LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-18-2010, 02:27 PM   #1
thelord23
LQ Newbie
 
Registered: Nov 2010
Posts: 2

Rep: Reputation: 0
nmap retuns many non existing local ip -- hacked?


Hi!

A scan on my computer reported as up many local ips which simply does not exist in my network. This host is supposed to have ip 192.168.0.4, but all other ip should not be there... I have a USB modem connected to a Linux box, connected itselfs to a wifi linksys router and thats it...

# nmap -sP '192.168.*.*' | grep -v down
Starting nmap 3.81 ( http://www.insecure.org/nmap/ ) at 2010-11-18 21:46 CET
Host 192.168.0.4 appears to be up.
Host 192.168.7.27 appears to be up.
Host 192.168.10.0 appears to be up.
Host 192.168.10.1 appears to be up.
Host 192.168.10.31 appears to be up.
Host 192.168.11.192 appears to be up.
Host 192.168.11.193 appears to be up.
Host 192.168.11.223 appears to be up.
Host 192.168.11.224 appears to be up.
Host 192.168.11.225 appears to be up.
...

And several run of this command does not produce exactly the same output (some ips appear, some others disapear...)

More surprisingly, a traceroute to any of these IP hops out of my box:

# traceroute 192.168.159.28
traceroute to 192.168.159.28 (192.168.159.28), 30 hops max, 38 byte packets
1 xxxxx.fr (x.x.x.x) 59.428 ms 168.240 ms 76.222 ms
2 x.x.x.x (x.x.x.x) 47.865 ms 52.671 ms 103.895 ms
3 xxxxx.francetelecom.net (x.x.x.x) 46.882 ms 48.879 ms 46.961 ms
4 xxxxx.francetelecom.net (x.x.x.x) 181.731 ms 51.690 ms 46.856 ms
5 xxxxx.francetelecom.net (193.252.161.106) 57.016 ms 60.682 ms 54.889 ms
6 xxxxx.francetelecom.net (81.253.129.97) 60.832 ms 52.676 ms 56.877 ms
7 xe-4-0-0-0.ncidf201.Aubervilliers.francetelecom.net (193.252.98.193) 56.916 ms 84.664 ms 56.884 ms
8 gi3-2.nafti103.Aubervilliers.francetelecom.net (193.252.98.241) 59.925 ms 61.623 ms 58.824 ms
9 * * *
10 * * *
...


I guess somebody hacked my box, but I really want to understand this topic better. If you need any additional information, just tell me...
 
Old 11-18-2010, 02:54 PM   #2
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
I'm not sure on this but it almost appears that you may seeing other nodes that use the same ISP you do. I noticed something similar 8 years ago when I was using Adelphia as an ISP. I'm not sure how to validate that, though. I seriously doubt that whole range consists of your LAN. After you run that nmap scan, can you check your ARP table? It may show some host names or MAC addresses that may contain some hint as to what's going on. I'm almost positive it isn't a security issue, though.
 
Old 11-18-2010, 04:33 PM   #3
thelord23
LQ Newbie
 
Registered: Nov 2010
Posts: 2

Original Poster
Rep: Reputation: 0
Thank you for your fast and positive answer

This is the result of the command arp:

# arp -vn
Entries: 0 Skipped: 0 Found: 0

Everything is fine?
 
Old 11-19-2010, 01:49 PM   #4
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
Quote:
Originally Posted by thelord23 View Post
Thank you for your fast and positive answer

This is the result of the command arp:

# arp -vn
Entries: 0 Skipped: 0 Found: 0

Everything is fine?
Yeah, it looks to be that everything is fine. Continue to watch though, just in case.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Modifying Existing Local Zone File Systems On Solaris 10 Unix LXer Syndicated Linux News 0 10-22-2008 02:20 PM
LXer: Learn how to use nmap, and nmap GUI, a great port scan tool LXer Syndicated Linux News 0 01-03-2008 09:10 AM
malloc always retuns NULL sramy Programming 1 02-12-2007 07:19 AM
malloc retuns NULL sramy Linux - Server 1 02-12-2007 06:50 AM
How To Format An existing partition on the local harddisk benben_shen Linux - Software 4 03-16-2006 10:48 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:48 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration