Subject: Re: 1.5.x Sudden hangups on LX164.
To: None <port-alpha@netbsd.org>
From: der Mouse <mouse@Rodents.Montreal.QC.CA>
List: port-alpha
Date: 08/12/2002 22:50:00
> My alpha hangs from time to time, just super hangs, console, vga
> nothing works, has to hardreboot it through pressing the off button.

> Today i noticed something on the console though just before it hung.

> Aug 11 03:24:11 sonya inetd[794]: warning: can't verify hostname: gethostbyname2(h52-210-243-221.seed.net.tw, 2) failed
> Aug 11 03:24:11 sonya inetd[795]: warning: can't verify hostname: gethostbyname2(h52-210-243-221.seed.net.tw, 2) failed

> And then somthing like:

> Warning Processor return correct.. here it froze....

This sounds to me as though someone is trying to crack you from a
machine in Taiwan, but is probably throwing Intel shellcode at you,
which of course doesn't work.  And that this is collaborating with some
bug (software, hardware, I don't have enough information to even
speculate which) to lock up your machine.

It might be interesting to put a sniffer machine on its network
connection and capture a copy of the network traffic in question.
Identifying it may be hard, though.  Neither 52.210.243.221 nor
221.243.210.52 has a name, those being the two obvious addresses based
on the name in your logs; 52.210.243.221 is in duPont space and
unlikely to be returning a seed.net.tw name, whereas 221.243.210.52 is
in APNIC space but seems to have no further info; as near as I can tell
the whole /8 is assigned to APNIC.  TWNIC is not returning any response
and may even be off the air.  Traceroute to 221.243.210.52 dies as soon
as it hits routers that maintain a full routing table (instead of just
having a default route pointing upstream).

/~\ The ASCII				der Mouse
\ / Ribbon Campaign
 X  Against HTML	       mouse@rodents.montreal.qc.ca
/ \ Email!	     7D C8 61 52 5D E7 2D 39  4E F1 31 3E E8 B3 27 4B