LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-19-2004, 10:16 AM   #1
orgcandman
Member
 
Registered: May 2002
Location: new hampshire
Distribution: Fedora, RHEL
Posts: 600

Rep: Reputation: 110Reputation: 110
odd behavior from linux kernel


Today I was working on some software that involved network traffic, so I started tcpdump, and sat there happily doing my thing.

I killed off my network programs, and was busy debugging something when I noticed a weird bunch of SYNACK->ACK on the loopback device. there are no TCP SYN's starting it, and there's nothing else I can think of. there are no non-ack packets, netstat doesn't report anything unusual, there are no extraneous file descriptors in /proc that could explain it. could it be internal transfer between some running programs? maybe IPC?

Anyone with any information feel free to reply

snippet of some of the packets:

Code:
10:44:53.502287 reveka.orgcandman.com.60317 > reveka.orgcandman.com.1098: S 2228933544:2228933544(0) win 32767 <mss 16396,sackOK,timestamp 14350431[|tcp]> (DF)
0x0000   4500 003c 2bf7 4000 4006 8d70 c0a8 0002        E..<+.@.@..p....
0x0010   c0a8 0002 eb9d 044a 84da d3a8 0000 0000        .......J........
0x0020   a002 7fff cab5 0000 0204 400c 0402 080a        ..........@.....
0x0030   00da f85f 0000                                 ..._..
10:44:53.502355 reveka.orgcandman.com.1098 > reveka.orgcandman.com.60317: S 2219981233:2219981233(0) ack 2228933545 win 32767 <mss 16396,sackOK,timestamp 14350431[|tcp]> (DF)
0x0000   4500 003c 0000 4000 4006 b967 c0a8 0002        E..<..@.@..g....
0x0010   c0a8 0002 044a eb9d 8452 39b1 84da d3a9        .....J...R9.....
0x0020   a012 7fff 1367 0000 0204 400c 0402 080a        .....g....@.....
0x0030   00da f85f 00da                                 ..._..
the ports ARE changing. maybe this is related to emacs/the fact that I'm sshed in. I'm just paranoid because a while ago I was subjected to a lot of failed ssh attacks (none were successful, and md5 sums were untouched). am I just freaking out? does anyone know what this is related to?
 
Old 11-19-2004, 10:31 AM   #2
bignerd
Member
 
Registered: Nov 2004
Distribution: FC1, Gentoo, Mdk 8.1, RH7-8-9, Knoppix, Zuarus rom 3.13
Posts: 98

Rep: Reputation: 15
Have you ran lsof to see what process is listening and what process is sending?

-b
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Odd Knoppix behavior Darkstar Linux - Distributions 1 06-25-2005 09:46 PM
Odd kernel-package behavior. yarjar Debian 3 05-11-2005 03:38 AM
Odd Behavior of Epiphany Jeffmrg Slackware 2 09-09-2004 08:23 AM
Odd CD behavior in installation MockieMoo Slackware - Installation 1 05-14-2004 10:28 PM
RH 6.2 ... odd behavior jubal Linux - Networking 3 02-27-2001 09:04 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:33 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration