netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* DoS by cat /proc/net/ip_conntrack ?
@ 2008-03-06 13:43 Denys Fedoryshchenko
  2008-03-06 13:51 ` Krzysztof Oledzki
  0 siblings, 1 reply; 7+ messages in thread
From: Denys Fedoryshchenko @ 2008-03-06 13:43 UTC (permalink / raw)
  To: netdev

Hi again

On loaded router
net.netfilter.nf_conntrack_count = 415633
passing about 100-150 Mbps
network cards 3xe100, 1xe1000e

i tried to issue command cat /proc/net/ip_conntrack |grep 'something'

Router went dead for about 2 minutes, even i disconnect ssh session. 
Ping was looks like this:
64 bytes from dotfib (10.184.184.1): icmp_seq=15 ttl=61 time=4321 ms
64 bytes from dotfib (10.184.184.1): icmp_seq=50 ttl=61 time=398 ms
64 bytes from dotfib (10.184.184.1): icmp_seq=122 ttl=61 time=15.3 ms
64 bytes from dotfib (10.184.184.1): icmp_seq=142 ttl=61 time=4452 ms
64 bytes from dotfib (10.184.184.1): icmp_seq=180 ttl=61 time=850 ms
(system recovered)
64 bytes from dotfib (10.184.184.1): icmp_seq=182 ttl=61 time=0.681 ms
64 bytes from dotfib (10.184.184.1): icmp_seq=183 ttl=61 time=0.936 ms
64 bytes from dotfib (10.184.184.1): icmp_seq=184 ttl=61 time=2.94 ms

I dont think it is normal, and such command taking a lot of system resources 
and cause whole system to hang.

Kernel 2.6.24.2

--
Denys Fedoryshchenko
Technical Manager
Virtual ISP S.A.L.


^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2008-03-08 15:47 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-03-06 13:43 DoS by cat /proc/net/ip_conntrack ? Denys Fedoryshchenko
2008-03-06 13:51 ` Krzysztof Oledzki
2008-03-08 12:26   ` Jarek Poplawski
2008-03-08 12:33     ` Jarek Poplawski
2008-03-08 14:24       ` Denys Fedoryshchenko
2008-03-08 14:44         ` Jarek Poplawski
2008-03-08 15:18           ` Patrick McHardy

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).