Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance Networking & Security
  • Search

spamdyke on hardened - RLIMIT_AS

Having problems getting connected to the internet or running a server? Wondering about securing your box? Ask here.
Post Reply
Advanced search
4 posts • Page 1 of 1
Author
Message
NeddySeagoon
Administrator
Administrator
User avatar
Posts: 56077
Joined: Sat Jul 05, 2003 9:37 am
Location: 56N 3W

spamdyke on hardened - RLIMIT_AS

  • Quote

Post by NeddySeagoon » Sun Apr 26, 2015 10:48 pm

Team,

I am trying to run spamdyke in front of qmail on a gentoo-hardened system. Its a KVM but that probably doesn't matter.

dmesg tells me

Code: Select all

grsec: From 212.23.1.5: denied resource overstep by requesting 16228352 for RLIMIT_AS against limit 16000000 for /usr/bin/spamdyke[spamdyke:1626] 
and /var/log/qmail/qmail-smtpd/current tells

Code: Select all

@40000000553d65a02edc836c /usr/bin/spamdyke: error while loading shared libraries: libz.so.1: failed to map segment from shared object.
So it looks like spamdyke needs more that a 16Mb address space.
spamdyke is made up of

Code: Select all

# lddtree /usr/bin/spamdyke
spamdyke => /usr/bin/spamdyke (interpreter => /lib64/ld-linux-x86-64.so.2)
    libssl.so.1.0.0 => /usr/lib64/libssl.so.1.0.0
    libcrypto.so.1.0.0 => /usr/lib64/libcrypto.so.1.0.0
        libdl.so.2 => /lib64/libdl.so.2
        libz.so.1 => /lib64/libz.so.1
    libc.so.6 => /lib64/libc.so.6
RLIMIT_AS against limit 16000000 says its allowed 16Mb of address space.
Having tried to change it in /etc/security/limits.conf and with ulimit -v in a wrapper script, nothing will change the RLIMIT_AS - not even downwards.

Where is RLIMIT_AS set and how can i change it?
Regards,

NeddySeagoon

Computer users fall into two groups:-
those that do backups
those that have never had a hard drive fail.
Top
boozo
Advocate
Advocate
User avatar
Posts: 3193
Joined: Thu Jul 01, 2004 8:35 am

  • Quote

Post by boozo » Mon Apr 27, 2015 9:13 am

Sir Neddy,

just an idea according to this : it seem that you should search directly from the spamdyke source-code

nb. I precise that I've never had to do something with any "AS" setting (noob inside) but there are an example to define this $vars in the RSBAC handbook ( §Ressources restrinctions) too ...
" Un psychotique, c'est quelqu'un qui croit dur comme fer que 2 et 2 font 5, et qui en est pleinement satisfait.
Un névrosé, c'est quelqu'un qui sait pertinemment que 2 et 2 font 4, et ça le rend malade ! "
Top
NeddySeagoon
Administrator
Administrator
User avatar
Posts: 56077
Joined: Sat Jul 05, 2003 9:37 am
Location: 56N 3W

  • Quote

Post by NeddySeagoon » Mon Apr 27, 2015 4:53 pm

boozo,

Thank you for the pointer. I'll look later this evening if I don't run out of time.
Regards,

NeddySeagoon

Computer users fall into two groups:-
those that do backups
those that have never had a hard drive fail.
Top
NeddySeagoon
Administrator
Administrator
User avatar
Posts: 56077
Joined: Sat Jul 05, 2003 9:37 am
Location: 56N 3W

  • Quote

Post by NeddySeagoon » Tue Apr 28, 2015 10:34 pm

qmail runs under softlimit=16000000 and it seems as if its not enough.
That's not all of the issue. I havu to soften the hardening a little by turning off address space randomisation. under the PAX settings in the kernel too.
Regards,

NeddySeagoon

Computer users fall into two groups:-
those that do backups
those that have never had a hard drive fail.
Top
Post Reply

4 posts • Page 1 of 1

Return to “Networking & Security”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Foundation, Inc.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy

 

 

magic