Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Sat May 05, 2012 9:43 am 
Offline
Senior Newbie

Joined: Mon Jan 04, 2010 10:59 am
Posts: 6
Website: http://www.mikemartinelli.com
AOL: cpri50
Location: Bensalem PA
First - some quick details about my setup:

Ubuntu 8.04 (Latest Legacy (2.6.18.8-linode22))
Apache version 2.2.8
PHP version: 5.2.4-2ubuntu5.23
MySQL version: 5.0.51a
phpMyAdmin - 2.11.3deb1ubuntu1.3

Second - the full error:
ALERT - canary mismatch on efree() - heap overflow detected (attacker 'xx.xxx.xxx.xxx', file '................./template-functions.php', line 4570

Third - I've searched here which helped me enable logging to find the actual error and which pointed me to finding and trying a few things I will link to below...

Now on to the specific details of the issue...

I'm a Linux/web server NOOB so my friend helped me set everything up - and overall it was straightforward...been going great for several years now. I'm currently hosting 9 websites, several of which are my person sites.

So I was having this issue with my personal site where it wouldn't load. (Old version of the site was just a blank page - new version is just a "The connection was reset" error - more details on this below)

If I browse directly to an image - the image will load. I can also FTP and SSH in no problems...everything is there. Once I restart apache the site is fine again - nothing is lost and it was like nothing ever happened. When this happens, it only happens to my personal site...and ONLY to the "www" domain - all sub-domains always work fine (more on that later) No other sites on my server have this issue either. Several of them use the same CMS also. I've also checked server load when this happens via "screen" and nothing abnormal there either.

It's a fairly large site with tons of pics and vids and content so I just thought something was going wacky with the database or the CMS I was using. As such, I started to build a new site. I got everything going in a new sub-domain (dev). Latest version of the CMS, new database and everything. I didn't want to import any old content just in case something was screwy with the database.

Fast forward several weeks - I now have a working beta site that's completely designed and I am now loading content. It's a fully functional site though. Well, I get this issue with my main site (www) not loading once again. Now that I have a beta site I decide to see what's going on with that...well it loads fine. No issues. And again no issues with the other sites on the server either.

Again if I restart apache all is fine.

Fast forward to going live with the new version of my site. Everything goes well and I'm up and running in no time. The old site now resides under the "dev" sub-domain just in case I missed something or need to revert back for whatever reason. Again all is well. Fast forward again a month or so and now the NEW site isn't loading...this time the error is slightly different - it's a "The connection was reset" error compared to just a blank empty page like before. I can still browse to display an image and also a standard html page loads fine...

NOW, here's the strange thing...when I browse to the old site (that was originally giving me issues and now resides in the "dev" sub-directory) it loads perfectly fine! No issues. And once again all the other sites on the server load fine. I've since added another subdomain to my site for my wifes recipes and that loads fine too. And once again restarting apache gets the site back up instantly...

We've tried a few things like checking log files and stuff but nothing stands out. It's hard to determine exactly when it goes "down" but I usually check it several times a day just to make sure. It seems to be ONLY affecting the "www" area of my personal site...no other sub-domains within that domain are affected nor are any other sites on the server. I'm hoping someone with fresh eyes can help with this issue. My Virtual Host file for the problem site is the exact same as all the others - other than the site specific stuff of course. There is nothing special with this site that the other sites/sub-domains don't have either. Additionally, there are other sites that get much more traffic than my site so I can't imagine it's traffic related either. We've got the server locked down pretty good so I don't think it's a hack...as I said once I restart apache all is well - nothing is lost or weird after the restart...

Finally what I've tried already - as mentioned after searching here...

1st thing I tried was this:
"Decomment" the line "mssql.datetimeconvert = On" and change it to "mssql.datetimeconvert = Off"
https://bugs.php.net/bug.php?id=47877

2nd - I tried this when the above didn't work:
Put suhosin.session.encrypt=off to php.ini
http://www.suspekt.org/2008/10/12/suhos ... -detected/
Now, the above text was not in the php.ini file at all...I simply added it, saved and restarted Apache...was there a different method I should have followed?

Also, my php.ini file doesn't reside in /etc/php.ini. It's located at /etc/php5/apache2/php.ini. Not sure if this makes a difference or not but just thought I'd note it.

Again I'm fairly new at this stuff so bare with me - feel free to ask for more specs or questions...

Much appreciated,
Mike

_________________
Mike


Last edited by n20capri on Thu Jul 19, 2012 11:01 am, edited 1 time in total.

Top
   
 Post subject:
PostPosted: Mon May 14, 2012 8:23 am 
Offline
Senior Newbie

Joined: Mon Jan 04, 2010 10:59 am
Posts: 6
Website: http://www.mikemartinelli.com
AOL: cpri50
Location: Bensalem PA
This happened again over the weekend...anyone have any ideas?

Thanks

_________________
Mike


Top
   
 Post subject:
PostPosted: Mon May 14, 2012 9:05 am 
Offline
Senior Member
User avatar

Joined: Sat Feb 25, 2012 4:44 pm
Posts: 71
Website: http://inhomeitsupport.com
Have you update php there was a critical security update for php a few days ago.


Top
   
 Post subject:
PostPosted: Mon May 14, 2012 10:54 am 
Offline
Senior Newbie

Joined: Mon Jan 04, 2010 10:59 am
Posts: 6
Website: http://www.mikemartinelli.com
AOL: cpri50
Location: Bensalem PA
kyrunner wrote:
Have you update php there was a critical security update for php a few days ago.


No I hadn't heard about it...could my issue be related to this?

_________________
Mike


Top
   
PostPosted: Thu Jul 19, 2012 11:06 am 
Offline
Senior Newbie

Joined: Mon Jan 04, 2010 10:59 am
Posts: 6
Website: http://www.mikemartinelli.com
AOL: cpri50
Location: Bensalem PA
Any other opinions on this error? Still happening and driving me nuts...

I've recently tried (separately):
suhosin.session.encrypt=off
and
suhosin.simulation=true

and neither did anything...

As mentioned it's ONLY happening on the www domain of My site - no other sub-domains or other sites on the server...

Thanks,
Mike

_________________
Mike


Top
   
PostPosted: Wed May 01, 2013 2:16 pm 
Offline
Senior Newbie

Joined: Mon Jan 04, 2010 10:59 am
Posts: 6
Website: http://www.mikemartinelli.com
AOL: cpri50
Location: Bensalem PA
Anyone have any new insight on this issue? I've tried everything. Need it gone - it's killing my site!!

_________________
Mike


Top
   
PostPosted: Wed May 01, 2013 4:16 pm 
Offline
Senior Member
User avatar

Joined: Sun Dec 27, 2009 11:12 pm
Posts: 1038
Location: Colorado, USA
Your post is pretty fuzzy.

Have you updated to a NEW (as in EVERYTHING is current releases) system or not?

If not, who knows what those dinosaur versions are doing (or not).

_________________
Either provide enough details for people to help, or sit back and listen to the crickets chirp.
Security thru obscurity is a myth - and really really annoying.


Top
   
PostPosted: Wed May 01, 2013 4:37 pm 
Offline
Senior Newbie

Joined: Mon Jan 04, 2010 10:59 am
Posts: 6
Website: http://www.mikemartinelli.com
AOL: cpri50
Location: Bensalem PA
Everything was updated several weeks ago. Was hoping that would help but it didn't.

As mentioned its only ONE site out of all of them on my server. Driving me nuts.

_________________
Mike


Top
   
PostPosted: Wed May 01, 2013 5:23 pm 
Offline
Senior Member

Joined: Sun Mar 07, 2010 7:47 pm
Posts: 1970
Website: http://www.rwky.net
Location: Earth
Not particularly helpful on this particular issue but it might solve it. Ubuntu 8.04's support ends on the 9th of May so upgrading to 10.04 or 12.04 might solve your issue and keep your server secure. Also the kernel you're using is ancient.

_________________
Paid support
How to ask for help
1. Give details of your problem
2. Post any errors
3. Post relevant logs.
4. Don't hide details i.e. your domain, it just makes things harder
5. Be polite or you'll be eaten by a grue


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group