[khelper:7582] uid/euid:0/0 gid/egid:0/0
Apr 10 08:31:35 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:31:35 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:31:45 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:8320] uid/euid:0/0 gid/egid:0/0, parent /[khelper:8319] uid/euid:0/0 gid/egid:0/0
Apr 10 08:31:45 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:31:45 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:8323] uid/euid:0/0 gid/egid:0/0, parent /[khelper:8322] uid/euid:0/0 gid/egid:0/0
Apr 10 08:31:45 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:31:45 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:31:45 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:8328] uid/euid:0/0 gid/egid:0/0, parent /[khelper:8327] uid/euid:0/0 gid/egid:0/0
Apr 10 08:31:45 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:8331] uid/euid:0/0 gid/egid:0/0, parent /[khelper:8330] uid/euid:0/0 gid/egid:0/0
Apr 10 08:31:45 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:31:45 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:8336] uid/euid:0/0 gid/egid:0/0, parent /[khelper:8335] uid/euid:0/0 gid/egid:0/0
Apr 10 08:31:45 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:31:45 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:31:45 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:31:55 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:9099] uid/euid:0/0 gid/egid:0/0, parent /[khelper:9098] uid/euid:0/0 gid/egid:0/0
Apr 10 08:31:55 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:31:57 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:31:57 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:9267] uid/euid:0/0 gid/egid:0/0, parent /[khelper:9266] uid/euid:0/0 gid/egid:0/0
Apr 10 08:31:57 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:31:57 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:9271] uid/euid:0/0 gid/egid:0/0, parent /[khelper:9270] uid/euid:0/0 gid/egid:0/0
Apr 10 08:31:57 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:9275] uid/euid:0/0 gid/egid:0/0, parent /[khelper:9274] uid/euid:0/0 gid/egid:0/0
Apr 10 08:31:57 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:31:57 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:9279] uid/euid:0/0 gid/egid:0/0, parent /[khelper:9278] uid/euid:0/0 gid/egid:0/0
Apr 10 08:31:57 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:31:57 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:32:03 ehost-services201 modprobe: FATAL: Error inserting ipt_LOG (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/ipv4/netfilter/ipt_LOG.ko): Operation not permitted
Apr 10 08:32:03 ehost-services201 modprobe: FATAL: Error inserting ipt_LOG (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/ipv4/netfilter/ipt_LOG.ko): Operation not permitted
Apr 10 08:32:08 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:10661] uid/euid:0/0 gid/egid:0/0, parent /[khelper:10660] uid/euid:0/0 gid/egid:0/0
Apr 10 08:32:08 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:32:08 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:10671] uid/euid:0/0 gid/egid:0/0, parent /[khelper:10670] uid/euid:0/0 gid/egid:0/0
Apr 10 08:32:08 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:32:08 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:10681] uid/euid:0/0 gid/egid:0/0, parent /[khelper:10680] uid/euid:0/0 gid/egid:0/0
Apr 10 08:32:08 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:32:08 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:10691] uid/euid:0/0 gid/egid:0/0, parent /[khelper:10690] uid/euid:0/0 gid/egid:0/0
Apr 10 08:32:08 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:32:08 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:32:08 ehost-services201 kernel: grsec: denied modification of module state by /sbin/modprobe[modprobe:10701] uid/euid:0/0 gid/egid:0/0, parent /[khelper:10700] uid/euid:0/0 gid/egid:0/0
Apr 10 08:32:09 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:32:09 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:32:09 ehost-services201 modprobe: FATAL: Error inserting xt_multiport (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_multiport.ko): Operation not permitted
Apr 10 08:32:10 ehost-services201 modprobe: FATAL: Error inserting xt_limit (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/netfilter/xt_limit.ko): Operation not permitted
Apr 10 08:32:10 ehost-services201 modprobe: FATAL: Error inserting iptable_mangle (/lib/modules/2.6.27.7-9.art.x86_64/kernel/net/ipv4/netfilter/iptable_mangle.ko): Operation not permitted
So ideally it would be great if all of those firewall modules needed are auto loaded
I know its because the kmod loading is off and I attempted to do this after boot, I just wanted to see which modules they were.