NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

AGILIT's avatar
AGILIT
Aspirant
Nov 15, 2015
Solved

System volume 'root' usage is 100 % and system is now inactive

My RN102 started to become unresponsive.  I went to the logs and found the dreaded 'System volume 'root' usage is 100%' message and noticed that it had been occurring with increasing frequency.  At t...
  • AGILIT's avatar
    Nov 15, 2015

    OK: looks Iike I was able to fix it.

     

    Further research showed that the btmp records failed attempts to login to the system.  I ran the command

     

    last -f /var/log/btmp

    and got a stream of messages like this:


    root     ssh:notty    43.229.53.59     Tue Oct 20 00:34 - 00:34  (00:00)
    root     ssh:notty    43.229.53.59     Tue Oct 20 00:34 - 00:34  (00:00)
    root     ssh:notty    43.229.53.59     Tue Oct 20 00:34 - 00:34  (00:00)
    root     ssh:notty    43.229.53.59     Tue Oct 20 00:34 - 00:34  (00:00)
    root     ssh:notty    43.229.53.59     Tue Oct 20 00:34 - 00:34  (00:00)
    root     ssh:notty    43.229.53.59     Tue Oct 20 00:34 - 00:34  (00:00)
    root     ssh:notty    43.229.53.59     Tue Oct 20 00:34 - 00:34  (00:00)
    root     ssh:notty    43.229.53.59     Tue Oct 20 00:34 - 00:34  (00:00)
    root     ssh:notty    43.229.53.59     Tue Oct 20 00:34 - 00:34  (00:00)
    root     ssh:notty    43.229.53.59     Tue Oct 20 00:34 - 00:34  (00:00)
    root     ssh:notty    43.229.53.59     Tue Oct 20 00:34 - 00:34  (00:00

     

    So it looks like someone was trying to brute force connect to my system.

     

    I ran the command:

    sudo > /var/log/btmp

    and that cleared it out.  I have access to my system now.

     

    Now the challenge will be to figure out how to better protect my system.  Maybe I'll just turn off remote access.

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More