9 ms·
You might want to stop running atop
- jaffa2 2y agoenigmatic? Anyone know why
- subract 2y agoNo clue personally, but the author is prolific enough here that I thought it merited posting.
- ggm 2y agoI go with three paths out. 1. it consumes too much systems resources. So its net-negative impact on the system under observation 2. it's misleading and leads to false diagnoses of situations under review 3. she's under an NDA of some kind related to a CVE or some other high class risk which will come out in due course but she felt a burden to stop people being exposed to risk. 4. I can't count and there are 4, 5, 6 other reasons but these 3 are mine.
- AnimalMuppet 2y agoI'll go with number 3. She didn't just say "don't run", she said "uninstall". That doesn't sound like "misleading" or "uses too much resources". It sounds very CVE-ish.
- arkx 2y agoAnother xz case?
- bee_rider 2y agoDoes atop have any legitimate need to connect to the network? I can’t think of any legitimate accidental security holes that might show up in something like atop, but then, these utilities often have funky features I don’t know about!
- _--__--__ 2y agoThat's what it smells like but this is still a weird way to disclose something like that. I imagine some people with free afternoons are taking a stab at auditing atop's PR history right now. I'm not personally up to the task, but the fact that the top 3 contributors other than the original author are ByteDance employees might cause some to jump to conclusions.
- phire 2y ago"uninstall" points at a very specific type of exploit.
- adrianmonk 2y agoAssuming it's actually necessary to uninstall. It might just be that "uninstall" is the simplest one-word advice you can give that will definitely solve the problem.
- deleted 2y ago[deleted]
- benmmurphy 2y ago1) is possible because it uses some interesting options like nice/mlockall/changing its oom score so if the atop process went out of control your box would probably be fucked.
- crimsonpowder 2y agoIf it was 1 or 2, there would be a long Rachel-style post ranting about it and explaining exactly why. It has to be 3. And she knows her stuff, so I'm listening. Luckily we don't use atop.
- thayne 2y agoBut if it was 3, why not say "I know there is a vulnerability, but I can't share the details"? I'm not saying it isn't 3, but if it is, it seems like there might be more to it than a run-of-the-mill CVE. Or maybe she doesn't know of a specific vulnerability/backdoor but has some reason to be suspicious there might be.
- desktopninja 2y ago[flagged]
- slicktux 2y agoOminous, I’ll heed the warning!
- jofzar 2y agoThis screams NDA/disclosure but things are so mega super fucked that they feel obligated to pre warn as early as possible. I wonder how long/old the problem is in atop?
- czk 2y agoSeems like the latest version might be as old as July 2024? https://www.atoptool.nl/allnews.php https://www.atoptool.nl/allnews.php For anyone interested, here are the latest commits to the GitHub: https://github.com/Atoptool/atop/commits/master/ https://github.com/Atoptool/atop/commits/master/
- jofzar 2y agoI have this weird gut feeling that it's going to be one of those "this was introduced in 2010 commit and has been in every build since" Edit: I have no knowledge of what this is FYI.
- DominoTree 2y agoSkimming through the code (particularly from past issues and PRs) highlights a number of things that look sketchy to me at first glance (in a coding practices way, not in a malicious way) - my gut feeling is that someone smarter than me going through much of this with a fine-toothed-comb would likely find something exploitable. Rewrite it in Rust. /s
- benterix 2y ago> my gut feeling is that someone smarter than me going through much of this with a fine-toothed-comb Seems that's already started: https://github.com/Atoptool/atop/issues/330 https://github.com/Atoptool/atop/issues/330
- plorkyeran 2y agoYeah, from a rando this would be just bad vagueposting but Rachel is absolutely someone who could know about a very good reason why we should uninstall atop but be unable to legally say why. I would heed her warning.
- alsetmusic 2y agoI’m actually surprised I didn’t have it installed, what with all the packages I check out just through sheer curiosity. Thanks Rachel! I’ll avoid it in the future.
- stavros 2y agoAlarmingly, I had it installed on my home server, for some odd reason. I don't remember ever using it.
- Hello71 2y agoI stopped using atop when I found it installs several hooks which automatically run code as root and deposit files around the filesystem, including a "power management" hook.
- lolinder 2y agoDo you have any references that describe this behavior? That sounds like exactly the kind of thing that could conceal a backdoor of the sort this seems to be warning about.
- Hello71 2y agohttps://github.com/Atoptool/atop/blob/77e658ea04f4901adf44c73cdd98bd4f0e664be0/atop-pm.sh https://github.com/Atoptool/atop/blob/77e658ea04f4901adf44c7... installed by default in most distributions, e.g. https://packages.debian.org/bookworm/amd64/atop/filelist https://packages.debian.org/bookworm/amd64/atop/filelist
- deleted 2y ago[deleted]
- dgacmu 2y agoThere's a lot of speculation about why, with the answer almost certainly security / exploitable (or backdoor), and I'll just throw an extra little tidbit in: atop seems to run persistently as root, which may be the reason for preventing it from running/uninstalling. the netatop part of atop installs a persistent kernel module, netatop.ko, as part of its installation. The module hooks netfilter to be able to monitor all traffic. If there's an exploitable flaw in the kernel module, this would be a max-severity CVE. netatop _also_ runs a persistent daemon, netatopd, which I believe from inspecting the source runs as root. The article's language about uninstalling it kinda sorta makes you think one of these three parts is in some way exploitable or backdoored -- any which way it's a privileged process, and one that's monitoring network traffic. (I'm not sure if netatop is installed by default on systems when you install atop, per czk's comment below)
- czk 2y agoI'm not familiar with atop but the website mentions netatop is optional and what I've found suggests you have to manually install it. Do you know if any distributions/packages install this by default alongside the atop install?
- dgacmu 2y agoThis is a good question - I'm not sure. The rpmspec doesn't seem to install it, so perhaps it's not quite that bad. The atop program _itself_ runs persistently, though, so, uh, still bad. :)
- deleted 2y ago[deleted]
- mappu 2y agonetatop is not in Debian, and the atop package doesn't include any .ko files.
- __turbobrew__ 2y agoI don’t think netatop is installed in Ubuntu packages either.
- geenat 2y agoProbably a backdoor. Repositories controlled by accounts based in mainland China and Russia are always a risk- it's too easy for a dictatorship to force something to happen even if the authors themselves are trying to act in good faith. XZ, Swoole... examples off the top of my head.
- lionkor 2y agoWhat about the fact that software is hosted on US/German/Australian/whatever else platforms and infrastructure, what's different with that, technically speaking? The fact that a majority of software we rely on is hosted on GitHub, isn't that scary the same way that a repo owned by someone in a other country is scary? Does a government need to openly act in a specific way for there to be a risk, or is this perceived risk due to a media bias? I'm genuinely curious if there's a good answer
- deleted 2y ago[deleted]
- geenat 2y agoGitHub has a lot to lose if it was leaked that they were knowingly facilitating backdoors behind the scenes- many pay for the convenience and trust. By the same standard, what are the repercussions for these random fly by night accounts? Just make a new account and try again on an existing project or fork / tweak / rebrand another project. Steam, VSCode, PyPI, NPM... it would ruin those platforms overnight if they were putting in backdoors themselves.
- lionkor 2y agoReputational loss isn't a good argument either, because what the comment I replied to said is that repositories in control of people in e.g. Russia are dangerous. That implies that a Russian or Chinese maintainer of popular open source software is not safe, whereas someone employed by an American company is. However, maintainers have a reputational loss risk, just like someone working at a company does, no? And, of course, GitHub could just replace the file you're served when you download a file from it, and then blame a hacker, a rogue employee, or deny it happened. That is just as well technically possible as any other entity being forced, by their government, to do something, no? And, of course, if a govt forces you, your reputation is not the thing you're worried about. I understand your argument, but that seems like it's a different argument from the one I was disagreeing with.
- bitbasher 2y agoPure speculation; but it sounds to me like she was doing some sysadmin triage and possibly stumbled onto a backdoor/exfiltration through atop. She likely can't disclose anything right now.
- nodesocket 2y agoExcept, she kinda did disclose already. Seems a bit strange to circumvent standard embargo practices, only to publicly hint of an exploit but not give any details.
- whazor 2y agoMaybe because it is a non-essential tool with many alternatives available? It could also be because there are already illicit parties using atop to hack companies? Still, publishing a CVE with the specific exploit and a recommendation to fully delete atop would be better. Even if there is no patch available.
- imoreno 2y agoLuckily I use a much better *top, btop.
- d3Xt3r 2y agoThis. Not only that, I don't know of a single person (IRL or online) who used atop, like, ever. In fact, this is the first time I'm even hearing of atop. IIRC, most folks went from top -> htop -> glances -> various btop variants (bashtop, bpytop, btop++ etc)
- SubiculumCode 2y agoBtop variants, glances, why should I move from htop?
- refulgentis 2y agoWhy should I move on from top? (serious question) I'm genuinely stunned to figure out there's a whole set of lore of *tops. I'm not sure I'm being rational from a textbook security perspective, but, it'd take a whole lot of tangible reward to get me off the binaries supplied with the system.
- do_not_redeem 2y agobtop gives you a more holistic overview of the system: individual disk stats, network stats, graphs of mem/cpu/bandwidth usage over time, etc. I think it's handy having everything on one screen, but if you know your way around all the individual builtin tools for these, more power to you, no reason to change.
- d3Xt3r 2y agoFirst of all, btop is included in the default repos of most Linux distros, so you don't need to worry about security. This also applies to htop and glances by the way. In terms of tangible feature benefits, btop also offers disk I/O stats, network throughput stats, partition usage, and even GPU usage (if your distro compiled it with GPU support). In terms of "nice" stuff that's non-essential, the overall UI is a lot more user-friendly and in many ways, better (subjectively). Eg there are visual graphs for various metrics, you can filter process names by substring, get detailed stats of a specific process, see the tree view of all the processes, easily show/hide various parts of the UI (eg you can focus solely on the process list if that's the only thing you're interested in). There are also some distinct advantages the UI offers easier to send specific signals to processes. Eg in btop I can just select SIGSTOP from the menu, whereas in top, I'd need to remember or lookup the numeric equivalent (eg 19 for SIGSTOP). Other top alternatives also offer similar feature sets. Glances also shows the most recent warning/errors from the system logs), as well as container resource usage which would be handy for some folks.
- keyle 2y agoIs atop included in any distributions? Is there even a tool to search what is pre-installed in each major distribution(s)?
- LinuxBender 2y ago"Ubuntu, Debian, Red Hat Enterprise Linux, Fedora, Linux Mint, SUSE Linux Enterprise, CentOS, Manjaro, elementary OS, Gentoo, Oracle Linux, and Pop!_OS" ~--Google's AI. I am not aware of any that install it by default.
- Macha 2y agoGoogle's AI has just given you a plausible sounding but mostly wrong list of distros - it's not in the enterprise distros, elementary or pop os
- LinuxBender 2y agoMissing from their output is an upvote and downvote button. Or a debug function that forces it to divulge where it obtained the data. Wait, now that I think about it why are there Fact Checkers for humans and not for AI?
- ndsipa_pomu 2y agoThat sounds like a lot of work, can't we get AI to do it for us?
- LinuxBender 2y agoYou jest but I think it can happen. Grok could be responsible for tagging the output of all the other AI's as "Potential Misinformation, Disinformation per the Ministry of Truth".
- Macha 2y agoThe data source seems pretty obvious here. It doesn't know much about atop, but your question has led it to believe that it's something available on Linux distros, so it spat out a likely list of Linux distros based on the weighted average of linux distros listed by other projects in its training set.
- xyst 2y ago[flagged]
- mvdtnz 2y agoNot everything is about American politics.
- nextts 2y agoIs there a mechanism where this sort of advice can flow through security teams to everyone (assuming it is about security) without dropping the details. How are zero days dealt with?
- TheDong 2y agoFor non-public zero-days on packages in linux/BSD distros - https://oss-security.openwall.org/wiki/mailing-lists/distros https://oss-security.openwall.org/wiki/mailing-lists/distros For public issues - https://oss-security.openwall.org/wiki/mailing-lists/oss-security https://oss-security.openwall.org/wiki/mailing-lists/oss-sec... For vague-posting about unconfirmed CVEs and zero days - twitter.com and/or mastodon and/or your friend on signal
- amiga386 2y ago[flagged]
- vanc_cefepime 2y agoLinux newbie here. Jumped into the Linux world after getting tired of Microsoft's BS with Win 11. Running Linux mint on my laptop and desktop. Looks like 'atop' is not installed by default, but regular 'top'. Anyone know which distros I should be worried about that have it? Also I have been dabbling with proxmox, I checked and looks like 'top' is the default there too.
- grayfaced 2y agoYou're probably not running either unless you know what they are. Top is an equivalent of windows taskmanager, most often to used identify "top" processes using memory/cpu (and other resources) and only ran briefly. Atop is a different long-running version used to create logs of the same data to understand trends.
- cesarb 2y ago> [...] and only ran briefly. Atop is a different long-running version used to create logs of the same data to understand trends. atop is also normally only ran briefly. It has an optional mode (enabled by default in some, but not all distributions) in which it runs as a service and saves a snapshot of the system state every few seconds; atop can read and show these snapshots when ran briefly.
- zertrin 2y agoSeems it's currently experiencing the HN hug of death (not responding for me), here's an archived version https://archive.is/MvNSk https://archive.is/MvNSk
- justinator 2y ago[flagged]
- justinator 2y ago[flagged]
- deleted 2y ago[deleted]
- teekert 2y agoI recently had a course from the author of atop. Seemed like a straight up FOSS friendly guy, I’ll forward him this page.
- LorenDB 2y agoFor openSUSE users: `sudo zypper al atop` will prevent atop from being installed for any reason, as long as it's uninstalled before you add the lock.
- rdtsc 2y agoIt's Rachel. If she says to remove it, I'll remove it. I see people are suspicious, but I think I'll trust someone like her at least once to do this.
- agnishom 2y agoI am out of the loop. Who is Rachel, and what are they famous for?
- rdtsc 2y agoShe is a known technology blogger https://rachelbythebay.com https://rachelbythebay.com, active for more than a decade. Her posts often make it to front page. I'd trust her enough to remove a non-essential component like atop basically.
- Niten 2y agoWhy should one trust her? What's her full name and the reason for deferring to her expertise? And yes I'm aware her posts have made it to the top of HN many times in the past. That I've seen, they've all been unhelpful vague-posts like this one. Maybe she's actually a real expert I should be listening to! But layer upon layer of vague "if you know, you know" do not make that case.
- SG- 2y agoturns out you can Google it.
- emmelaich 2y agoThere's a bunch of interesting recent commits from someone without a public signing key. Removed excess checks before free() Fixed possible wrong result bit shifting on 64bit after left op type overflow Fixed possible wrong result bit shifting on 64bit after left operand type overflow Fixed possible access out-of-bounds items array better check index before using Could be legit or flawed. Or even fixes for the possible flaw.
- wejick 2y agoSeems they also are not coming PR. Sus
- TheDong 2y agohttps://github.com/Atoptool/atop/pull/327 https://github.com/Atoptool/atop/pull/327 and https://github.com/Atoptool/atop/pull/325 https://github.com/Atoptool/atop/pull/325 are the PRs with those commits. Come on.
- TheDong 2y ago1. Unsigned commits is the norm. It's weird to sign git commits. It's weird to upload your gpg key to github. gpg is a nightmare mess. 2. They aren't introducing the bug, those are all unreleased commits, so advice to "uninstall now" for something no distros are shipping would be silly. 3. The diff is trivial, you can read it and figure out if it looks like they're fixing a real exploitable thing. The answer is obviously no.
- twobiers 2y ago> It's weird to upload your gpg key to github. gpg is a nightmare mess. I agree on that, but note that you're also able to use your existing SSH key for signing commits. https://docs.github.com/en/authentication/managing-commit-signature-verification/telling-git-about-your-signing-key#telling-git-about-your-ssh-key https://docs.github.com/en/authentication/managing-commit-si...
- spudlyo 2y agoAt a previous gig, atop was running fleet-wide (> 1k servers) as sort of a resource monitoring tool of last resort, in a similar way as is described in this article[0]. I left a few years ago, but if memory serves, this thing was baked into base-image Puppet configs, and proved itself handy in past investigations of hard-to-find problems. If this turns to be real threat, I wouldn't be surprised if the blast radius for this is substantial. [0]: https://www.bodhost.com/kb/how-to-monitor-system-resource-usage-over-a-specified-time-using-atop/ https://www.bodhost.com/kb/how-to-monitor-system-resource-us...
- AlexClickHouse 2y agoI vaguely remember an old bug in atop, leading to a very unusual consequence. Atop will do an invalid memory write and crash with a segfault. But this writing is performed on a memory page mapped to a hardware timer. Despite not being able to write into that page, just touching it somehow changes how this hardware timer works. Then, the OS detects that this timer is inaccurate and switches to a different clock source (which you can see in /sys/devices/system/clocksource/clocksource0/current_clocksource). As a result, every call to clock_gettime becomes slower, and the system becomes slower as a whole until it restarts. In short, a segfault in atop leads to the whole system's performance degradation. But this was found around maybe 7 years ago.
- devoopsies 2y agoThis was found by the very same Rachel that's sounding the alarm here https://rachelbythebay.com/w/2014/03/02/sync/ https://rachelbythebay.com/w/2014/03/02/sync/
- anitil 2y agoThat is such an interesting bug!
- deleted 2y ago[deleted]
- TheDong 2y agoNo one else seems to have run 'grep system(', so I will: https://github.com/Atoptool/atop/blob/037a6d3e4ace6c7be6c5dcf0c286c013e3c884cc/rawlog.c#L554-L556 https://github.com/Atoptool/atop/blob/037a6d3e4ace6c7be6c5dc... > system ("gunzip -c %s > %s", tmpname1, tmpname2") tmpname2 is hardcoded as "/tmp/atopwrkXXXXXX", so that's fine. tmpname1 is '$irawname.gz'. '$irawname' is set by the '-r' flag. So, presumably if you can get the rest of the code to play nice and get you there, you can escalate from having shell access to run atop, to having shell access. Oh, I guess that's nothing. Anyway, still a really bad use of system + user-controlled input, don't do that.
- isotopp 2y agoEh? Calling system() for a binary without a path? And why system() using execl() in the first place, when you could do something using execve() without a sh inbetween instead? Even w/o an exploit this can be prettier and more secure.
- TheDong 2y agoWe're not disagreeing. Even if there's no 'sploit there, people have spaces in their directory or file names, and it's kinda nice for your tool to work with those, so obviously you should be using an execve variant to pass arguments properly. I assume the reason for the incorrect system call is that doing a shell redirect ('>') does actually look prettier though. Doing the actual right code is definitely less pretty looking IMO: https://github.com/luvit/zlib/blob/8de57bce969eb9dafc1f1f5c256ac608d0a73ec4/examples/zpipe.c#L92-L148 https://github.com/luvit/zlib/blob/8de57bce969eb9dafc1f1f5c2...
- lnxdork 2y agoAgree as a basic example. tmpname1 = "/tmp/file.txt; rm -rf /"; becomes gunzip -c /tmp/file.txt; rm -rf / > /tmp/atopwrkXXXXXX Also tmpname2 could be symlinked to /etc/passwd before it is unlinked..
- TheDong 2y ago> Also tmpname2 could be symlinked to /etc/passwd before it is unlinked.. Yeah, sure, but only if you run atop as root, otherwise it'll just get a "permission denied", and if you can run atop as root with whatever flags you like, you might as well just run 'rm' instead. It's not a suid binary, so while it's bad code and a smell, I don't think the TOCTOU is a security issue in how it's commonly run (i.e. as an interactive CLI running as your user).
- crmrc114 2y agoWell that ansible job was quickly ran, buhbye atop. Very concerning coming from Rachel and not some rando. I know a number of fortune 5's that use atop for troubleshooting as well. So as others have commented if you had this baked into images or loaded with puppet etc than now may be the time to cleanup.
- iJohnDoe 2y agoVery simple. From a state level, if they are trying to compromise a system, get persistent access, already have access, but need to escalate, then atop is a solution if it's already on the system. Just like Notepad++ back in the day.
- hanche 2y agoRachel has posted a follow-up: https://rachelbythebay.com/w/2025/03/26/atop/ https://rachelbythebay.com/w/2025/03/26/atop/ > user1 does something... and gets user2 to blow up. If you can make that do something useful, then you get user2 to run stuff on your behalf.
- Cyphase 2y agohttps://news.ycombinator.com/item?id=43485980 https://news.ycombinator.com/item?id=43485980
- spyc 2y agoIf anyone wonders what atop looks like at runtime or what it would be useful for, there's a video dedicated to the tool at https://www.youtube.com/watch?v=27AtCR5ftyM https://www.youtube.com/watch?v=27AtCR5ftyM .