LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-30-2005, 10:59 PM   #1
msound
Member
 
Registered: Jun 2003
Location: SoCal
Distribution: CentOS
Posts: 465

Rep: Reputation: 30
misc port traffic


Whenever I check my router's logs during off hours (11pm - 4am), I still notice a lot of traffic coming in and going out on misc ports. My question is should be concerned about this or are they just harmless ICMP messages?

When I say misc ports I'm talking about numbers that ranges in the 3,000's, 4,000's, 5,000's, 30,000's, 40'000's, and 50,000's. I'm running a linux proxy/firewall between my router and lan so I could close off any unneeded ports.

Perhaps I should have done this already but so far I haven't noticed any malicous log in attempts on any of our servers (knocks on wood).

What do you all think? Should I close off all inbound and outbound traffic for all unused ports, and just keep the basics open like 25, 80, 110, 143, etc etc.

Obviously I will have to do some further configuration later on because services like windows update and symantec live update may stop working after I close off the ports. But correcting that should be a quick fix.

Holla back!
 
Old 10-01-2005, 09:54 AM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Could you post an example of some of the traffic by capturing some packets with tcpdump? Is the traffic originating from one host in particular or is it just random IPs?

If this is an internet-facing router, then it's going to see alot of garbage packets from portscans and virus infected windows machines. That's just the normal background that's on the internet. I'd be concerned if the traffic was coming from a single host or if they were able to establish a connection to a strange port.

Wrt to firewalling, I would definitely recommend filtering any un-solicited incomming traffic. Egress filtering is a good idea as well, but can be a bit more difficult to get working properly.
 
Old 10-03-2005, 08:02 AM   #3
MensaWater
LQ Guru
 
Registered: May 2005
Location: Atlanta Georgia USA
Distribution: Redhat (RHEL), CentOS, Fedora, CoreOS, Debian, FreeBSD, HP-UX, Solaris, SCO
Posts: 7,831
Blog Entries: 15

Rep: Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669
You can turn on iptables to allow ONLY the ports you want. If it is internet facing I would recommend doing that.

Short of that you can just disable unusued services (telnet, ftpd etc...) in you inetd or xinetd (depending on distro) configuration. This will prevent it from opening ports just for LISTENING that hackers try to exploit.

Also for specific ports you can run "lsof -i :<portno>" to find out which process is associated with the port (has to be done while the port is still active - not for historical use.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
monitor traffic per port and ip robca Linux - Networking 1 11-23-2005 01:47 PM
How can I block all traffic to port 110 to and IP using IPtables? abefroman Linux - Networking 8 11-16-2005 07:26 PM
route locally generated traffic to ip:port to localhost:port maenho Linux - Software 2 03-11-2005 04:08 AM
Traffic shaping (Prioritizing by port) Tyco Linux - Networking 5 02-11-2004 03:56 AM
Inbound traffic for port 80 Gerardoj Linux - Networking 10 05-29-2003 04:27 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:36 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration