- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- /etc/resolv.conf file always be changed automatica...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-16-2010 05:45 PM
тАО11-16-2010 05:45 PM
Re: /etc/resolv.conf file always be changed automatically
Sorry for that and thank you for your idea.
I checked the server and there is no .rhosts file existing .
DiaoXin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-16-2010 05:51 PM
тАО11-16-2010 05:51 PM
Re: /etc/resolv.conf file always be changed automatically
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-16-2010 06:14 PM
тАО11-16-2010 06:14 PM
Re: /etc/resolv.conf file always be changed automatically
I really find there is one user account ssh to the server at 4:00am everyday , and I will try to discuss with the user to deny his ssh connection for test.
Thank you!
DiaoXin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-16-2010 06:46 PM
тАО11-16-2010 06:46 PM
Re: /etc/resolv.conf file always be changed automatically
I discussed with the user about his ssh connection. It is a cronjob for him to collect some information from the server and he only use the normal user permission to do this .
So I think it is not the root cause.
DiaoXin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-17-2010 06:02 AM
тАО11-17-2010 06:02 AM
Re: /etc/resolv.conf file always be changed automatically
Check /var/cfengine.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-17-2010 07:56 AM
тАО11-17-2010 07:56 AM
Re: /etc/resolv.conf file always be changed automatically
Verify the permissions of the file. It should be owned by root and have 644 (-rw-r--r--) permission mode. Therefore whatever is changing it is running as root.
Check if there is a batch scheduling tool installed other than cron.
Check if you have sudo installed and which users are allowed to run commands via sudo.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-17-2010 06:28 PM
тАО11-17-2010 06:28 PM
Re: /etc/resolv.conf file always be changed automatically
But I can not find /var/cfengine in the server.
DiaoXin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-17-2010 06:51 PM
тАО11-17-2010 06:51 PM
Re: /etc/resolv.conf file always be changed automatically
tcpdump is not installed .
I checked the permission of /etc/resolv.conf , it is 644 . and we use sudo in the server , but I find some users in sudoers file and I can not delete them because I am not sure whether they are necessary for some applications .
For the batch scheduler not cronjob , sorry I don't know how to check it in the server . Can you give me any ideas?
Diaoxin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-17-2010 06:52 PM
тАО11-17-2010 06:52 PM
Re: /etc/resolv.conf file always be changed automatically
Use HIDS to find out whats happening.
Tcpdump in that time is a good idea.
If its non-prod or if you can afford, take the network down for the said period and see if it happens just to isolate the cause being from n/w or local.
Think when the issue started and if you get a date/time, see what was changed if your change control is good.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-17-2010 10:11 PM
тАО11-17-2010 10:11 PM
Re: /etc/resolv.conf file always be changed automatically
You can install it from:
http://hpux.connect.org.uk/hppd/hpux/Networking/Admin/tcpdump-4.1.1/
Best regards,
Horia.
Horia.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-17-2010 10:17 PM
тАО11-17-2010 10:17 PM
Re: /etc/resolv.conf file always be changed automatically
The " last " command can not works ,it shows the error "Invalid record size. Unable to continue ...".
diaoxin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-17-2010 10:19 PM
тАО11-17-2010 10:19 PM
Re: /etc/resolv.conf file always be changed automatically
This means that you have a corrupted wtmp file.
You must do this:
cat /dev/null > /var/adm/wtmp
Horia.
Horia.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-17-2010 10:23 PM
тАО11-17-2010 10:23 PM
Re: /etc/resolv.conf file always be changed automatically
Just figure out which wtmp you have by running ls on /var/adm.
Horia.
Horia.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-17-2010 10:25 PM
тАО11-17-2010 10:25 PM
Re: /etc/resolv.conf file always be changed automatically
I run the commands as below,
server# cat /dev/null > /var/adm/wtmps
server# last
WTMPS_FILE begins at Thu Jan 1 07:59:59
it works.
diaoxin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-17-2010 10:26 PM
тАО11-17-2010 10:26 PM
Re: /etc/resolv.conf file always be changed automatically
Horia.
Horia.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-17-2010 10:28 PM
тАО11-17-2010 10:28 PM
Re: /etc/resolv.conf file always be changed automatically
I will try to install tcpdump .
Thanks.
diaoxin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-17-2010 10:32 PM
тАО11-17-2010 10:32 PM
Re: /etc/resolv.conf file always be changed automatically
Ok , I did it .and "last " shows the information now.
diaoxin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-17-2010 11:36 PM
тАО11-17-2010 11:36 PM
Re: /etc/resolv.conf file always be changed automatically
I installed tcpdump in the server , and tried to generate a log file whose contents as below ,
15:22:21.299732 IP 150.236.34.226.1023 > 150.236.34.229.2049: tcp 160
15:22:21.299930 IP 150.236.34.229.2049 > 150.236.34.226.1023: tcp 120
15:22:21.300020 IP 150.236.34.226.1023 > 150.236.34.229.2049: tcp 172
15:22:21.300248 IP 150.236.34.229.2049 > 150.236.34.226.1023: tcp 120
But I have no ideas how to analyse it . Can you help adivse?
diaoxin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-18-2010 12:02 AM
тАО11-18-2010 12:02 AM
Re: /etc/resolv.conf file always be changed automatically
>If you have tcpdump installed, run tcpdump from 4:59am to 5:01am to see who is connecting to the server and at what port. This will tell you if the resolv.conf file is overwritten by an external process or not.
You could start tcpdump by cron at 4:59 and monitor the TCP connections to/from your server.
You should add the following 2 lines into crontab for root user (assuming you have tcpdump in standard place: /usr/sbin, you should change that if inappropriate):
59 4 * * * /usr/sbin/tcpdump -w /root/tcpdump.txt
01 5 * * * /root/kill-tcpdump.sh
Where kill-tcpdump.sh looks something like this:
#!/bin/sh
PID=`ps -e |grep tcpdump |awk '{print $1}'`
kill -9 $PID
########## Done ##########
Next day you should check of course the file /root/tcpdump.txt. You could also, increase verbosity by adding -vv to tcpdump in crontab like in tcpdump -vv -w /root/tcpdump.txt
Best regards,
Horia.
Horia.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-18-2010 12:18 AM
тАО11-18-2010 12:18 AM
Re: /etc/resolv.conf file always be changed automatically
The format is like this:
date Source_IP_Address.Source_PortNo Dest_IP_Address.Dest_PortNo protocol size
So, at this time: 15:22:21.299732, the machine having IP address 150.236.34.226 is making a TCP connection from port 1023 to machine having IP: 150.236.34.229 to port 2049
Read manual page at:
http://www.tcpdump.org/tcpdump_man.html
Which IP address is the one of your server?
In the interval of time TTr suggested, you should check the connections made from other servers to yours.
Analyze those server's logs and try to understand why those are needed to make connections to your server.
Best regards from Romania,
Horia.
Horia.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-18-2010 01:40 AM
тАО11-18-2010 01:40 AM
Re: /etc/resolv.conf file always be changed automatically
Thank you so much !
I have added the script to crontab , and will check it tomorrow morning.
DiaoXin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-18-2010 06:19 AM
тАО11-18-2010 06:19 AM
Re: /etc/resolv.conf file always be changed automatically
HTH.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-18-2010 10:29 AM
тАО11-18-2010 10:29 AM
Re: /etc/resolv.conf file always be changed automatically
Not really, unless you want to match up successful logins and ignore typing mistakes. This is one file you shouldn't truncate, since it has the bad logins.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-18-2010 06:19 PM
тАО11-18-2010 06:19 PM
Re: /etc/resolv.conf file always be changed automatically
But the server really doesn't have cfengine. I cannot find "cfengine" under /opt , and can not find it from "swlist " output.
diaoxin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-18-2010 10:34 PM
тАО11-18-2010 10:34 PM
Re: /etc/resolv.conf file always be changed automatically
When I was talking about consistency I was in fact thinking about keeping both information (all/successful and bad login) from a common start point (in time).
DiaoXin: Did you manage to take a decision about connections made to/from your server in the specified time frame?
Horia.
Horia.