LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 08-25-2002, 11:01 PM   #1
mr.moto
LQ Newbie
 
Registered: Dec 2001
Posts: 15

Rep: Reputation: 0
unexplained Mandrake 8.2 traffic


netstat shows some kind of root process ( ports 1024 and below )

connecting to a foreign address of 0.0.0.0:*

its a udp packet

it connects for a second then disconnects


the local address port number increases each connect up to 1024
( 0.0.0.0:782 ) ( 0.0.0.0:789 )

there shouldn't be any servers on this system


its a stand alone dial up connection

Mandrake 8.2

What the heck is this ?
 
Old 08-26-2002, 02:43 AM   #2
rohang
Member
 
Registered: Aug 2002
Location: Sydney, Australia
Distribution: Redhat, Open BSD, SuSe, Debian, CentOS
Posts: 177

Rep: Reputation: 31
Have you tried using lsof (list open files) and looking for something that seems out of the ordinary?
 
Old 08-26-2002, 03:55 AM   #3
KayJay
Member
 
Registered: Mar 2002
Location: dev/null
Distribution: redhat, mandrake
Posts: 218

Rep: Reputation: 30
0.0.0.0 means all ip's
port 1024 udp is a reserved port
so find out what service u have running that can connect to every address
 
Old 08-26-2002, 11:54 PM   #4
mr.moto
LQ Newbie
 
Registered: Dec 2001
Posts: 15

Original Poster
Rep: Reputation: 0
thanx for the info

So is this process just spewing packets out onto the internet ?

My mission should be to hunt it down and kill it ?


I hate when that happens.
 
Old 08-27-2002, 06:25 AM   #5
KayJay
Member
 
Registered: Mar 2002
Location: dev/null
Distribution: redhat, mandrake
Posts: 218

Rep: Reputation: 30
try iptraf or tcpdump to see where those packages are going to
tcpdump is in your distro.. iptraf can be downloaded
 
Old 08-27-2002, 01:29 PM   #6
manaskb
Member
 
Registered: Jan 2002
Location: India
Distribution: Suse , Mandrake
Posts: 121

Rep: Reputation: 15
Here are the things that you can do to locate the source of the traffic:
1. use nmap ( or nmapfe ) to see if you have any strange udp sockets open.
2. use ethereal ( like tcpdump but has a very nice gui) to see these packets. You can set capture filter in ethereal.
3. You said that the source port keeps changing, see this document http://www.iana.org/assignments/port-numbers , you may be able to identify the source application.

Lets see what step 1 and step 2 shows.
Thanks,
Manas
 
Old 08-27-2002, 01:58 PM   #7
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
netstat -anp gives you the usuall address stuff with the PID (-p) and the process name, then look up the PID with ps make sure the process name is correct, and there's yer culprit.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Unexplained Compiling Error SlackwareInAZ Slackware 11 06-01-2005 10:46 AM
Unexplained out of memory Issue hiddenbrain Linux - Hardware 4 05-19-2005 05:02 PM
unexplained c++ pointer behaviour vmp Programming 5 10-15-2004 02:04 AM
Unexplained Netconf error message in Mandrake 9.0 Starblade Linux - Networking 0 10-25-2003 05:26 PM
unexplained traffic jarod Linux - Security 3 08-11-2003 10:31 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 01:15 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration