View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0001211 | unreal | ircd | public | 2003-08-26 20:47 | 2004-02-01 01:32 |
| Reporter | monolith | Assigned To | |||
| Priority | normal | Severity | major | Reproducibility | always |
| Status | closed | Resolution | open | ||
| Product Version | 3.2-beta17 | ||||
| Summary | 0001211: Extremely high CPU usage on gzlines (possibly glines as well) | ||||
| Description | When banning a botnet of approximately 300 bots, all of our beta17 servers encountered extremely high CPU usage (30% on my p4 2.4gHz). The bans were done via gzlines via services (www.ircservices.za.net/andrew church version - current stable release of 5.x). This should not be occuring, I would think. :) | ||||
| Steps To Reproduce | Just ban a large number of auto-reconnecting clients. You'll feel the pain. ;) | ||||
| Additional Information | I could see this potentially being a DoS situation for irc networks running unreal. A few thousand auto-reconnecting clients would grind the servers to a halt, no sysadmin on earth would allow them to continue to run like that. | ||||
| 3rd party modules | |||||
|
|
With a few thousand reconnecting clients you can kill almost any network/ircd I think, especially since there's usually a max socket fds limit of 1024. Hmmm 300 (re)connects/sec = 30% cpu? that's ~1000 connects/sec for 100% cpu [=speculation] and ~1.1ms CPU per connect... that's too high indeed, especially at such a machine.. but still... If I got the time I'll try to simulate the situation... I did a tiny test at my p450/384M/Linux box and it used ~8% cpu for 50 connects/sec... 300reconnects/sec at 30% cpu on a ~6x as fast machine seems weird then, but maybe it's exponential... blah... ;p. [End of speculation] |
|
|
That's the thing - this was 300 clients off the network, they were all connected to random servers, meaning that's 300 clients split over ~6 servers. Not 300 autoconnecting to one. |
|
|
Oh also, keep in mind these are 300 different hosts. Not one host but 300 connections. So ~150 gzlines (accounting for hosts that could be masked) with 300 matching clients split over 6 servers linked. The hub (one of my other servers) had almost no cpu usage. It was _only_ the machines performing the gzline. When removed, the cpu usage went back down to 0. |
|
|
Uhg, too many bugnotes! I need to stay quiet for a bit and put them all together. ;) I forgot to mention, it was not just my server, every server on the network (all kinds of OS's, different flavours of linux, freebsd). So I'd say it's probably not just unreal + freebsd. |
|
|
Yeah I get a emailflood with "bugnote added" ;)). Thanks for the additional info however.. pretty weird. |
|
|
on a side note, wouldnt the bots have something in common?? i mean every bot / botnet have a common factor, either same GECOS or a nickname / Ident match, or a part nickname / ident match like this ( AGJSY (ISUEYK|[email protected]) ) or same version / finger reply or No version / finger reply.... was they not on the same isp, many botnets some r on a " common " ISP. which if u banned would kill all, *shrugs*, same nicknames? same idents, lol list is endless i spend all my time online mirc coding against floods :/ If they have a common factor use it to ur advantage, coz all bots have them.. ( if u can prove me wrong i wanan see ;] ) |
|
|
Unfortunately White_Magic, that isn't true. We have finally managed to disinfect all of the computers with the trojan which solved that particular problem, but the trojan generated random replies for all queries, and the seed must have been randomized somehow too because we could not determine the algorithm of randomization. There was no commonality between the bots. I doubt syzop is enjoying getting his email box flooded over this, if you want to continue the discussion email me directly [email protected]. This really has nothing to do with the issue in unrealircd and cpu usage. :) Cheers. |
|
|
I was never able to track this issue, also I made some speed improvements in CVS (but since I don't think that was the problem in the first place I doubt that will improve much).. I'll close this bug now :). If it happends again and you got some idea what caused it, feel free to contact me at [email protected] |
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2003-08-26 20:47 | monolith | New Issue | |
| 2003-08-27 00:56 | syzop | Note Added: 0003523 | |
| 2003-08-27 00:57 | monolith | Note Added: 0003524 | |
| 2003-08-27 00:59 | monolith | Note Added: 0003525 | |
| 2003-08-27 01:01 | monolith | Note Added: 0003527 | |
| 2003-08-27 01:16 | syzop | Note Added: 0003529 | |
| 2003-12-04 18:27 | White_Magic | Note Added: 0004201 | |
| 2003-12-04 23:05 | monolith | Note Added: 0004205 | |
| 2004-02-01 01:32 | syzop | Status | new => closed |
| 2004-02-01 01:32 | syzop | Note Added: 0004833 |