[users@httpd] NeedHelp

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hello!
I use Apache/1.3.28 web-server under FreeBSD 5.2.1-RELEASE within jail
environment. And there is some strange thing when i'm checking
http-processes by `ps lax':

   80 57281 82970   0   4  0 11772 8916 accept SLJ   ??    0:27.66 /home/httpd/bin/httpd
   80 57658 82970   0   4  0 11404 8544 accept SLJ   ??    0:25.66 /home/httpd/bin/httpd
   80 57697 82970   0   4  0 10920 8056 accept SLJ   ??    0:25.95 /home/httpd/bin/httpd
   80 57783 82970   0   4  0 10832 7932 accept SLJ   ??    0:24.53 /home/httpd/bin/httpd
   80 57935 82970   0   4  0 11240 8356 sbwait SLJ   ??    0:24.56 /home/httpd/bin/httpd
   80 57995 82970   0   4  0 11132 8264 accept SLJ   ??    0:26.63 /home/httpd/bin/httpd
   80 58258 82970   0   4  0 11164 8284 sbwait SLJ   ??    0:24.28 /home/httpd/bin/httpd
   80 58311 82970   0   4  0 11060 8296 accept SLJ   ??    0:21.70 /home/httpd/bin/httpd
   80 73984 82970   0   4  0 11160 8260 accept SLJ   ??    0:17.02 /home/httpd/bin/httpd
    0 82970     1   0  96  0  8048 4892 select SLsJ  ??    0:30.28 /home/httpd/bin/httpd
>  80 69523     1   0  96  0  6148 1232 select SLsJ  ??    0:00.49 (httpd)
   80 84457 82970   0   4  0 10884 7972 accept SLJ   ??    0:11.19 /home/httpd/bin/httpd

The string `80 83454     1   0  96  0  6148 1232 select SLsJ  ??
0:00.49 (httpd)'
is confused me because i don't know what is the process (httpd) (it seems
to be there is parent process with PPID=1). And the following picture is
appearing when i do the `sockstat| grep http' command:

  www      httpd      89715 68 tcp4   217.144.97.27:80      *:*
  www      httpd      89616 68 tcp4   217.144.97.27:80      *:*
  www      httpd      89520 3  tcp4   217.144.97.27:80      81.3.182.146:58911
  www      httpd      89520 68 tcp4   217.144.97.27:80      *:*
  www      httpd      84457 3  tcp4   217.144.97.27:80      62.76.200.2:52881
  www      httpd      84457 4  stream -> /tmp/mysql.sock
  www      httpd      84457 68 tcp4   217.144.97.27:80      *:*
  www      httpd      73984 4  stream -> /tmp/mysql.sock
  www      httpd      73984 68 tcp4   217.144.97.27:80      *:*
  www      httpd      69523 4  stream -> /tmp/mysql.sock
> www      httpd      69523 5  tcp4   217.144.97.27:53407   84.19.182.61:6667
  www      httpd      58311 3  tcp4   217.144.97.27:80      62.76.200.2:52617
  www      httpd      58311 4  stream -> /tmp/mysql.sock

Same process is in the string `www      httpd      69523 5  tcp4
217.144.97.27:53407   84.19.182.61:6667'. Its not difficult to see that we
deal with tcp-connection to irc-server.
Could you please help me to anderstand such behaviour of Apache-server, is
it normal situation or maybe its a some vulnerability of my version of
Apache?


---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx
   "   from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx
For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx



[Index of Archives]     [Open SSH Users]     [Linux ACPI]     [Linux Kernel]     [Linux Laptop]     [Kernel Newbies]     [Security]     [Netfilter]     [Bugtraq]     [Squid]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Samba]     [Video 4 Linux]     [Device Mapper]

  Powered by Linux