public inbox for cygwin@cygwin.com
 help / color / mirror / Atom feed
* Re: sshd buildup of CLOSE_WAIT leading to unable to function
@ 2014-04-11 16:08 Joshua Hudson
  2014-04-12 11:31 ` Corinna Vinschen
  0 siblings, 1 reply; 6+ messages in thread
From: Joshua Hudson @ 2014-04-11 16:08 UTC (permalink / raw)
  To: cygwin

The interesting detail is it would always stop at exactly 64 sockets
open; which is the maximum number for which select() doesn't have to
spawn a second thread.

Problem disappeared. Given the traces I got the reproduction would
involve somebody's deranged trojan SSH scanner.

64 to too low for Fail2Ban to prevent disaster so I didn't bother. The
fools aren't getting in anyway. I turned off password auth.

--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

^ permalink raw reply	[flat|nested] 6+ messages in thread
* sshd buildup of CLOSE_WAIT leading to unable to function
@ 2014-04-01 20:38 Joshua Hudson
  2014-04-02  8:55 ` Corinna Vinschen
  2014-04-08 16:06 ` Joshua Hudson
  0 siblings, 2 replies; 6+ messages in thread
From: Joshua Hudson @ 2014-04-01 20:38 UTC (permalink / raw)
  To: cygwin

Hi. I'm getting a situation on one machine where sshd will fail to
accept connections in a way that says "connection refused" even though
it is listening. The server shows a large (58) number of connections
in CLOSE_WAIT.

A Google search leads me to
http://www.cygwin.com/ml/cygwin/2010-01/msg01235.html
and eventually to
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q198663
but I don't think that's right. Somebody else managed to this this in 2009
http://www.44342.com/ssh-f1158-t3789-p1.htm


Version:

OpenSSH_6.4p1, OpenSSL 1.0.1e 11 Feb 2013
CYGWIN_NT-6.1 redacted 1.7.25(0.270/5/3) 2013-08-31 20:37 x86_64 Cygwin

--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2014-04-12 11:31 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2014-04-11 16:08 sshd buildup of CLOSE_WAIT leading to unable to function Joshua Hudson
2014-04-12 11:31 ` Corinna Vinschen
  -- strict thread matches above, loose matches on Subject: below --
2014-04-01 20:38 Joshua Hudson
2014-04-02  8:55 ` Corinna Vinschen
2014-04-08 16:06 ` Joshua Hudson
2014-04-08 17:51   ` Corinna Vinschen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).