LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-17-2003, 02:23 PM   #1
MadCactus
Member
 
Registered: Jul 2003
Distribution: Slackware 9.1
Posts: 195

Rep: Reputation: 30
Any known nastiness with these ports?


I've noticed the following hits on my firewall, is there a perfectly good explanation for why these packets are finding their way to my PC, or are there exploits/hacks associated with them? I've omitted the countless hits on ports 135, 137, and 445 (MS.Blaster - shouldn't my ISP be blocking these?)

And also, wtf is SOCKS and AFT? Sounds a bit dodgy to me...

218.187.136.162 DPT=25 TCP - SMTP (my ISP doesn't supply an SMTP server...)
139.142.95.243 DPT=1433 TCP - Microsoft-SQL-Server.
218.2.141.142 DPT=445 TCP - Microsoft-DS
172.148.42.247 DPT=1080 TCP - SOCKS (Authenticated Firewall Traversal)
61.232.23.227 DPT=1434 UDP - Microsoft-SQL-Monitor
68.200.92.119 DPT=17300 TCP - ?

cheers
M
 
Old 08-17-2003, 02:35 PM   #2
yocompia
Member
 
Registered: Apr 2003
Location: Chicago, IL
Distribution: openbsd 3.6, slackware 10.0
Posts: 244

Rep: Reputation: 30
about the broadcasts on port 137, this is in the range for microsoft networks (135:139) and this usually sends UDP packets. that port is "defaulted" to the netbios name service, which might have to do w/ the microsoft network stuff. that's all i've got.

gl,
y-p
 
Old 08-17-2003, 02:39 PM   #3
MadCactus
Member
 
Registered: Jul 2003
Distribution: Slackware 9.1
Posts: 195

Original Poster
Rep: Reputation: 30
Any known nastiness with these ports?

I've noticed the following hits on my firewall, is there a perfectly good explanation for why these packets are finding their way to my PC, or are there exploits/hacks associated with them? I've omitted the countless hits on ports 135, 137, and 445 (MS.Blaster - shouldn't my ISP be blocking these?)

And also, wtf is SOCKS and AFT? Sounds a bit dodgy to me...

218.187.136.162 DPT=25 TCP - SMTP (my ISP doesn't supply an SMTP server...)
139.142.95.243 DPT=1433 TCP - Microsoft-SQL-Server.
218.2.141.142 DPT=445 TCP - Microsoft-DS
172.148.42.247 DPT=1080 TCP - SOCKS (Authenticated Firewall Traversal)
61.232.23.227 DPT=1434 UDP - Microsoft-SQL-Monitor
68.200.92.119 DPT=17300 TCP - ?

cheers
M
 
Old 08-17-2003, 02:45 PM   #4
2damncommon
Senior Member
 
Registered: Feb 2003
Location: Calif, USA
Distribution: PCLINUXOS
Posts: 2,918

Rep: Reputation: 103Reputation: 103
If you are on a dynamic IP it is possible that some of the hits could be an error in attempting to reach the PC that previously had that IP.
That said, someone attempted to connect to the mail server on your computer, and most the others are M$ vulnerabilities. I am not sure what the SOCKS thing is but I see it often also.
 
Old 08-17-2003, 02:52 PM   #5
Mathieu
Senior Member
 
Registered: Feb 2001
Location: Montreal, Quebec, Canada
Distribution: RedHat, Fedora, CentOS, SUSE
Posts: 1,403

Rep: Reputation: 46
Quote:
445 (MS.Blaster - shouldn't my ISP be blocking these?)
No, because windows 2000/2003/XP use port 445 for SMB.
Your ISP will never block any ports.

Ports 135, 137 and 139, these are NETBIOS ports.
Again, windows ports.

As for the other ports, if you get many hits, it is possible someone (or some worm) is trying to connect.
There are a few worms that attack Microsoft's SQL server.

Again windows.

Setup your firewall to block external connections to these ports,
and have faith in Linux.
 
Old 08-17-2003, 03:07 PM   #6
Mathieu
Senior Member
 
Registered: Feb 2001
Location: Montreal, Quebec, Canada
Distribution: RedHat, Fedora, CentOS, SUSE
Posts: 1,403

Rep: Reputation: 46
Double Post.
http://www.linuxquestions.org/questi...threadid=82880
 
Old 08-17-2003, 04:23 PM   #7
yocompia
Member
 
Registered: Apr 2003
Location: Chicago, IL
Distribution: openbsd 3.6, slackware 10.0
Posts: 244

Rep: Reputation: 30
bizzzzaaaaaaaaarrrrre
 
Old 08-17-2003, 05:22 PM   #8
tobyl
Member
 
Registered: Apr 2003
Location: uk
Distribution: slackware current
Posts: 768

Rep: Reputation: 64
I was getting several hits on 17300 as well, so I looked it up.
It is the backdoor for the kuang2 trojan.
Affects W95 & W98
Bored kids I guess.
 
Old 08-17-2003, 06:27 PM   #9
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
//moderator.note: merged threads w/o mercy. Don't double-post. Watch your triggerfinger.

Btw, since it's clear by now "the rest" is targetted at MICROS~1 boxen, the only thing you need to worry about is your MTA. If you don't do POP3/IMAP elsewhere and you need to *receive* mail directly, make sure you've taken the right precautions to harden the MTA. If OTOH you need to only *send* email, then disable your MTA, cuz running the daemon then aint necessary.
 
Old 08-22-2003, 04:54 PM   #10
MadCactus
Member
 
Registered: Jul 2003
Distribution: Slackware 9.1
Posts: 195

Original Poster
Rep: Reputation: 30
Oops begging your pardon for the dp - all those MS worms are eating my bandwidth!

All those packets are dropped and I don't use POP3/IMAP/SMTP at all. Was just curious - thanks for the tips.

I can sleep safely now
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Cannot Open Mail Server Ports 25, 110, and 220. Other Ports will open. Binxter Linux - Newbie 9 11-29-2007 02:03 AM
need help with ports alagenchev Linux - Security 5 10-22-2005 07:29 PM
Ports...how-to.. hlinux SUSE / openSUSE 1 03-19-2005 09:05 AM
help mi ports alek66 Linux - Hardware 1 07-24-2004 05:14 PM
Nvidia XFree86 Driver Nastiness ingy866 Linux - Hardware 2 03-05-2003 09:43 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:42 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration