Re: ASL Kernel (grsec) breaks Plesk Licence Key Update
Posted: Thu Sep 30, 2010 1:24 pm
What does Parallels say about that error with their product?
Security for Everyone
https://forums.atomicorp.com/
Disabling TPE did not solve your problem? If thats true, then the problem is not with the kernel - you can only get that message if TPE is enabled. So if you got that message you did not disable TPE. As I recall, you previously did not set the execute bit on the init script, so its likely your problem is as simple as that.The above steps are difficult, complicated and last time I initiated them - they did not solve the problem.
Please email support@atomicorp.com if you want professional services to send you a quote for this.I offer you the opportunity to access my system and initiate the above, thereby allowing you to assess the efficiency of the solution.
In Linux you should just configure your system to not boot into it the ASL kernel - removing kernels in Linux is dangerous:I think I would prefer to uninstall the ASL Kernel.
This is not an error, this is a protection message. So yes, if you boot into a non-ASL kernel this protection message will go away and your non-ASL kernel will now be vulnerable to kernel level rootkits, so yes, that would get rid of this protection and therefore this message.Uninstalling the kernel should also deal with these warnings, yes?
Oct 25 00:00:04 loft2234 kernel: grsec: denied kernel module auto-load of net-pf-10 by /usr/sbin/httpd[httpd:26479] uid/euid:48/48 gid/egid:48/48, parent /usr/sbin/httpd[httpd:13969] uid/euid:0/0 gid/egid:0/0
No idea. If you disabled TPE and Dr. Web still didnt work, then no - thats a Parallels issue.Removing GRSEC should solve my Dr. Web License update problem, correct?
We do not recommend you uninstall Linux kernels unless you know what you are doing - Linux is not really designed to do this its very dangerous. You are better off just telling your system to boot into a different kernel:How do I uninstall the ASL kernel?
So if I understand you correctly, you disabled TPE and you are not getting a grsec message? If so, then ASL is not the source of your difficulties with Dr. Web.I had already implemented option 4. The grsec-related error is no longer. However the license update issue persists
Don't remove the kernel (never do that, its dangerous and you can end up making your system unbootable), just set your system to boot into another kernel. The process is pretty simple in Linux. You can even do it when the system boots from the boot manager menu.But, again, removing the kernel seems very complicated, if this ends up being the solution. Waiting to see what Parallels say...
Is clamav used by asl?The ClamAV update process (freshclam daemon) was not running!
If you no longer wish to run freshclam, deleting the freshclam.log file will suppress this error message.
Code: Select all
################### Logwatch 7.3 (03/24/06) ####################
Processing Initiated: Tue Oct 26 04:02:14 2010
Date Range Processed: yesterday
( 2010-Oct-25 )
Period is day.
Detail Level of Output: 0
Type of Output: unformatted
Logfiles for Host:
##################################################################
--------------------- clam-update Begin ------------------------
The ClamAV update process (freshclam daemon) was not running!
If you no longer wish to run freshclam, deleting the freshclam.log
file will suppress this error message.
---------------------- clam-update End -------------------------
--------------------- Clamav Begin ------------------------
**Unmatched Entries**
Not loading PUA signatures.
Loaded 1761816 signatures.
TCP: Bound to address 127.0.0.1 on port 3310
TCP: Setting connection queue length to 30
LOCAL: Unix socket file /tmp/clamd.socket
LOCAL: Setting connection queue length to 30
Limits: Global size limit set to 104857600 bytes.
Limits: File size limit set to 26214400 bytes.
Limits: Recursion level limit set to 16.
Limits: Files limit set to 10000.
Algorithmic detection enabled.
Database correctly reloaded (1761816 signatures)
Not loading PUA signatures.
Loaded 1761816 signatures.
TCP: Bound to address 127.0.0.1 on port 3310
TCP: Setting connection queue length to 30
LOCAL: Removing stale socket file /tmp/clamd.socket
LOCAL: Unix socket file /tmp/clamd.socket
LOCAL: Setting connection queue length to 30
Limits: Global size limit set to 104857600 bytes.
Limits: File size limit set to 26214400 bytes.
Limits: Recursion level limit set to 16.
Limits: Files limit set to 10000.
Algorithmic detection enabled.
Database correctly reloaded (1761816 signatures)
---------------------- Clamav End -------------------------
Code: Select all
################### Logwatch 7.3 (03/24/06) ####################
Processing Initiated: Sun Oct 24 21:02:18 2010
Date Range Processed: yesterday
( 2010-Oct-23 )
Period is day.
Detail Level of Output: 0
Type of Output: unformatted
Logfiles for Host:
##################################################################
--------------------- clam-update Begin ------------------------
Last ClamAV update process started at Sat Oct 23 21:14:40 2010
Last Status:
Using IPv6 aware code
Querying current.cvd.clamav.net
TTL: 10
Software version from DNS: 0.96.3
WARNING: Your ClamAV installation is OUTDATED!
WARNING: Local version: 0.96.2 Recommended version: 0.96.3
DON'T PANIC! Read http://www.clamav.net/support/faq
main.cvd version from DNS: 52
main.cvd is up to date (version: 52, sigs: 704727, f-level: 44, builder: sven)
daily.cvd version from DNS: 12172
daily.cld is up to date (version: 12172, sigs: 142604, f-level: 53, builder: guitar)
safebrowsing.cvd version from DNS: 24693
Retrieving http://db.us.clamav.net/safebrowsing-24670.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24670.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24670.cdiff [100%]
cdiff_apply: Parsed 13359 lines and executed 13235 commands
Retrieving http://db.us.clamav.net/safebrowsing-24671.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24671.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24671.cdiff [100%]
cdiff_apply: Parsed 639 lines and executed 639 commands
Retrieving http://db.us.clamav.net/safebrowsing-24672.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24672.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24672.cdiff [100%]
cdiff_apply: Parsed 450 lines and executed 450 commands
Retrieving http://db.us.clamav.net/safebrowsing-24673.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24673.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24673.cdiff [100%]
cdiff_apply: Parsed 404 lines and executed 404 commands
Retrieving http://db.us.clamav.net/safebrowsing-24674.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24674.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24674.cdiff [100%]
cdiff_apply: Parsed 848 lines and executed 848 commands
Retrieving http://db.us.clamav.net/safebrowsing-24675.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24675.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24675.cdiff [100%]
cdiff_apply: Parsed 211 lines and executed 211 commands
Retrieving http://db.us.clamav.net/safebrowsing-24676.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24676.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24676.cdiff [100%]
cdiff_apply: Parsed 226 lines and executed 226 commands
Retrieving http://db.us.clamav.net/safebrowsing-24677.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24677.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24677.cdiff [100%]
cdiff_apply: Parsed 13813 lines and executed 13398 commands
Retrieving http://db.us.clamav.net/safebrowsing-24678.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24678.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24678.cdiff [100%]
cdiff_apply: Parsed 334 lines and executed 334 commands
Retrieving http://db.us.clamav.net/safebrowsing-24679.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24679.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24679.cdiff [100%]
cdiff_apply: Parsed 324 lines and executed 324 commands
Retrieving http://db.us.clamav.net/safebrowsing-24680.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24680.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24680.cdiff [100%]
cdiff_apply: Parsed 298 lines and executed 298 commands
Retrieving http://db.us.clamav.net/safebrowsing-24681.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24681.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24681.cdiff [100%]
cdiff_apply: Parsed 455 lines and executed 455 commands
Retrieving http://db.us.clamav.net/safebrowsing-24682.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24682.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24682.cdiff [100%]
cdiff_apply: Parsed 296 lines and executed 296 commands
Retrieving http://db.us.clamav.net/safebrowsing-24683.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24683.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24683.cdiff [100%]
cdiff_apply: Parsed 2342 lines and executed 2342 commands
Retrieving http://db.us.clamav.net/safebrowsing-24684.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24684.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24684.cdiff [100%]
cdiff_apply: Parsed 670 lines and executed 670 commands
Retrieving http://db.us.clamav.net/safebrowsing-24685.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24685.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24685.cdiff [100%]
cdiff_apply: Parsed 3402 lines and executed 3390 commands
Retrieving http://db.us.clamav.net/safebrowsing-24686.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24686.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24686.cdiff [100%]
cdiff_apply: Parsed 472 lines and executed 472 commands
Retrieving http://db.us.clamav.net/safebrowsing-24687.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24687.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24687.cdiff [100%]
cdiff_apply: Parsed 524 lines and executed 524 commands
Retrieving http://db.us.clamav.net/safebrowsing-24688.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24688.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24688.cdiff [100%]
cdiff_apply: Parsed 461 lines and executed 461 commands
Retrieving http://db.us.clamav.net/safebrowsing-24689.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24689.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24689.cdiff [100%]
cdiff_apply: Parsed 618 lines and executed 618 commands
Retrieving http://db.us.clamav.net/safebrowsing-24690.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24690.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24690.cdiff [100%]
cdiff_apply: Parsed 1900 lines and executed 1900 commands
Retrieving http://db.us.clamav.net/safebrowsing-24691.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24691.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24691.cdiff [100%]
cdiff_apply: Parsed 374 lines and executed 374 commands
Retrieving http://db.us.clamav.net/safebrowsing-24692.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24692.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24692.cdiff [100%]
cdiff_apply: Parsed 308 lines and executed 308 commands
Retrieving http://db.us.clamav.net/safebrowsing-24693.cdiff
Trying to download http://db.us.clamav.net/safebrowsing-24693.cdiff (IP: 168.143.19.95)
Downloading safebrowsing-24693.cdiff [100%]
cdiff_apply: Parsed 9554 lines and executed 9137 commands
Properly loaded 895514 signatures from new safebrowsing.cld
safebrowsing.cld updated (version: 24693, sigs: 895514, f-level: 53, builder: google)
bytecode.cvd version from DNS: 86
bytecode.cvd is up to date (version: 86, sigs: 10, f-level: 53, builder: edwin)
Database updated (1742855 signatures) from db.us.clamav.net (IP: 168.143.19.95)
Clamd successfully notified about the update.
---------------------- clam-update End -------------------------
--------------------- Clamav Begin ------------------------
**Unmatched Entries**
Database correctly reloaded (1752027 signatures)
---------------------- Clamav End -------------------------
Code: Select all
--------------------- Kernel Begin ------------------------
WARNING: Kernel Errors Present
Error: Driver 'pcspkr' ...: 2 Time(s)
---------------------- Kernel End -------------------------
Releasing Parallels Plesk Panel scripts from grsec is not enough in this particular case.
I tried to reinstall drweb-daemon package and got the following:
[root@loft2234 ~]# rpm -Uvh --force /root/parallels/PSA_9.2.3/dist-rpm-CentOS-5-x86_64/opt/drweb/drweb-daemon-5.0.1-0plesk.i386.rpm
Preparing... ########################################### [100%]
Shutting down Dr. Web daemon...
1:drweb-daemon ########################################### [100%]
Starting Dr. Web daemon...
Dr.Web (R) daemon for Linux/Plesk Edition v5.0.0 (Jun 4 2009)
Copyright (c) Igor Daniloff, 1992-2009
Doctor Web, Moscow, Russia
Support service: http://support.drweb.com
To purchase: http://buy.drweb.com
mprotect(): 13 (Permission denied)
Please, completely disable grsec or load usual stock kernel instead of art's kernel.
Please,let us know the results of the above solution.
Piece of cake:mprotect(): 13 (Permission denied)