Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st.
We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here.
Need help or have questions? Drop us a line at [email protected]
Created 05-22-2024 12:09 AM
Hello Community,
I have an old CDH6 and realized the following suspicious traces in cloudera.flood.log in /var/log/cloudera-scm-server
and the same for another almost 100 different IPs outside the network by using the p2p libraries (and not sure that they are Cloudera Repository Ps)
Did you see anything similar? this activity is quite suspicious.
Thanks for your help
Created 05-24-2024 02:53 AM
The dht_pkt_alert messages you’re seeing in the cloudera.flood.log are indicative of Distributed Hash Table (DHT) packet alerts, which are associated with peer-to-peer (P2P) network activity. This type of activity is unusual for a Cloudera CDH6 environment and could potentially point to a security concern, such as unauthorized software or a compromised system.
Created 05-24-2024 02:53 AM
The dht_pkt_alert messages you’re seeing in the cloudera.flood.log are indicative of Distributed Hash Table (DHT) packet alerts, which are associated with peer-to-peer (P2P) network activity. This type of activity is unusual for a Cloudera CDH6 environment and could potentially point to a security concern, such as unauthorized software or a compromised system.
Created 05-27-2024 12:28 AM
Thank you @robert199re for the information, the system is isolated, I would do some additional investigations but not I can asume that this traffic is not usual for CDH6.
Best Regards