öàªèÒ »ÃÐàÀ·µèÒ§æ
öàªèÒ ¨Ñ§ËÇÑ´
brute force
Çѹ·Õè: 26/04/2012
àÇÅÒ: 09:36:09
http://help.directadmin.com/item.php?id=402
If you're noticing your system load is on the rise, as you can see that the "dataskq" binary is running at the top of the list (in "top"), this guide will help you debug what it's doing.
1) Check:
/var/log/directadmin/system.log
to see if the tally is being run. If Users continue to be added to the log (the logs is doing something), then it's likely just the nightly tally, which is normal (assuming the log continues to grow and isn't just stuck on one User)
2) The first thing to do, is to simply ask the dataskq what it's up to. To do this, type:
3) If the output makes reference to Maildir along with a path, then what it likely means is that the mentioned path contains an over-sized inbox. Check that inbox and delete the messages, if the email user doesn't seem to be deleting them.
4) If the output makes reference to brute_force or some related file, then the cause is likely the dataskq chewing on the system logs with many entries.
- First ensure you're using the latest version of DirectAdmin
- check:
- if the brute_log_entries.list contiues to grow and you'd like it to keep itself smaller, go to:
Admin Level -> Admin Settings
and lower the value for:
Clear failed login attempts from log X days after entry was made.
to something around 2 days.
Also, increasing the values for:
Notify Admins after an IP has X login failures on any account.
Notify Admins after a User has X login failures from any IP.
will reduce the number of entries made into the brute_log_entries.list file.
1) Check:
/var/log/directadmin/system.log
to see if the tally is being run. If Users continue to be added to the log (the logs is doing something), then it's likely just the nightly tally, which is normal (assuming the log continues to grow and isn't just stuck on one User)
2) The first thing to do, is to simply ask the dataskq what it's up to. To do this, type:
killall -USR1 dataskq
tail -n 10 /var/log/directadmin/errortaskq.log
3) If the output makes reference to Maildir along with a path, then what it likely means is that the mentioned path contains an over-sized inbox. Check that inbox and delete the messages, if the email user doesn't seem to be deleting them.
4) If the output makes reference to brute_force or some related file, then the cause is likely the dataskq chewing on the system logs with many entries.
- First ensure you're using the latest version of DirectAdmin
- check:
cd /usr/local/directadmin/data/admin
ls -la brute_force*
- if the brute_log_entries.list contiues to grow and you'd like it to keep itself smaller, go to:
Admin Level -> Admin Settings
and lower the value for:
Clear failed login attempts from log X days after entry was made.
to something around 2 days.
Also, increasing the values for:
Notify Admins after an IP has X login failures on any account.
Notify Admins after a User has X login failures from any IP.
will reduce the number of entries made into the brute_log_entries.list file.
¤ÇÒÁ¤Ô´àËç¹·Ñé§ËÁ´
ÂѧäÁèÁÕ¤ÇÒÁ¤Ô´àËç¹ ÁÒÃèÇÁáÊ´§¤ÇÒÁ¤Ô´àËç¹à»ç¹¤¹ááÊÔ!