Code:
(johan@server)-(~) $ lsmod
Module Size Used by
That's all I get from lsmod. :/ Doesn't matter if I sudo lsmod either, still no real output.
Code:
(johan@server)-(~) $ sudo modprobe xt_NFQUEUE
FATAL: Module xt_NFQUEUE not found.
(johan@server)-(~) $ echo $?
1
Code:
(johan@server)-(~) $ ls /boot/config-"$(uname -r)"
ls: cannot access /boot/config-2.6.32.8: No such file or directory
This seemed quite strange.. I don't have a configuration file? Here are the contents of /boot:
Code:
(johan@server)-(~) $ cd /boot
(johan@server)-(/boot) $ ls -a
. .. System.map boot.0800 bzImage coffee.bmp debian.bmp debianlilo.bmp map sarge.bmp sid.bmp
Could it be RKhunter that hides it for some reason?
The path /lib/modules/2.6.32.8/kernel/ contains only one folder; /lib/modules/2.6.32.8/kernel/drivers. The only thing in that folder is another folder named "scsi", which contains the file "scsi_wait_scan.ko". It corresponds to writing the following:
Code:
(johan@server)-(/lib/modules/2.6.32.8/kernel/drivers/scsi) $ modprobe -ls
kernel/drivers/scsi/scsi_wait_scan.ko
It sure looks like I have only one (1) kernel module. A module that doesn't seem to be loaded.
Here's what I get in blockcontrol.log, repeating itself every 5 minutes:
Code:
2010-03-29 14:45:14 CEST Begin: blockcontrol restart
Stopping blockcontrol.wd ...done.
Deleting iptables ...
...done.
Stopping moblock ... ...done.
Inserting iptables ...
Allowing outbound traffic to DNS server XXX.XXX.XX.X ...done.
Allowing forwarded traffic to DNS server XXX.XXX.XX.X ...done.
Allowing outbound traffic to DNS server YYY.YYY.YY.Y ...done.
Allowing forwarded traffic to DNS server YYY.YYY.YY.Y ...done.
Allowing loopback traffic ...done.
...done.
Starting moblock ... ...done.
Starting blockcontrol.wd ... ...done.
2010-03-29 14:45:14 CEST End: blockcontrol restart
Like I said, exactly 5 minutes later, it does a new blockcontrol restart (2010-03-29 14:50:14 CEST Begin: blockcontrol restart).
Anyway, I guess the real problem is the (lack of) kernel modules and config. Does that mean my iptables are ignored by the kernel as well?
Bookmarks