Hello! I use Apache/1.3.28 web-server under FreeBSD 5.2.1-RELEASE within jail environment. And there is some strange thing when i'm checking http-processes by `ps lax': 80 57281 82970 0 4 0 11772 8916 accept SLJ ?? 0:27.66 /home/httpd/bin/httpd 80 57658 82970 0 4 0 11404 8544 accept SLJ ?? 0:25.66 /home/httpd/bin/httpd 80 57697 82970 0 4 0 10920 8056 accept SLJ ?? 0:25.95 /home/httpd/bin/httpd 80 57783 82970 0 4 0 10832 7932 accept SLJ ?? 0:24.53 /home/httpd/bin/httpd 80 57935 82970 0 4 0 11240 8356 sbwait SLJ ?? 0:24.56 /home/httpd/bin/httpd 80 57995 82970 0 4 0 11132 8264 accept SLJ ?? 0:26.63 /home/httpd/bin/httpd 80 58258 82970 0 4 0 11164 8284 sbwait SLJ ?? 0:24.28 /home/httpd/bin/httpd 80 58311 82970 0 4 0 11060 8296 accept SLJ ?? 0:21.70 /home/httpd/bin/httpd 80 73984 82970 0 4 0 11160 8260 accept SLJ ?? 0:17.02 /home/httpd/bin/httpd 0 82970 1 0 96 0 8048 4892 select SLsJ ?? 0:30.28 /home/httpd/bin/httpd > 80 69523 1 0 96 0 6148 1232 select SLsJ ?? 0:00.49 (httpd) 80 84457 82970 0 4 0 10884 7972 accept SLJ ?? 0:11.19 /home/httpd/bin/httpd The string `80 83454 1 0 96 0 6148 1232 select SLsJ ?? 0:00.49 (httpd)' is confused me because i don't know what is the process (httpd) (it seems to be there is parent process with PPID=1). And the following picture is appearing when i do the `sockstat| grep http' command: www httpd 89715 68 tcp4 217.144.97.27:80 *:* www httpd 89616 68 tcp4 217.144.97.27:80 *:* www httpd 89520 3 tcp4 217.144.97.27:80 81.3.182.146:58911 www httpd 89520 68 tcp4 217.144.97.27:80 *:* www httpd 84457 3 tcp4 217.144.97.27:80 62.76.200.2:52881 www httpd 84457 4 stream -> /tmp/mysql.sock www httpd 84457 68 tcp4 217.144.97.27:80 *:* www httpd 73984 4 stream -> /tmp/mysql.sock www httpd 73984 68 tcp4 217.144.97.27:80 *:* www httpd 69523 4 stream -> /tmp/mysql.sock > www httpd 69523 5 tcp4 217.144.97.27:53407 84.19.182.61:6667 www httpd 58311 3 tcp4 217.144.97.27:80 62.76.200.2:52617 www httpd 58311 4 stream -> /tmp/mysql.sock Same process is in the string `www httpd 69523 5 tcp4 217.144.97.27:53407 84.19.182.61:6667'. Its not difficult to see that we deal with tcp-connection to irc-server. Could you please help me to anderstand such behaviour of Apache-server, is it normal situation or maybe its a some vulnerability of my version of Apache? --------------------------------------------------------------------- The official User-To-User support forum of the Apache HTTP Server Project. See <URL:http://httpd.apache.org/userslist.html> for more info. To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx " from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx