Avatar of sunhux
sunhux
 asked on

Trendmicro's Interscan proxy out of memory

Refer to attached  TrendMicro's  Interscan proxy VM (a custom Linux)
that shows spurious memory shortage.

Have allocated 32GB to the VM & with only 2 users accessing, already
getting these memory messages : plan to roll out to 500 users.


What can be done to address this?  Increase swap space or RAM?
Or there's something to tune?  Hopefully don't have to switch to
another type of proxy.

As this is a bundled free product, quite difficult to get support.

Btw, what's the default root password when it's first set up?
TMproxyoutofMem.png
LinuxLinux SecurityOS SecurityLinux OS Dev

Avatar of undefined
Last Comment
sunhux

8/22/2022 - Mon
Mal Osborne

Check the scan settings, you might be being hit by "Zip bombs".

This is when a recursive compressed file with a heap more compressed files inside of it is sent via email. It is pretty simple to craft for instance a 1Mb attachment that contains a terabyte of data, once uncompressed. Some scanners will attempt to open up such an archive, usually running into RAM or hard drive resource. There are usually therefore setting to just block incoming files that have a ridiculous compression ratio, or a stupid amount of data.

Zip bombs were more prevalent a few decades ago, but could still be around.

More here: https://en.wikipedia.org/wiki/Zip_bomb
ASKER CERTIFIED SOLUTION
Dr. Klahn

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
sunhux

ASKER
Have not sent any zip through the proxy yet so far : it's a newly set up VM.

to run 'top', I'll first need to know the Linux root password: logging case with Trendmicro but it's taking a while
SOLUTION
David Favor

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
sunhux

ASKER
Guessed the root password right & got in : found that it's due to the "low power"
triggering it:  we ordered the server hardware but it took a month longer than
expected to arrive so we installed this proxy on a PC with 32GB RAM.

The "low power" UPS issue was fixed & my colleague reported this fixed it.
Your help has saved me hundreds of hours of internet surfing.
fblack61
sunhux

ASKER
correction: had to disable  Power Savings  feature on the PC