Hi there,
I have a problem, maybe security problem. I am pretty scared of it.
There are some activity between my NAS server and my laptop(or other pc). If am connected via sshfs there are work with drives on server.
I have tried to detect a core of problem. But, because I am not advanced unix user I have find out only basic info(please, see bellow). I don't know what next I have to try to find out. Could you help me please.
CLIENT
top
PHP Code:
PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
3605 root 20 0 99952 54m 604 S 6.3 2.7 0:24.65 sshfs
3592 root 20 0 5260 2360 1884 S 4.3 0.1 0:12.87 ssh
...
dstat
PHP Code:
top - 08:38:11 up 23 min, 3 users, load average: 0.01, 0.19, 0.31
Tasks: 126 total, 2 running, 124 sleeping, 0 stopped, 0 zombie
Cpu(s): 11.3%us, 7.3%sy, 0.7%ni, 75.7%id, 0.0%wa, 0.3%hi, 4.7%si, 0.0%st
Mem: 2074596k total, 1514064k used, 560532k free, 52056k buffers
Swap: 1951856k total, 0k used, 1951856k free, 640960k cached
usr sys idl wai hiq siq| read writ| recv send| in out | int csw
21 10 68 0 0 1| 0 0 | 201k 99k| 0 0 |1685 7264
13 10 75 1 0 1| 0 400k| 200k 83k| 0 0 |1473 6338
9 9 82 0 0 0| 0 0 | 170k 70k| 0 0 |1349 5428
38 13 48 0 0 1| 0 0 | 211k 109k| 0 0 |1861 7799
15 8 75 0 0 2| 0 0 | 217k 81k| 0 0 |1535 6814
40 10 48 0 1 1| 0 0 | 182k 99k| 0 0 |1713 7867
20 12 65 0 0 3| 0 408k| 209k 107k| 0 0 |1860 7773
8 7 83 0 0 2| 0 0 | 123k 84k| 0 0 |1448 5208
8 4 80 0 2 6| 0 0 | 128k 80k| 0 0 |1447 5050
9 3 84 0 2 2| 0 0 | 186k 51k| 0 0 |1141 5209
10 8 81 0 1 0| 0 0 | 246k 42k| 0 0 |1031 6144
12 10 78 0 0 0| 0 328k| 347k 83k| 0 0 |1624 9144
5 3 1 91 0 0|1320k 0 |3594B 478B| 0 0 | 490 1073
5 4 0 90 0 1|2080k 0 | 358B 70B| 0 0 | 458 916
4 1 0 94 0 1|1536k 0 | 476B 140B| 0 0 | 527 999
5 5 0 90 0 0|3232k 0 | 358B 70B| 0 0 | 675 1251
5 5 0 90 0 0|2416k 0 | 358B 70B| 0 0 | 620 1123
8 4 0 88 0 0|1448k 968k| 358B 70B| 0 0 | 462 966
4 6 0 90 0 0|2000k 176k| 358B 70B| 0 0 | 548 1153
7 3 0 90 0 0|1760k 0 | 358B 70B| 0 0 | 484 897
3 3 0 94 0 0|1824k 0 | 358B 70B| 0 0 | 468 970
9 2 0 89 0 0|1488k 0 | 358B 70B| 0 0 | 426 867
3 4 0 93 0 0|1368k 832k| 358B 70B| 0 0 | 459 927
3 3 0 94 0 0|1160k 0 | 358B 70B| 0 0 | 399 771
5 3 0 92 0 0|1160k 0 | 358B 70B| 0 0 | 443 984
4 3 0 93 0 0|1280k 0 | 358B 70B| 0 0 | 359 753
6 3 0 91 0 0|1024k 0 | 358B 70B| 0 0 | 426 836
5 4 0 91 0 0|1736k 504k| 358B 70B| 0 0 | 437 880
24 5 0 71 0 0|1696k 0 | 358B 70B| 0 0 | 574 1418
17 7 0 75 1 0|2064k 0 | 358B 70B| 0 0 | 862 2081
10 5 0 85 0 0|1532k 0 | 358B 70B| 0 0 | 480 1254
11 5 0 82 1 1|2996k 0 | 358B 70B| 0 0 | 711 1542
10 2 0 88 0 0|1512k 880k| 358B 70B| 0 0 | 449 923
8 4 0 88 0 0|2640k 56k| 358B 70B| 0 0 | 648 1186
10 6 0 84 0 0|3024k 0 | 358B 70B| 0 0 | 718 1333
9 4 0 87 0 0|1184k 0 | 358B 70B| 0 0 | 414 813
10 4 0 86 0 0|1936k 0 | 358B 70B| 0 0 | 550 1152
10 6 0 84 0 0|2488k 1328k| 236B 258B| 0 0 | 555 1115 ...the problem finish
4 4 0 90 2 0|2120k 0 | 0 0 | 0 0 | 570 1092
3 3 0 94 0 0|2040k 0 | 0 0 | 0 0 | 458 906
2 5 0 92 0 1|1944k 0 | 0 0 | 0 0 | 546 1034
17 5 0 78 0 0|2096k 0 | 0 0 | 0 0 | 541 1729
7 5 0 88 0 0|1872k 576k| 0 0 | 0 0 | 507 1149
10 4 0 86 0 0|1368k 0 | 0 0 | 0 0 | 478 1005
8 4 0 87 0 1|2128k 0 | 0 0 | 0 0 | 482 953
SERVER
top
PHP Code:
PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
11670 myuser R 1240 11669 29.3 0.9 sftp-server
11669 myuser S 1232 11665 17.5 0.9 sshd
3202 root S 2068 1 0.3 1.6 scemd
...
dstat
PHP Code:
----total-cpu-usage---- -dsk/total- -net/total- ---paging-- ---system--
usr sys idl wai hiq siq| read writ| recv send| in out | int csw
10 28 11 48 0 3| 636k 0 | 87k 206k| 0 0 |2490 5852
16 21 11 49 0 3| 612k 0 | 78k 206k| 0 0 |2282 5404
6 16 8 69 0 1| 472k 1016k| 69k 168k| 0 0 |1961 4621
16 25 27 31 0 1| 892k 0 | 134k 249k| 0 0 |3760 8641
12 22 16 48 0 2| 612k 0 | 75k 222k| 0 0 |2228 4865
9 18 5 65 0 3| 460k 0 | 53k 216k| 0 0 |1584 3527
14 20 8 58 0 0| 436k 0 | 53k 216k| 0 0 |1571 3576
12 12 15 59 0 2| 428k 1080k| 44k 154k| 0 0 |1362 3085
12 20 17 49 0 2| 552k 0 | 83k 188k| 0 0 |2247 5250
14 20 3 62 0 1| 552k 0 | 83k 174k| 0 0 |2258 5274
16 15 16 48 0 5| 612k 0 | 97k 201k| 0 0 |2610 5956
15 15 21 42 0 7| 608k 0 | 92k 185k| 0 0 |2522 5977
8 12 7 72 0 1| 436k 1016k| 51k 185k| 0 0 |1538 3386
12 19 3 62 0 4| 672k 16k| 101k 179k| 0 0 |2795 6554
12 15 24 45 0 4| 620k 0 | 88k 226k| 0 0 |2485 5666
8 17 27 45 0 3| 736k 0 | 98k 206k| 0 0 |2718 6220
8 19 10 62 0 1| 568k 0 | 89k 190k| 0 0 |2415 5564
10 27 6 54 0 3| 740k 896k| 123k 181k| 0 0 |3382 7970
4 11 4 77 0 4| 240k 6184k| 38k 59k| 0 0 |1391 2583
13 13 18 53 0 3| 612k 0 | 79k 199k| 0 0 |2345 5180
9 7 9 71 0 4| 440k 0 | 43k 153k| 0 0 |1421 3155
21 28 3 46 0 2| 708k 0 | 71k 390k| 0 0 |2198 4811
11 7 60 22 0 0| 264k 0 | 26k 114k| 0 0 | 936 2057
0 1 99 0 0 0| 0 1008k| 66B 354B| 0 0 | 120 29 ...the problem finish
1 2 97 0 0 0| 0 0 | 66B 354B| 0 0 | 102 18
0 1 99 0 0 0| 0 0 | 132B 468B| 0 0 | 104 20
0 1 99 0 0 0| 0 0 | 66B 354B| 0 0 | 102 62
0 1 99 0 0 0| 0 0 | 66B 354B| 0 0 | 102 18
...
lsof
it display work with my data directory, but I don't use this directory to view by no program.
I think something copies my data. But maybe I am paranoid.
--------------------------
client:
Debian 5.0.7(5.0.6), kernel 2.6.32-bpo.5-686 (2.6.26)
SSHFS version 2.1
FUSE library version: 2.7.4
fusermount version: 2.7.4
using FUSE kernel interface version 7.8
server:
kernel 2.6.24 (Synology)