httpd-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Igor V. Ruzanov" <world...@redline.ru>
Subject [users@httpd] NeedHelp
Date Tue, 19 Sep 2006 10:23:47 GMT
Hello!
I use Apache/1.3.28 web-server under FreeBSD 5.2.1-RELEASE within jail
environment. And there is some strange thing when i'm checking
http-processes by `ps lax':

   80 57281 82970   0   4  0 11772 8916 accept SLJ   ??    0:27.66 /home/httpd/bin/httpd
   80 57658 82970   0   4  0 11404 8544 accept SLJ   ??    0:25.66 /home/httpd/bin/httpd
   80 57697 82970   0   4  0 10920 8056 accept SLJ   ??    0:25.95 /home/httpd/bin/httpd
   80 57783 82970   0   4  0 10832 7932 accept SLJ   ??    0:24.53 /home/httpd/bin/httpd
   80 57935 82970   0   4  0 11240 8356 sbwait SLJ   ??    0:24.56 /home/httpd/bin/httpd
   80 57995 82970   0   4  0 11132 8264 accept SLJ   ??    0:26.63 /home/httpd/bin/httpd
   80 58258 82970   0   4  0 11164 8284 sbwait SLJ   ??    0:24.28 /home/httpd/bin/httpd
   80 58311 82970   0   4  0 11060 8296 accept SLJ   ??    0:21.70 /home/httpd/bin/httpd
   80 73984 82970   0   4  0 11160 8260 accept SLJ   ??    0:17.02 /home/httpd/bin/httpd
    0 82970     1   0  96  0  8048 4892 select SLsJ  ??    0:30.28 /home/httpd/bin/httpd
>  80 69523     1   0  96  0  6148 1232 select SLsJ  ??    0:00.49 (httpd)
   80 84457 82970   0   4  0 10884 7972 accept SLJ   ??    0:11.19 /home/httpd/bin/httpd

The string `80 83454     1   0  96  0  6148 1232 select SLsJ  ??
0:00.49 (httpd)'
is confused me because i don't know what is the process (httpd) (it seems
to be there is parent process with PPID=1). And the following picture is
appearing when i do the `sockstat| grep http' command:

  www      httpd      89715 68 tcp4   217.144.97.27:80      *:*
  www      httpd      89616 68 tcp4   217.144.97.27:80      *:*
  www      httpd      89520 3  tcp4   217.144.97.27:80      81.3.182.146:58911
  www      httpd      89520 68 tcp4   217.144.97.27:80      *:*
  www      httpd      84457 3  tcp4   217.144.97.27:80      62.76.200.2:52881
  www      httpd      84457 4  stream -> /tmp/mysql.sock
  www      httpd      84457 68 tcp4   217.144.97.27:80      *:*
  www      httpd      73984 4  stream -> /tmp/mysql.sock
  www      httpd      73984 68 tcp4   217.144.97.27:80      *:*
  www      httpd      69523 4  stream -> /tmp/mysql.sock
> www      httpd      69523 5  tcp4   217.144.97.27:53407   84.19.182.61:6667
  www      httpd      58311 3  tcp4   217.144.97.27:80      62.76.200.2:52617
  www      httpd      58311 4  stream -> /tmp/mysql.sock

Same process is in the string `www      httpd      69523 5  tcp4
217.144.97.27:53407   84.19.182.61:6667'. Its not difficult to see that we
deal with tcp-connection to irc-server.
Could you please help me to anderstand such behaviour of Apache-server, is
it normal situation or maybe its a some vulnerability of my version of
Apache?


---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
   "   from the digest: users-digest-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org


Mime
View raw message