Networking Forums

Networking Forums > Computer Networking > Linux Networking > Ports "suddenly" open

Reply
Thread Tools Display Modes

Ports "suddenly" open

 
 
j.sun.
Guest
Posts: n/a

 
      09-15-2003, 05:38 PM
Hey all,

I setup a new linux box last winter/spring running redhat 9. I scan it with
namp from time to time to make sure no one hacked in and opened any ports.
Today I scanned it remotely which showed four new ports open that were never
open before and that I never configured to be open:

135/tcp filtered loc-srv
137/tcp filtered netbios-ns
139/tcp filtered netbios-ssn
4444/tcp filtered krb524

Samba isn't running so I have no idea why 135, 137 and 139 are open. I
haven't found any traces of anyone breaking in (I try to keep it as secure
as possible), though, of course, that doesn't mean no one did break in. I
don't know what's going on with port 4444, either. I don't know if these
ports were opened after running up2date at some point or what. Does anyone
have any ideas as to what steps to take from here?

Thanks,
Jason


 
Reply With Quote
 
 
 
 
/dev/rob0
Guest
Posts: n/a

 
      09-15-2003, 06:09 PM
In article <lZ-dnQiizN0iZPiiRVn-(E-Mail Removed)>, j.sun. wrote:
> Today I scanned it remotely which showed four new ports open that were never
> open before and that I never configured to be open:
>
> 135/tcp filtered loc-srv


"filtered" != "open"

> have any ideas as to what steps to take from here?


Ask your ISP why they are blocking these ports. Well, I know the answer
to that: they're protecting Windows people from the Blaster worm, and
thereby keeping the complaints at their abuse@ address to a minimum.
--
/dev/rob0 - preferred_email=i$((28*28+28))@softhome.net
or put "not-spam" or "/dev/rob0" in Subject header to reply
 
Reply With Quote
 
Jan Geertsma
Guest
Posts: n/a

 
      09-15-2003, 09:19 PM
I really like and promote rob0's anti-spam-thingy ... It's cute!

and to say something productive, try to telnet to these ports, if you get a
prompt that means that you CAN actually connect, otherwise you are in the
clear.

Puppywhacker.

"/dev/rob0" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> In article <lZ-dnQiizN0iZPiiRVn-(E-Mail Removed)>, j.sun. wrote:
> > Today I scanned it remotely which showed four new ports open that were

never
> > open before and that I never configured to be open:
> >
> > 135/tcp filtered loc-srv

>
> "filtered" != "open"
>
> > have any ideas as to what steps to take from here?

>
> Ask your ISP why they are blocking these ports. Well, I know the answer
> to that: they're protecting Windows people from the Blaster worm, and
> thereby keeping the complaints at their abuse@ address to a minimum.
> --
> /dev/rob0 - preferred_email=i$((28*28+28))@softhome.net
> or put "not-spam" or "/dev/rob0" in Subject header to reply



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Sending a "ping": Which (ICMP) ports must be open in firewall to receive answer ? Peter Waibel Linux Networking 2 03-29-2007 05:49 PM
[Fwd: SPEWS DOLTS "SneakyP", "Kevin!:?)", "WindsorFox" SPAM braodbandnewsgroup] !:?) Broadband 0 11-30-2005 01:04 AM
Re: SPEWS SLIMES "WindsorFox", "Kevin-!:?)", "Spin Dryer" get the cold shoulder at broadband ng! SneakyP Broadband 0 11-29-2005 10:46 PM
Attention Plus.net Re: SPEWS DOLTS "WindsorFox", "Kevin-!:?)", "SpinDryer" SPAM broadband newsgroup !:?) Broadband 0 11-28-2005 04:28 AM
Attention Plus.Net Re: SPEWS DOLTS "WindsorFox", "Kevin-!:?)", "SpinDryer" SPAM braodband newsgroup !:?) Broadband 0 11-28-2005 03:03 AM



1 2 3 4 5 6 7 8 9 10 11