From: "Massimo S." Received: from [192.168.100.201] (HELO mail.2rosenthals.com) by 2rosenthals.com (CommuniGate Pro SMTP 5.4.10) with ESMTPS id 9412041 for ecs-isp@2rosenthals.com; Wed, 03 Apr 2024 09:22:31 -0400 Received: from secmgr-va.2rosenthals.com ([50.73.8.217]:41537 helo=mail2.2rosenthals.com) by mail.2rosenthals.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1rs0ZK-00063U-1X for ecs-isp@2rosenthals.com; Wed, 03 Apr 2024 09:22:23 -0400 Received: from mail2.quasarbbs.net ([80.86.52.115]:10154) by mail2.2rosenthals.com with esmtp (Exim 4.96) (envelope-from ) id 1rs0ZI-0001zT-1c for ecs-isp@2rosenthals.com; Wed, 03 Apr 2024 09:22:21 -0400 X-SASI-Hits: BODY_SIZE_3000_3999 0.000000, BODY_SIZE_5000_LESS 0.000000, BODY_SIZE_7000_LESS 0.000000, CTE_8BIT 0.000000, HTML_00_01 0.050000, HTML_00_10 0.050000, IN_REP_TO 0.000000, LEGITIMATE_SIGNS 0.000000, MSGID_SAMEAS_FROM_HEX_844412 0.100000, MSG_THREAD 0.000000, NO_CTA_URI_FOUND 0.000000, NO_URI_HTTPS 0.000000, REFERENCES 0.000000, REPLYTO_SAMEAS_FROM 0.000000, SENDER_NO_AUTH 0.000000, SUSP_DH_NEG 0.000000, TO_IN_SUBJECT 0.500000, __ANY_URI 0.000000, __BODY_NO_MAILTO 0.000000, __BOUNCE_CHALLENGE_SUBJ 0.000000, __BOUNCE_NDR_SUBJ_EXEMPT 0.000000, __CT 0.000000, __CTE 0.000000, __CT_TEXT_PLAIN 0.000000, __DQ_NEG_DOMAIN 0.000000, __DQ_NEG_HEUR 0.000000, __DQ_NEG_IP 0.000000, __FORWARDED_MSG 0.000000, __FROM_DOMAIN_NOT_IN_BODY 0.000000, __FROM_NAME_NOT_IN_ADDR 0.000000, __FROM_NAME_NOT_IN_BODY 0.000000, __FUR_HEADER 0.000000, __HAS_FROM 0.000000, __HAS_MSGID 0.000000, __HAS_REFERENCES 0.000000, __HAS_REPLYTO 0.000000, __HEADER_ORDER_FROM 0.000000, __INVOICE_MULTILINGUAL 0.000000, __IN_REP_TO 0.000000, __MAIL_CHAIN 0.000000, __MAIL_CHAIN_OLD 0.000000, __MIME_BOUND_CHARSET 0.000000, __MIME_TEXT_ONLY 0.000000, __MIME_TEXT_P 0.000000, __MIME_TEXT_P1 0.000000, __MIME_VERSION 0.000000, __MOZILLA_USER_AGENT 0.000000, __MSGID_HEX_844412 0.000000, __NO_HTML_TAG_RAW 0.000000, __REFERENCES 0.000000, __REPLYTO_SAMEAS_FROM_ACC 0.000000, __REPLYTO_SAMEAS_FROM_ADDY 0.000000, __REPLYTO_SAMEAS_FROM_DOMAIN 0.000000, __SANE_MSGID 0.000000, __SCAN_D_NEG 0.000000, __SCAN_D_NEG2 0.000000, __SCAN_D_NEG_HEUR 0.000000, __SCAN_D_NEG_HEUR2 0.000000, __SUBJ_ALPHA_NEGATE 0.000000, __SUBJ_REPLY 0.000000, __TO_IN_SUBJECT 0.000000, __TO_MALFORMED_2 0.000000, __TO_NAME 0.000000, __TO_NAME_DIFF_FROM_ACC 0.000000, __TO_REAL_NAMES 0.000000, __URI_MAILTO 0.000000, __URI_NO_WWW 0.000000, __URI_NS 0.000000, __USER_AGENT 0.000000 X-SASI-Probability: 10% X-SASI-RCODE: 200 X-SASI-Version: Antispam-Engine: 5.1.4, AntispamData: 2024.4.3.123919 X-SASI-Hits: BODY_SIZE_3000_3999 0.000000, BODY_SIZE_5000_LESS 0.000000, BODY_SIZE_7000_LESS 0.000000, CTE_8BIT 0.000000, HTML_00_01 0.050000, HTML_00_10 0.050000, IN_REP_TO 0.000000, LEGITIMATE_SIGNS 0.000000, MSGID_SAMEAS_FROM_HEX_844412 0.100000, MSG_THREAD 0.000000, NO_CTA_URI_FOUND 0.000000, NO_URI_HTTPS 0.000000, REFERENCES 0.000000, REPLYTO_SAMEAS_FROM 0.000000, SUSP_DH_NEG 0.000000, TO_IN_SUBJECT 0.500000, __ANY_URI 0.000000, __AUTH_RES_PASS 0.000000, __BODY_NO_MAILTO 0.000000, __BOUNCE_CHALLENGE_SUBJ 0.000000, __BOUNCE_NDR_SUBJ_EXEMPT 0.000000, __CT 0.000000, __CTE 0.000000, __CT_TEXT_PLAIN 0.000000, __DQ_NEG_DOMAIN 0.000000, __DQ_NEG_HEUR 0.000000, __DQ_NEG_IP 0.000000, __FORWARDED_MSG 0.000000, __FROM_DOMAIN_NOT_IN_BODY 0.000000, __FROM_NAME_NOT_IN_ADDR 0.000000, __FROM_NAME_NOT_IN_BODY 0.000000, __FUR_HEADER 0.000000, __HAS_FROM 0.000000, __HAS_MSGID 0.000000, __HAS_REFERENCES 0.000000, __HAS_REPLYTO 0.000000, __HEADER_ORDER_FROM 0.000000, __INVOICE_MULTILINGUAL 0.000000, __IN_REP_TO 0.000000, __MAIL_CHAIN 0.000000, __MAIL_CHAIN_OLD 0.000000, __MIME_BOUND_CHARSET 0.000000, __MIME_TEXT_ONLY 0.000000, __MIME_TEXT_P 0.000000, __MIME_TEXT_P1 0.000000, __MIME_VERSION 0.000000, __MOZILLA_USER_AGENT 0.000000, __MSGID_HEX_844412 0.000000, __NO_HTML_TAG_RAW 0.000000, __REFERENCES 0.000000, __REPLYTO_SAMEAS_FROM_ACC 0.000000, __REPLYTO_SAMEAS_FROM_ADDY 0.000000, __REPLYTO_SAMEAS_FROM_DOMAIN 0.000000, __SANE_MSGID 0.000000, __SCAN_D_NEG 0.000000, __SCAN_D_NEG2 0.000000, __SCAN_D_NEG_HEUR 0.000000, __SCAN_D_NEG_HEUR2 0.000000, __SUBJ_ALPHA_NEGATE 0.000000, __SUBJ_REPLY 0.000000, __TO_IN_SUBJECT 0.000000, __TO_MALFORMED_2 0.000000, __TO_NAME 0.000000, __TO_NAME_DIFF_FROM_ACC 0.000000, __TO_REAL_NAMES 0.000000, __URI_MAILTO 0.000000, __URI_NO_WWW 0.000000, __URI_NS 0.000000, __USER_AGENT 0.000000 X-SASI-Probability: 10% X-SASI-RCODE: 200 X-SASI-Version: Antispam-Engine: 5.1.4, AntispamData: 2024.4.3.123919 Received: from [192.168.10.199] (dtp [192.168.10.199]) by srv2 (Weasel v2.89) for ; Wed, 03 Apr 2024 15:22:20 -0000 Reply-To: ml@ecomstation.it Subject: Re: [eCS-ISP] system stuck in "system is rebooting" To: eCS ISP Mailing List References: Organization: eComStation dot it Message-ID: <7f39a17d-f654-aea2-8242-7e2b17dca5a9@ecomstation.it> Date: Wed, 3 Apr 2024 15:22:16 +0200 User-Agent: Mozilla/5.0 (OS/2; U; Warp 4.5; it-IT; rv:1.7.13) Gecko/20060424 Thunderbird/1.0.8 Mnenhy/0.7.4.0 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=iso-8859-15; format=flowed Content-Language: it-IT Content-Transfer-Encoding: 8bit Hi Lewis, i found that i had suffered a http/https DDOS rotating packets attack massimo Il 02/04/2024 22:32, Lewis G Rosenthal ha scritto: > On 04/02/24 04:24 am, Massimo S. wrote: >> >> >> Il 04/12/2022 19:48, Massimo S. ha scritto: >>> >>> >>> Il 03/12/2022 01:56, Steven Levine ha scritto: >>>> In , on 12/01/22 >>>>     at 12:02 PM, "Massimo S." said: >>>> >>>> Hi Massimo, >>>> >>>>> if i recall well you should have some utility to avoid this (rare) >>>>> situation? >>>> >>>> I'm not sure what utility you are thinking of.  What a reboot request >>>> hangs, there's not much you can do.  What I do have is scripts that shut >>>> down as much as possible before the reboot is requested and this gives the >>>> best chance of avoiding reboot hangs. >>>> >>>> As always the best solution is to detect that you are running low of >>>> resources and resolve this isssue before it can hang the system. >>>> >>>> Steven >>> >>> this only happens (luckily rarely) on the web server that use apache+PHP >>> >>> massimo >> >> hi all, >> >> in this period unfortunately it's happening quite often >> >> eg. at 6,50 the server did one of his scheduled reboots, all ok >> some minutes later apache exited (i've nothing in popuplog.os2 or eQ dumps) >> the rexx procedure tried to restart it with no success >> at 7,08 the rexx procedure gave the setboot /b >> and the vm stuck at the "system is rebooting" >> >> in apache access log i've only normal requests after the reboot at around 6,50 since >> 7,06 (the last http request) a mix of some normal users requests or some bot scanning >> web pages (eg. scroogle or semrush) >> since semrush is of no interest i will try to filter the bot on the firewall >> nowadays robots.txt is completely ignored by anyone >> >> >> since the other web server that has no PHP and running apache with html/js websites only >> is rock solid stable, i guess it's something on PHP >> > > Why guess? > > You mention the access log, but you don't mention the error log, POPUPLOG, or the exceptq logs. Check the php > error log as well. > > I would also not overlook something simple, like the need for a full disk check. PHP apps can be finicky about > the inability to write to the filesystem. > > If this were to happen to me (and it has), I would check the above logs for clues. Then, I would reboot with > the Apache startup disabled to make sure that the VM could boot properly. I would boot from alternative media > and run a full diskcheck on *all* volumes, looking also for adequate available space to write on each of them. > Then, after another reboot, I would disable the loading of the PHP module (and anything else which I thought > might add complexity to the Apache startup, and try starting Apache by itself. If that worked, I would then > add back each of those modules (PHP last, if possible) and observe the Apache startup behavior, as well as > shutdown behavior. > > It's best not to make suppositions or guesses. As we say in the vernacular, you never know; you just never, > never know. > > GL HTH >