Hi Joe, Thanks for your reply. As per your instruction I started strace. I'm getting read(5, <unfinished ...> as a last line. I couldn't understand what it's trying to do. Your help is really appreciated in this matter. Following is tracer for one PID 20342 clone(child_stack=0, flags=CLONE_CHILD_CLEARTID|CLONE_CHILD_SETTID|SIGCHLD, child_tidptr=0x2aaaad0f9610) = 20636 20636 close(3) = 0 20636 dup2(0, 1) = 1 20636 dup2(0, 2) = 2 20636 getpeername(0, {sa_family=AF_INET, sin_port=htons(42757), sin_addr=inet_addr("172.31.1.50")}, [16]) = 0 20636 getsockname(0, {sa_family=AF_INET, sin_port=htons(21), sin_addr=inet_addr("172.31.1.168")}, [16]) = 0 20636 open("/etc/hosts.allow", O_RDONLY) = 3 20636 fstat(3, {st_mode=S_IFREG|0644, st_size=523, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac6000 20636 read(3, "#\n# hosts.allow\tThis file descri"..., 4096) = 523 20636 socket(PF_NETLINK, SOCK_RAW, 0) = 4 20636 bind(4, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0 20636 getsockname(4, {sa_family=AF_NETLINK, pid=20636, groups=00000000}, [4294967308]) = 0 20636 sendto(4, "\24\0\0\0\26\0\1\3\3531QH\0\0\0\0\0\0\0\0", 20, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20 20636 recvmsg(4, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"<\0\0\0\24\0\2\0\3531QH\234P\0\0\2\10\200\376\1\0\0\0\10\0\1\0 \177\0\0\1"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128 20636 recvmsg(4, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\3531QH\234P\0\0\n\200\200\376\1\0\0\0\24\0\1\ 0\0\0\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128 20636 recvmsg(4, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0\3531QH\234P\0\0\0\0\0\0\1\0\0\0\24\0\1\0\0\0 \0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20 20636 close(4) = 0 20636 socket(PF_NETLINK, SOCK_RAW, 0) = 4 20636 bind(4, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0 20636 getsockname(4, {sa_family=AF_NETLINK, pid=20636, groups=00000000}, [4294967308]) = 0 20636 sendto(4, "\24\0\0\0\26\0\1\3\3531QH\0\0\0\0\0\0\0\0", 20, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20 20636 recvmsg(4, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"<\0\0\0\24\0\2\0\3531QH\234P\0\0\2\10\200\376\1\0\0\0\10\0\1\0 \177\0\0\1"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128 20636 recvmsg(4, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\3531QH\234P\0\0\n\200\200\376\1\0\0\0\24\0\1\ 0\0\0\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128 20636 recvmsg(4, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0\3531QH\234P\0\0\0\0\0\0\1\0\0\0\24\0\1\0\0\0 \0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20 20636 close(4) = 0 20636 close(3) = 0 20636 munmap(0x2aaaaaac6000, 4096) = 0 20636 fstat(0, {st_mode=S_IFSOCK|0777, st_size=0, ...}) = 0 20636 getpeername(0, {sa_family=AF_INET, sin_port=htons(42757), sin_addr=inet_addr("172.31.1.50")}, [407294299890253840]) = 0 20636 getsockname(0, {sa_family=AF_INET, sin_port=htons(21), sin_addr=inet_addr("172.31.1.168")}, [1513209483386421264]) = 0 20636 socket(PF_FILE, SOCK_STREAM, 0) = 3 20636 fcntl(3, F_GETFL) = 0x2 (flags O_RDWR) 20636 fcntl(3, F_SETFL, O_RDWR|O_NONBLOCK) = 0 20636 connect(3, {sa_family=AF_FILE, path="/var/run/nscd/socket"}, 110) = -1 ENOENT (No such file or directory) 20636 close(3) = 0 20636 socket(PF_FILE, SOCK_STREAM, 0) = 3 20636 fcntl(3, F_GETFL) = 0x2 (flags O_RDWR) 20636 fcntl(3, F_SETFL, O_RDWR|O_NONBLOCK) = 0 20636 connect(3, {sa_family=AF_FILE, path="/var/run/nscd/socket"}, 110) = -1 ENOENT (No such file or directory) 20636 close(3) = 0 20636 open("/etc/nsswitch.conf", O_RDONLY) = 3 20636 fstat(3, {st_mode=S_IFREG|0644, st_size=1696, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac6000 20636 read(3, "#\n# /etc/nsswitch.conf\n#\n# An ex"..., 4096) = 1696 20636 read(3, "", 4096) = 0 20636 close(3) = 0 20636 munmap(0x2aaaaaac6000, 4096) = 0 20636 open("/u01/app/oracle/oracle/product/10.2.0/db_2/lib/libnss_files.so.2", O_RDONLY) = -1 ENOENT (No such file or directory) 20636 open("/lib/libnss_files.so.2", O_RDONLY) = 3 20636 read(3, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\320\30\0\0004\0\0\0"..., 832) = 832 20636 close(3) = 0 20636 open("/usr/lib/libnss_files.so.2", O_RDONLY) = -1 ENOENT (No such file or directory) 20636 open("/usr/local/lib/libnss_files.so.2", O_RDONLY) = -1 ENOENT (No such file or directory) 20636 open("/etc/ld.so.cache", O_RDONLY) = 3 20636 fstat(3, {st_mode=S_IFREG|0644, st_size=34353, ...}) = 0 20636 mmap(NULL, 34353, PROT_READ, MAP_PRIVATE, 3, 0) = 0x2aaaaaac6000 20636 close(3) = 0 20636 open("/lib64/libnss_files.so.2", O_RDONLY) = 3 20636 read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0 \0\0\0\0\0\0"..., 832) = 832 20636 fstat(3, {st_mode=S_IFREG|0755, st_size=53880, ...}) = 0 20636 mmap(NULL, 2139432, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2aaaad0fa000 20636 mprotect(0x2aaaad104000, 2093056, PROT_NONE) = 0 20636 mmap(0x2aaaad303000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x9000) = 0x2aaaad303000 20636 close(3) = 0 20636 mprotect(0x2aaaad303000, 4096, PROT_READ) = 0 20636 munmap(0x2aaaaaac6000, 34353) = 0 20636 open("/etc/passwd", O_RDONLY) = 3 20636 fcntl(3, F_GETFD) = 0 20636 fcntl(3, F_SETFD, FD_CLOEXEC) = 0 20636 fstat(3, {st_mode=S_IFREG|0644, st_size=1649, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac6000 20636 read(3, "root:x:0:0:root:/root:/bin/bash\n"..., 4096) = 1649 20636 close(3) = 0 20636 munmap(0x2aaaaaac6000, 4096) = 0 20636 setsid() = 20636 20636 getpgrp() = 20636 20636 umask(077) = 022 20636 open("/etc/localtime", O_RDONLY) = 3 20636 fstat(3, {st_mode=S_IFREG|0644, st_size=265, ...}) = 0 20636 fstat(3, {st_mode=S_IFREG|0644, st_size=265, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac6000 20636 read(3, "TZif2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\0"..., 4096) = 265 20636 lseek(3, -156, SEEK_CUR) = 109 20636 read(3, "TZif2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\5\0\0\0\5\0\0\0\0"..., 4096) = 156 20636 close(3) = 0 20636 munmap(0x2aaaaaac6000, 4096) = 0 20636 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=265, ...}) = 0 20636 rt_sigaction(SIGPIPE, {0x555555567b80, ~[RTMIN RT_1], SA_RESTORER, 0x2aaaab974070}, NULL, 8) = 0 20636 socket(PF_FILE, SOCK_DGRAM, 0) = 3 20636 fcntl(3, F_SETFD, FD_CLOEXEC) = 0 20636 connect(3, {sa_family=AF_FILE, path="/dev/log"}, 110) = 0 20636 open("/var/log/xferlog", O_WRONLY|O_CREAT|O_APPEND|O_NONBLOCK, 0600) = 4 20636 setsockopt(0, SOL_SOCKET, SO_KEEPALIVE, [1], 4) = 0 20636 setsockopt(0, SOL_TCP, TCP_NODELAY, [1], 4) = 0 20636 setsockopt(0, SOL_SOCKET, SO_OOBINLINE, [1], 4) = 0 20636 socketpair(PF_FILE, SOCK_STREAM, 0, [5, 6]) = 0 20636 rt_sigprocmask(SIG_BLOCK, [CHLD], NULL, 8) = 0 20636 rt_sigaction(SIGCHLD, {0x555555564ce0, ~[RTMIN RT_1], SA_RESTORER, 0x2aaaab974070}, NULL, 8) = 0 20636 clone(child_stack=0, flags=CLONE_CHILD_CLEARTID|CLONE_CHILD_SETTID|SIGCHLD, child_tidptr=0x2aaaad0f9610) = 20637 20636 rt_sigprocmask(SIG_UNBLOCK, [CHLD], NULL, 8) = 0 20636 read(5, <unfinished ...> 20636 <... read resumed> "\1", 1) = 1 20636 rt_sigprocmask(SIG_BLOCK, [CHLD], <unfinished ...> 20636 <... rt_sigprocmask resumed> NULL, 8) = 0 20636 read(5, <unfinished ...> 20636 <... read resumed> "\f\0\0\0", 4) = 4 20636 read(5, "moneycontrol", 12) = 12 20636 read(5, "\f\0\0\0", 4) = 4 20636 read(5, "tin~101lizzy", 12) = 12 20636 read(5, "\0\0\0\0", 4) = 4 20636 read(5, "\0\0\0\0", 4) = 4 20636 stat("/etc/pam.d", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0 20636 open("/etc/pam.d/vsftpd", O_RDONLY) = 7 20636 fstat(7, {st_mode=S_IFREG|0644, st_size=329, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac6000 20636 read(7, "#%PAM-1.0\nsession optional "..., 4096) = 329 20636 open("/lib64/security/pam_keyinit.so", O_RDONLY) = 8 20636 read(8, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0p\7\0\0\0\0\0\0"..., 832) = 832 20636 fstat(8, {st_mode=S_IFREG|0755, st_size=6800, ...}) = 0 20636 mmap(NULL, 2102072, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 8, 0) = 0x2aaaad305000 20636 mprotect(0x2aaaad307000, 2093056, PROT_NONE) = 0 20636 mmap(0x2aaaad506000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 8, 0x1000) = 0x2aaaad506000 20636 close(8) = 0 20636 open("/lib64/security/pam_listfile.so", O_RDONLY) = 8 20636 read(8, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0@\f\0\0\0\0\0\0"..., 832) = 832 20636 fstat(8, {st_mode=S_IFREG|0755, st_size=10824, ...}) = 0 20636 mmap(NULL, 2106072, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 8, 0) = 0x2aaaad507000 20636 mprotect(0x2aaaad509000, 2097152, PROT_NONE) = 0 20636 mmap(0x2aaaad709000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 8, 0x2000) = 0x2aaaad709000 20636 close(8) = 0 20636 open("/lib64/security/pam_shells.so", O_RDONLY) = 8 20636 read(8, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0 \7\0\0\0\0\0\0"..., 832) = 832 20636 fstat(8, {st_mode=S_IFREG|0755, st_size=5464, ...}) = 0 20636 mmap(NULL, 2100720, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 8, 0) = 0x2aaaad70a000 20636 mprotect(0x2aaaad70b000, 2093056, PROT_NONE) = 0 20636 mmap(0x2aaaad90a000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 8, 0) = 0x2aaaad90a000 20636 close(8) = 0 20636 open("/etc/pam.d/system-auth", O_RDONLY) = 8 20636 fstat(8, {st_mode=S_IFREG|0644, st_size=844, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaad90b000 20636 read(8, "#%PAM-1.0\n# This file is auto-ge"..., 4096) = 844 20636 open("/lib64/security/pam_env.so", O_RDONLY) = 9 20636 read(9, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0P\n\0\0\0\0\0\0"..., 832) = 832 20636 fstat(9, {st_mode=S_IFREG|0755, st_size=11480, ...}) = 0 20636 mmap(NULL, 2106728, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 9, 0) = 0x2aaaad90c000 20636 mprotect(0x2aaaad90f000, 2093056, PROT_NONE) = 0 20636 mmap(0x2aaaadb0e000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 9, 0x2000) = 0x2aaaadb0e000 20636 close(9) = 0 20636 open("/lib64/security/pam_unix.so", O_RDONLY) = 9 20636 read(9, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\360#\0\0\0\0\0\0"..., 832) = 832 20636 fstat(9, {st_mode=S_IFREG|0755, st_size=45032, ...}) = 0 20636 mmap(NULL, 2189608, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 9, 0) = 0x2aaaadb0f000 20636 mprotect(0x2aaaadb1a000, 2093056, PROT_NONE) = 0 20636 mmap(0x2aaaadd19000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 9, 0xa000) = 0x2aaaadd19000 20636 mmap(0x2aaaadd1a000, 47400, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2aaaadd1a000 20636 close(9) = 0 20636 open("/u01/app/oracle/oracle/product/10.2.0/db_2/lib/libcrypt.so.1", O_RDONLY) = -1 ENOENT (No such file or directory) 20636 open("/lib/libcrypt.so.1", O_RDONLY) = 9 20636 read(9, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\200F@\0004\0\0\0"..., 832) = 832 20636 close(9) = 0 20636 open("/usr/lib/libcrypt.so.1", O_RDONLY) = -1 ENOENT (No such file or directory) 20636 open("/usr/local/lib/libcrypt.so.1", O_RDONLY) = -1 ENOENT (No such file or directory) 20636 open("/etc/ld.so.cache", O_RDONLY) = 9 20636 fstat(9, {st_mode=S_IFREG|0644, st_size=34353, ...}) = 0 20636 mmap(NULL, 34353, PROT_READ, MAP_PRIVATE, 9, 0) = 0x2aaaadd26000 20636 close(9) = 0 20636 open("/lib64/libcrypt.so.1", O_RDONLY) = 9 20636 read(9, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0`\t\340\3500\0\0\0"..., 832) = 832 20636 fstat(9, {st_mode=S_IFREG|0755, st_size=30920, ...}) = 0 20636 mmap(NULL, 2306464, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 9, 0) = 0x2aaaadd2f000 20636 mprotect(0x2aaaadd34000, 2093056, PROT_NONE) = 0 20636 mmap(0x2aaaadf33000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 9, 0x4000) = 0x2aaaadf33000 20636 mmap(0x2aaaadf35000, 184736, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2aaaadf35000 20636 close(9) = 0 20636 open("/u01/app/oracle/oracle/product/10.2.0/db_2/lib/libselinux.so.1", O_RDONLY) = -1 ENOENT (No such file or directory) 20636 open("/lib/libselinux.so.1", O_RDONLY) = 9 20636 read(9, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\0205\0\0004\0\0\0"..., 832) = 832 20636 close(9) = 0 20636 open("/usr/lib/libselinux.so.1", O_RDONLY) = -1 ENOENT (No such file or directory) 20636 open("/usr/local/lib/libselinux.so.1", O_RDONLY) = -1 ENOENT (No such file or directory) 20636 open("/lib64/libselinux.so.1", O_RDONLY) = 9 20636 read(9, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0PE\240\3470\0\0\0"..., 832) = 832 20636 fstat(9, {st_mode=S_IFREG|0755, st_size=95480, ...}) = 0 20636 mmap(NULL, 2192816, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 9, 0) = 0x2aaaadf63000 20636 mprotect(0x2aaaadf78000, 2097152, PROT_NONE) = 0 20636 mmap(0x2aaaae178000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 9, 0x15000) = 0x2aaaae178000 20636 mmap(0x2aaaae17a000, 1456, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2aaaae17a000 20636 close(9) = 0 20636 open("/u01/app/oracle/oracle/product/10.2.0/db_2/lib/libcrack.so.2", O_RDONLY) = -1 ENOENT (No such file or directory) 20636 open("/lib/libcrack.so.2", O_RDONLY) = -1 ENOENT (No such file or directory) 20636 open("/usr/lib/libcrack.so.2", O_RDONLY) = 9 20636 read(9, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\20\33\0\0004\0\0\0"..., 832) = 832 20636 close(9) = 0 20636 open("/usr/local/lib/libcrack.so.2", O_RDONLY) = -1 ENOENT (No such file or directory) 20636 open("/usr/lib64/libcrack.so.2", O_RDONLY) = 9 20636 read(9, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0@8\240\3460\0\0\0"..., 832) = 832 20636 fstat(9, {st_mode=S_IFREG|0755, st_size=40904, ...}) = 0 20636 mmap(NULL, 2148896, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 9, 0) = 0x2aaaae17b000 20636 mprotect(0x2aaaae183000, 2097152, PROT_NONE) = 0 20636 mmap(0x2aaaae383000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 9, 0x8000) = 0x2aaaae383000 20636 mmap(0x2aaaae384000, 14880, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2aaaae384000 20636 close(9) = 0 20636 open("/u01/app/oracle/oracle/product/10.2.0/db_2/lib/libsepol.so.1", O_RDONLY) = -1 ENOENT (No such file or directory) 20636 open("/lib/libsepol.so.1", O_RDONLY) = 9 20636 read(9, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\340.\0\0004\0\0\0"..., 832) = 832 20636 close(9) = 0 20636 open("/usr/lib/libsepol.so.1", O_RDONLY) = -1 ENOENT (No such file or directory) 20636 open("/usr/local/lib/libsepol.so.1", O_RDONLY) = -1 ENOENT (No such file or directory) 20636 open("/lib64/libsepol.so.1", O_RDONLY) = 9 20636 read(9, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\340<`\3470\0\0\0"..., 832) = 832 20636 fstat(9, {st_mode=S_IFREG|0755, st_size=247528, ...}) = 0 20636 mmap(NULL, 2383168, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 9, 0) = 0x2aaaae388000 20636 mprotect(0x2aaaae3c3000, 2097152, PROT_NONE) = 0 20636 mmap(0x2aaaae5c3000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 9, 0x3b000) = 0x2aaaae5c3000 20636 mmap(0x2aaaae5c4000, 40256, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x2aaaae5c4000 20636 close(9) = 0 20636 mprotect(0x2aaaadf33000, 4096, PROT_READ) = 0 20636 access("/etc/selinux/", F_OK) = 0 20636 open("/etc/selinux/config", O_RDONLY) = 9 20636 fstat(9, {st_mode=S_IFREG|0644, st_size=447, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaae5ce000 20636 read(9, "# This file controls the state o"..., 4096) = 447 20636 read(9, "", 4096) = 0 20636 close(9) = 0 20636 munmap(0x2aaaae5ce000, 4096) = 0 20636 open("/proc/mounts", O_RDONLY) = 9 20636 fstat(9, {st_mode=S_IFREG|0444, st_size=0, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaae5ce000 20636 read(9, "rootfs / rootfs rw 0 0\n/dev/root"..., 4096) = 523 20636 read(9, "", 4096) = 0 20636 close(9) = 0 20636 munmap(0x2aaaae5ce000, 4096) = 0 20636 munmap(0x2aaaadd26000, 34353) = 0 20636 open("/lib64/security/pam_succeed_if.so", O_RDONLY) = 9 20636 read(9, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\220\v\0\0\0\0\0\0"..., 832) = 832 20636 fstat(9, {st_mode=S_IFREG|0755, st_size=12232, ...}) = 0 20636 mmap(NULL, 2107480, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 9, 0) = 0x2aaaae5ce000 20636 mprotect(0x2aaaae5d1000, 2093056, PROT_NONE) = 0 20636 mmap(0x2aaaae7d0000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 9, 0x2000) = 0x2aaaae7d0000 20636 close(9) = 0 20636 open("/lib64/security/pam_deny.so", O_RDONLY) = 9 20636 read(9, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\200\4\0\0\0\0\0\0"..., 832) = 832 20636 fstat(9, {st_mode=S_IFREG|0755, st_size=4080, ...}) = 0 20636 mmap(NULL, 2099408, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 9, 0) = 0x2aaaae7d1000 20636 mprotect(0x2aaaae7d2000, 2093056, PROT_NONE) = 0 20636 mmap(0x2aaaae9d1000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 9, 0) = 0x2aaaae9d1000 20636 close(9) = 0 20636 read(8, "", 4096) = 0 20636 close(8) = 0 20636 munmap(0x2aaaad90b000, 4096) = 0 20636 open("/etc/pam.d/system-auth", O_RDONLY) = 8 20636 fstat(8, {st_mode=S_IFREG|0644, st_size=844, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaad90b000 20636 read(8, "#%PAM-1.0\n# This file is auto-ge"..., 4096) = 844 20636 open("/lib64/security/pam_permit.so", O_RDONLY) = 9 20636 read(9, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0P\5\0\0\0\0\0\0"..., 832) = 832 20636 fstat(9, {st_mode=S_IFREG|0755, st_size=4472, ...}) = 0 20636 mmap(NULL, 2099728, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 9, 0) = 0x2aaaae9d2000 20636 mprotect(0x2aaaae9d3000, 2093056, PROT_NONE) = 0 20636 mmap(0x2aaaaebd2000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 9, 0) = 0x2aaaaebd2000 20636 close(9) = 0 20636 read(8, "", 4096) = 0 20636 close(8) = 0 20636 munmap(0x2aaaad90b000, 4096) = 0 20636 open("/etc/pam.d/system-auth", O_RDONLY) = 8 20636 fstat(8, {st_mode=S_IFREG|0644, st_size=844, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaad90b000 20636 read(8, "#%PAM-1.0\n# This file is auto-ge"..., 4096) = 844 20636 open("/lib64/security/pam_limits.so", O_RDONLY) = 9 20636 read(9, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0000\16\0\0\0\0\0\0"..., 832) = 832 20636 fstat(9, {st_mode=S_IFREG|0755, st_size=12480, ...}) = 0 20636 mmap(NULL, 2107736, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 9, 0) = 0x2aaaaebd3000 20636 mprotect(0x2aaaaebd6000, 2093056, PROT_NONE) = 0 20636 mmap(0x2aaaaedd5000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 9, 0x2000) = 0x2aaaaedd5000 20636 close(9) = 0 20636 read(8, "", 4096) = 0 20636 close(8) = 0 20636 munmap(0x2aaaad90b000, 4096) = 0 20636 open("/lib64/security/pam_loginuid.so", O_RDONLY) = 8 20636 read(8, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\360\10\0\0\0\0\0\0"..., 832) = 832 20636 fstat(8, {st_mode=S_IFREG|0755, st_size=6664, ...}) = 0 20636 mmap(NULL, 2101912, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 8, 0) = 0x2aaaaedd6000 20636 mprotect(0x2aaaaedd7000, 2097152, PROT_NONE) = 0 20636 mmap(0x2aaaaefd7000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 8, 0x1000) = 0x2aaaaefd7000 20636 close(8) = 0 20636 read(7, "", 4096) = 0 20636 close(7) = 0 20636 munmap(0x2aaaaaac6000, 4096) = 0 20636 open("/etc/pam.d/other", O_RDONLY) = 7 20636 fstat(7, {st_mode=S_IFREG|0644, st_size=154, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac6000 20636 read(7, "#%PAM-1.0\nauth required "..., 4096) = 154 20636 read(7, "", 4096) = 0 20636 close(7) = 0 20636 munmap(0x2aaaaaac6000, 4096) = 0 20636 socket(PF_FILE, SOCK_STREAM, 0) = 7 20636 fcntl(7, F_GETFL) = 0x2 (flags O_RDWR) 20636 fcntl(7, F_SETFL, O_RDWR|O_NONBLOCK) = 0 20636 connect(7, {sa_family=AF_FILE, path="/var/run/nscd/socket"}, 110) = -1 ENOENT (No such file or directory) 20636 close(7) = 0 20636 socket(PF_FILE, SOCK_STREAM, 0) = 7 20636 fcntl(7, F_GETFL) = 0x2 (flags O_RDWR) 20636 fcntl(7, F_SETFL, O_RDWR|O_NONBLOCK) = 0 20636 connect(7, {sa_family=AF_FILE, path="/var/run/nscd/socket"}, 110) = -1 ENOENT (No such file or directory) 20636 close(7) = 0 20636 open("/etc/resolv.conf", O_RDONLY) = 7 20636 fstat(7, {st_mode=S_IFREG|0644, st_size=43, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac6000 20636 read(7, "search localdomain\nnameserver 20"..., 4096) = 43 20636 read(7, "", 4096) = 0 20636 close(7) = 0 20636 munmap(0x2aaaaaac6000, 4096) = 0 20636 open("/etc/host.conf", O_RDONLY) = 7 20636 fstat(7, {st_mode=S_IFREG|0644, st_size=17, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac6000 20636 read(7, "order hosts,bind\n", 4096) = 17 20636 read(7, "", 4096) = 0 20636 close(7) = 0 20636 munmap(0x2aaaaaac6000, 4096) = 0 20636 open("/etc/hosts", O_RDONLY) = 7 20636 fcntl(7, F_GETFD) = 0 20636 fcntl(7, F_SETFD, FD_CLOEXEC) = 0 20636 fstat(7, {st_mode=S_IFREG|0644, st_size=339, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac6000 20636 read(7, "# Do not remove the following li"..., 4096) = 339 20636 read(7, "", 4096) = 0 20636 close(7) = 0 20636 munmap(0x2aaaaaac6000, 4096) = 0 20636 open("/u01/app/oracle/oracle/product/10.2.0/db_2/lib/libnss_dns.so.2", O_RDONLY) = -1 ENOENT (No such file or directory) 20636 open("/lib/libnss_dns.so.2", O_RDONLY) = 7 20636 read(7, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\200\v\0\0004\0\0\0"..., 832) = 832 20636 close(7) = 0 20636 open("/usr/lib/libnss_dns.so.2", O_RDONLY) = -1 ENOENT (No such file or directory) 20636 open("/usr/local/lib/libnss_dns.so.2", O_RDONLY) = -1 ENOENT (No such file or directory) 20636 open("/etc/ld.so.cache", O_RDONLY) = 7 20636 fstat(7, {st_mode=S_IFREG|0644, st_size=34353, ...}) = 0 20636 mmap(NULL, 34353, PROT_READ, MAP_PRIVATE, 7, 0) = 0x2aaaaaac6000 20636 close(7) = 0 20636 open("/lib64/libnss_dns.so.2", O_RDONLY) = 7 20636 read(7, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\300\17\0\0\0\0\0\0"..., 832) = 832 20636 fstat(7, {st_mode=S_IFREG|0755, st_size=23728, ...}) = 0 20636 mmap(NULL, 2113792, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 7, 0) = 0x2aaaaefd8000 20636 mprotect(0x2aaaaefdc000, 2093056, PROT_NONE) = 0 20636 mmap(0x2aaaaf1db000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 7, 0x3000) = 0x2aaaaf1db000 20636 close(7) = 0 20636 mprotect(0x2aaaaf1db000, 4096, PROT_READ) = 0 20636 munmap(0x2aaaaaac6000, 34353) = 0 20636 socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 7 20636 connect(7, {sa_family=AF_INET, sin_port=htons(53), sin_addr=inet_addr("202.87.39.14")}, 28) = 0 20636 fcntl(7, F_GETFL) = 0x2 (flags O_RDWR) 20636 fcntl(7, F_SETFL, O_RDWR|O_NONBLOCK) = 0 20636 poll([{fd=7, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1 20636 sendto(7, "\366\21\1\0\0\1\0\0\0\0\0\0\00250\0011\00231\003172\7in-addr"..., 42, MSG_NOSIGNAL, NULL, 0) = 42 20636 poll([{fd=7, events=POLLIN, revents=POLLIN}], 1, 5000) = 1 20636 ioctl(7, FIONREAD, [119]) = 0 20636 recvfrom(7, "\366\21\205\203\0\1\0\0\0\1\0\0\00250\0011\00231\003172\7in-addr"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53), sin_addr=inet_addr("202.87.39.14")}, [16]) = 119 20636 close(7) = 0 20636 lstat("/etc/vsftpd/ftpusers", {st_mode=S_IFREG|0600, st_size=125, ...}) = 0 20636 open("/etc/vsftpd/ftpusers", O_RDONLY) = 7 20636 fstat(7, {st_mode=S_IFREG|0600, st_size=125, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac6000 20636 read(7, "# Users that are not allowed to "..., 4096) = 125 20636 read(7, "", 4096) = 0 20636 close(7) = 0 20636 munmap(0x2aaaaaac6000, 4096) = 0 20636 open("/etc/passwd", O_RDONLY) = 7 20636 fcntl(7, F_GETFD) = 0 20636 fcntl(7, F_SETFD, FD_CLOEXEC) = 0 20636 fstat(7, {st_mode=S_IFREG|0644, st_size=1649, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac6000 20636 read(7, "root:x:0:0:root:/root:/bin/bash\n"..., 4096) = 1649 20636 close(7) = 0 20636 munmap(0x2aaaaaac6000, 4096) = 0 20636 stat("/etc/shells", {st_mode=S_IFREG|0644, st_size=60, ...}) = 0 20636 open("/etc/shells", O_RDONLY) = 7 20636 fstat(7, {st_mode=S_IFREG|0644, st_size=60, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac6000 20636 read(7, "/bin/sh\n/bin/bash\n/sbin/nologin\n"..., 4096) = 60 20636 close(7) = 0 20636 munmap(0x2aaaaaac6000, 4096) = 0 20636 getuid() = 0 20636 open("/etc/passwd", O_RDONLY) = 7 20636 fcntl(7, F_GETFD) = 0 20636 fcntl(7, F_SETFD, FD_CLOEXEC) = 0 20636 fstat(7, {st_mode=S_IFREG|0644, st_size=1649, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac6000 20636 read(7, "root:x:0:0:root:/root:/bin/bash\n"..., 4096) = 1649 20636 close(7) = 0 20636 munmap(0x2aaaaaac6000, 4096) = 0 20636 open("/etc/shadow", O_RDONLY) = 7 20636 fcntl(7, F_GETFD) = 0 20636 fcntl(7, F_SETFD, FD_CLOEXEC) = 0 20636 fstat(7, {st_mode=S_IFREG|0400, st_size=1074, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac6000 20636 read(7, "root:$1$KvX3NsHQ$2vEzb1c1cUMGfKi"..., 4096) = 1074 20636 close(7) = 0 20636 munmap(0x2aaaaaac6000, 4096) = 0 20636 open("/etc/passwd", O_RDONLY) = 7 20636 fcntl(7, F_GETFD) = 0 20636 fcntl(7, F_SETFD, FD_CLOEXEC) = 0 20636 fstat(7, {st_mode=S_IFREG|0644, st_size=1649, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac6000 20636 read(7, "root:x:0:0:root:/root:/bin/bash\n"..., 4096) = 1649 20636 close(7) = 0 20636 munmap(0x2aaaaaac6000, 4096) = 0 20636 open("/etc/shadow", O_RDONLY) = 7 20636 fcntl(7, F_GETFD) = 0 20636 fcntl(7, F_SETFD, FD_CLOEXEC) = 0 20636 fstat(7, {st_mode=S_IFREG|0400, st_size=1074, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac6000 20636 read(7, "root:$1$KvX3NsHQ$2vEzb1c1cUMGfKi"..., 4096) = 1074 20636 close(7) = 0 20636 munmap(0x2aaaaaac6000, 4096) = 0 20636 socket(PF_NETLINK, SOCK_RAW, 9) = 7 20636 fcntl(7, F_SETFD, FD_CLOEXEC) = 0 20636 socket(PF_NETLINK, SOCK_RAW, 0) = 8 20636 bind(8, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0 20636 getsockname(8, {sa_family=AF_NETLINK, pid=20636, groups=00000000}, [4294967308]) = 0 20636 sendto(8, "\24\0\0\0\26\0\1\3\3531QH\0\0\0\0\0\0\0\0", 20, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20 20636 recvmsg(8, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"<\0\0\0\24\0\2\0\3531QH\234P\0\0\2\10\200\376\1\0\0\0\10\0\1\0 \177\0\0\1"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128 20636 recvmsg(8, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\3531QH\234P\0\0\n\200\200\376\1\0\0\0\24\0\1\ 0\0\0\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128 20636 recvmsg(8, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0\3531QH\234P\0\0\0\0\0\0\1\0\0\0\24\0\1\0\0\0 \0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20 20636 close(8) = 0 20636 readlink("/proc/self/exe", "/usr/sbin/vsftpd", 4095) = 16 20636 sendto(7, "\224\0\0\0L\4\5\0\1\0\0\0\0\0\0\0PAM: authenticat"..., 148, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 148 20636 poll([{fd=7, events=POLLIN, revents=POLLIN}], 1, 100) = 1 20636 recvfrom(7, "$\0\0\0\2\0\0\0\1\0\0\0\234P\0\0\0\0\0\0\224\0\0\0L\4\5\0\1\0\0\0"..., 8988, MSG_PEEK|MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 36 20636 recvfrom(7, "$\0\0\0\2\0\0\0\1\0\0\0\234P\0\0\0\0\0\0\224\0\0\0L\4\5\0\1\0\0\0"..., 8988, MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 36 20636 close(7) = 0 20636 getuid() = 0 20636 open("/etc/passwd", O_RDONLY) = 7 20636 fcntl(7, F_GETFD) = 0 20636 fcntl(7, F_SETFD, FD_CLOEXEC) = 0 20636 fstat(7, {st_mode=S_IFREG|0644, st_size=1649, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac6000 20636 read(7, "root:x:0:0:root:/root:/bin/bash\n"..., 4096) = 1649 20636 close(7) = 0 20636 munmap(0x2aaaaaac6000, 4096) = 0 20636 open("/etc/shadow", O_RDONLY) = 7 20636 fcntl(7, F_GETFD) = 0 20636 fcntl(7, F_SETFD, FD_CLOEXEC) = 0 20636 fstat(7, {st_mode=S_IFREG|0400, st_size=1074, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac6000 20636 read(7, "root:$1$KvX3NsHQ$2vEzb1c1cUMGfKi"..., 4096) = 1074 20636 close(7) = 0 20636 munmap(0x2aaaaaac6000, 4096) = 0 20636 open("/etc/passwd", O_RDONLY) = 7 20636 fcntl(7, F_GETFD) = 0 20636 fcntl(7, F_SETFD, FD_CLOEXEC) = 0 20636 fstat(7, {st_mode=S_IFREG|0644, st_size=1649, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac6000 20636 read(7, "root:x:0:0:root:/root:/bin/bash\n"..., 4096) = 1649 20636 close(7) = 0 20636 munmap(0x2aaaaaac6000, 4096) = 0 20636 socket(PF_NETLINK, SOCK_RAW, 9) = 7 20636 fcntl(7, F_SETFD, FD_CLOEXEC) = 0 20636 socket(PF_NETLINK, SOCK_RAW, 0) = 8 20636 bind(8, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0 20636 getsockname(8, {sa_family=AF_NETLINK, pid=20636, groups=00000000}, [12]) = 0 20636 sendto(8, "\24\0\0\0\26\0\1\3\3531QH\0\0\0\0\0\0\0\0", 20, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20 20636 recvmsg(8, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"<\0\0\0\24\0\2\0\3531QH\234P\0\0\2\10\200\376\1\0\0\0\10\0\1\0 \177\0\0\1"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128 20636 recvmsg(8, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\3531QH\234P\0\0\n\200\200\376\1\0\0\0\24\0\1\ 0\0\0\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128 20636 recvmsg(8, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0\3531QH\234P\0\0\0\0\0\0\1\0\0\0\24\0\1\0\0\0 \0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20 20636 close(8) = 0 20636 readlink("/proc/self/exe", "/usr/sbin/vsftpd", 4095) = 16 20636 sendto(7, "\220\0\0\0M\4\5\0\2\0\0\0\0\0\0\0PAM: accounting "..., 144, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 144 20636 poll([{fd=7, events=POLLIN, revents=POLLIN}], 1, 100) = 1 20636 recvfrom(7, "$\0\0\0\2\0\0\0\2\0\0\0\234P\0\0\0\0\0\0\220\0\0\0M\4\5\0\2\0\0\0"..., 8988, MSG_PEEK|MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 36 20636 recvfrom(7, "$\0\0\0\2\0\0\0\2\0\0\0\234P\0\0\0\0\0\0\220\0\0\0M\4\5\0\2\0\0\0"..., 8988, MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 36 20636 close(7) = 0 20636 open("/etc/security/pam_env.conf", O_RDONLY) = 7 20636 fstat(7, {st_mode=S_IFREG|0644, st_size=3088, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac6000 20636 read(7, "# $Date: 2005/08/16 12:27:42 $\n#"..., 4096) = 3088 20636 read(7, "", 4096) = 0 20636 close(7) = 0 20636 munmap(0x2aaaaaac6000, 4096) = 0 20636 open("/etc/environment", O_RDONLY) = 7 20636 fstat(7, {st_mode=S_IFREG|0644, st_size=0, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac6000 20636 read(7, "", 4096) = 0 20636 close(7) = 0 20636 munmap(0x2aaaaaac6000, 4096) = 0 20636 socket(PF_NETLINK, SOCK_RAW, 9) = 7 20636 fcntl(7, F_SETFD, FD_CLOEXEC) = 0 20636 socket(PF_NETLINK, SOCK_RAW, 0) = 8 20636 bind(8, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0 20636 getsockname(8, {sa_family=AF_NETLINK, pid=20636, groups=00000000}, [12]) = 0 20636 sendto(8, "\24\0\0\0\26\0\1\3\3531QH\0\0\0\0\0\0\0\0", 20, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20 20636 recvmsg(8, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"<\0\0\0\24\0\2\0\3531QH\234P\0\0\2\10\200\376\1\0\0\0\10\0\1\0 \177\0\0\1"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128 20636 recvmsg(8, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\3531QH\234P\0\0\n\200\200\376\1\0\0\0\24\0\1\ 0\0\0\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128 20636 recvmsg(8, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0\3531QH\234P\0\0\0\0\0\0\1\0\0\0\24\0\1\0\0\0 \0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20 20636 close(8) = 0 20636 readlink("/proc/self/exe", "/usr/sbin/vsftpd", 4095) = 16 20636 sendto(7, "\214\0\0\0O\4\5\0\3\0\0\0\0\0\0\0PAM: setcred acc"..., 140, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 140 20636 poll([{fd=7, events=POLLIN, revents=POLLIN}], 1, 100) = 1 20636 recvfrom(7, "$\0\0\0\2\0\0\0\3\0\0\0\234P\0\0\0\0\0\0\214\0\0\0O\4\5\0\3\0\0\0"..., 8988, MSG_PEEK|MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 36 20636 recvfrom(7, "$\0\0\0\2\0\0\0\3\0\0\0\234P\0\0\0\0\0\0\214\0\0\0O\4\5\0\3\0\0\0"..., 8988, MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 36 20636 close(7) = 0 20636 munmap(0x2aaaad305000, 2102072) = 0 20636 munmap(0x2aaaad507000, 2106072) = 0 20636 munmap(0x2aaaad70a000, 2100720) = 0 20636 munmap(0x2aaaad90c000, 2106728) = 0 20636 munmap(0x2aaaadb0f000, 2189608) = 0 20636 munmap(0x2aaaadd2f000, 2306464) = 0 20636 munmap(0x2aaaadf63000, 2192816) = 0 20636 munmap(0x2aaaae17b000, 2148896) = 0 20636 munmap(0x2aaaae388000, 2383168) = 0 20636 munmap(0x2aaaae5ce000, 2107480) = 0 20636 munmap(0x2aaaae7d1000, 2099408) = 0 20636 munmap(0x2aaaae9d2000, 2099728) = 0 20636 munmap(0x2aaaaebd3000, 2107736) = 0 20636 munmap(0x2aaaaedd6000, 2101912) = 0 20636 rt_sigaction(SIGCHLD, {0x555555567b80, ~[RTMIN RT_1], SA_RESTORER, 0x2aaaab974070}, NULL, 8) = 0 20636 write(5, "\1", 1) = 1 20636 wait4(-1, <unfinished ...> 20636 <... wait4 resumed> [{WIFEXITED(s) && WEXITSTATUS(s) == 0}], 0, NULL) = 20637 20636 rt_sigprocmask(SIG_UNBLOCK, [CHLD], NULL, 8) = 0 20636 --- SIGCHLD (Child exited) @ 0 (0) --- 20636 rt_sigreturn(0x11) = 0 20636 rt_sigprocmask(SIG_BLOCK, [CHLD], NULL, 8) = 0 20636 rt_sigaction(SIGCHLD, {0x555555564ce0, ~[RTMIN RT_1], SA_RESTORER, 0x2aaaab974070}, NULL, 8) = 0 20636 clone(child_stack=0, flags=CLONE_CHILD_CLEARTID|CLONE_CHILD_SETTID|SIGCHLD, child_tidptr=0x2aaaad0f9610) = 20638 20636 getuid() = 0 20636 open("/etc/passwd", O_RDONLY) = 7 20636 fcntl(7, F_GETFD) = 0 20636 fcntl(7, F_SETFD, FD_CLOEXEC <unfinished ...> 20636 <... fcntl resumed> ) = 0 20636 fstat(7, {st_mode=S_IFREG|0644, st_size=1649, ...}) = 0 20636 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0 <unfinished ...> 20636 <... mmap resumed> ) = 0x2aaaaaac6000 20636 read(7, <unfinished ...> 20636 <... read resumed> "root:x:0:0:root:/root:/bin/bash\n"..., 4096) = 1649 20636 close(7) = 0 20636 munmap(0x2aaaaaac6000, 4096) = 0 20636 setgroups(0, []) = 0 20636 chdir("/usr/share/empty") = 0 20636 chroot("." <unfinished ...> 20636 <... chroot resumed> ) = 0 20636 capget(0x19980330, 0, {CAP_CHOWN|CAP_DAC_OVERRIDE|CAP_DAC_READ_SEARCH|CAP_FOWNER|CAP_FSETID|CAP_KI LL|CAP_SETGID|CAP_SETUID|CAP_LINUX_IMMUTABLE|CAP_NET_BIND_SERVICE|CAP_NET_BR OADCAST|CAP_NET_ADMIN|CAP_NET_RAW|CAP_IPC_LOCK|CAP_IPC_OWNER|CAP_SYS_MODULE| CAP_SYS_RAWIO|CAP_SYS_CHROOT|CAP_SYS_PTRACE|CAP_SYS_PACCT|CAP_SYS_ADMIN|CAP_ SYS_BOOT|CAP_SYS_NICE|CAP_SYS_RESOURCE|CAP_SYS_TIME|CAP_SYS_TTY_CONFIG|0xf80 00000, CAP_CHOWN|CAP_DAC_OVERRIDE|CAP_DAC_READ_SEARCH|CAP_FOWNER|CAP_FSETID|CAP_KIL L|CAP_SETGID|CAP_SETUID|CAP_LINUX_IMMUTABLE|CAP_NET_BIND_SERVICE|CAP_NET_BRO ADCAST|CAP_NET_ADMIN|CAP_NET_RAW|CAP_IPC_LOCK|CAP_IPC_OWNER|CAP_SYS_MODULE|C AP_SYS_RAWIO|CAP_SYS_CHROOT|CAP_SYS_PTRACE|CAP_SYS_PACCT|CAP_SYS_ADMIN|CAP_S YS_BOOT|CAP_SYS_NICE|CAP_SYS_RESOURCE|CAP_SYS_TIME|CAP_SYS_TTY_CONFIG|0xf800 0000, 0}) = 0 20636 prctl(0x8, 0, 0x21, 0x555558600ba0, 0x555558600bb0) = 0 20636 prctl(0x8, 0x1, 0x1, 0xffffffffffffffff, 0x555558600bb0 <unfinished ...> 20636 <... prctl resumed> ) = 0 20636 setgid(99 <unfinished ...> 20636 <... setgid resumed> ) = 0 20636 setuid(99 <unfinished ...> 20636 <... setuid resumed> ) = 0 20636 capset(0x19980330, 0, {CAP_NET_BIND_SERVICE, CAP_NET_BIND_SERVICE, 0} <unfinished ...> 20636 <... capset resumed> ) = 0 20636 rt_sigprocmask(SIG_UNBLOCK, [CHLD], <unfinished ...> 20636 <... rt_sigprocmask resumed> NULL, 8) = 0 20636 read(5, <unfinished ...> -----Original Message----- From: Joe Landman [mailto:landman@xxxxxxxxxxxxxxxxxxxxxxx] Sent: Thursday, June 12, 2008 6:19 PM To: Rohan Cc: 'Krishna Srinivas'; Gluster-devel@xxxxxxxxxx Subject: Re: FW: GlusterFS as home directory on FTP server Rohan wrote: > Any feedback? Hi Rohan: Could you strace a few of these to see what they are up to? BTW, are you using xinetd to launch vsftpd or running it stand alone? We usually recommend the latter to our customers. If you are running it through xinetd, please restart xinetd, and add strace to the startup in /etc/xinetd.d/vsftpd file. It would be useful to be able to see these logs to see what is going on. strace -p PROCESS_ID will get you the current system call trace. Joe > > -----Original Message----- > From: gluster-devel-bounces+rohan.thale=moneycontrol.com@xxxxxxxxxx > [mailto:gluster-devel-bounces+rohan.thale=moneycontrol.com@xxxxxxxxxx] On > Behalf Of Rohan > Sent: Thursday, June 12, 2008 2:46 PM > To: 'Krishna Srinivas' > Cc: Gluster-devel@xxxxxxxxxx > Subject: RE: FW: GlusterFS as home directory on FTP server > > When I do ps -eF I can see many vsftpd process running. > > I can see behavior only after we moved to gluster fs. > > # ps -eF|grep vsftp > root 12822 1 0 9385 576 3 14:41 ? 00:00:00 > /usr/sbin/vsftpd /etc/vsftpd/vsftpd.conf > nobody 12826 12822 0 10425 1368 3 14:41 ? 00:00:00 > /usr/sbin/vsftpd /etc/vsftpd/vsftpd.conf > 500 12828 12826 0 10425 840 0 14:41 ? 00:00:00 > /usr/sbin/vsftpd /etc/vsftpd/vsftpd.conf -- Joseph Landman, Ph.D Founder and CEO Scalable Informatics LLC, email: landman@xxxxxxxxxxxxxxxxxxxxxxx web : http://www.scalableinformatics.com http://jackrabbit.scalableinformatics.com phone: +1 734 786 8423 fax : +1 866 888 3112 cell : +1 734 612 4615