Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here. |
| Notices |
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Are you new to LinuxQuestions.org? Visit the following links:
Site Howto |
Site FAQ |
Sitemap |
Register Now
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
 |
GNU/Linux Basic Guide
This 255-page guide will provide you with the keys to understand the philosophy of free software, teach you how to use and handle it, and give you the tools required to move easily in the world of GNU/Linux. Many users and administrators will be taking their first steps with this GNU/Linux Basic guide and it will show you how to approach and solve the problems you encounter.
Click Here to receive this Complete Guide absolutely free. |
|
 |
06-04-2002, 09:16 PM
|
#1
|
|
LQ Newbie
Registered: Jun 2002
Posts: 16
Rep:
|
port 113
I found from my firewall monitor, our linux server keeps using port 113 to connect to a few external IP addresses. This did not happened before.
Based on my firewall information, it is my server which directly contact those external IP instead of coming in (our firewall blocks incoming signals from port 113).
Does anyone know what can I do about it ?
|
|
|
|
06-05-2002, 02:36 AM
|
#2
|
|
Member
Registered: May 2002
Location: London
Distribution: Debian
Posts: 388
Rep:
|
If you take a look at /etc/services you'll see that port 113 is used by ident. Unless you need it, disable it.
Regards
|
|
|
|
06-05-2002, 02:59 AM
|
#3
|
|
LQ Newbie
Registered: Jun 2002
Posts: 16
Original Poster
Rep:
|
We are currently running Apache, Sendmail and POP3 service in the Linux server. Is port 113 useful ?
I used the firewall to blocked all outgoing signals from port 113, it appears the server need this port to send something back to our e-mail users (but I don't know it is used in POP3 or SMTP).
No matter what, blocking this port seems not affecting our e-mails at this moment.
|
|
|
|
06-05-2002, 04:33 AM
|
#4
|
|
Member
Registered: May 2002
Location: Dalec, HU
Distribution: Redhat 7.3
Posts: 696
Rep:
|
i think it mostly used for ftp and pop3 so you'll probably have to keep it
|
|
|
|
06-05-2002, 08:46 AM
|
#5
|
|
Member
Registered: Apr 2002
Posts: 498
Rep:
|
Try rejecting instead of dropping. There is still a time lag when users try to log in, but it isn't nearly as bad with a REJECT rather than a DROP.
|
|
|
|
06-05-2002, 10:12 PM
|
#6
|
|
LQ Newbie
Registered: Jun 2002
Posts: 16
Original Poster
Rep:
|
when I issue command : netstat , I found the Linux server is using port 4256, 4257, 4258.... instead of Port 113, POP3 and SMTP. And the destination IPs are in line with the outgoing addresses captured by our firewall from Port 113 of the Linux.
I feel uncomfortable and wonder my server has been trojan. Any software allows me to watch what is the data passing through these port ?
|
|
|
|
06-06-2002, 12:34 AM
|
#7
|
|
LQ Addict
Registered: Dec 2001
Location: Brooklyn, NY
Distribution: *NIX
Posts: 3,704
Rep:
|
man tcpdump
the expression allows you to specify port
|
|
|
|
06-06-2002, 05:53 AM
|
#8
|
|
Member
Registered: May 2002
Location: Dalec, HU
Distribution: Redhat 7.3
Posts: 696
Rep:
|
go rather for sniffit progie; really nice and adjustable
|
|
|
|
| Thread Tools |
Search this Thread |
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
Similar Threads
|
| Thread |
Thread Starter |
Forum |
Replies |
Last Post |
|
Port 113
|
floppywhopper |
Linux - Security |
7 |
02-07-2008 06:51 PM |
|
port 113
|
jthepro |
Linux - Networking |
2 |
05-24-2004 12:52 PM |
|
113 port
|
spank |
Linux - Newbie |
3 |
12-02-2003 03:54 PM |
|
blocking port 113
|
pix |
Debian |
6 |
08-01-2003 05:53 AM |
|
How to stealth port #113 ?
|
johnm1957 |
Linux - Networking |
5 |
06-05-2002 10:25 PM |
All times are GMT -5. The time now is 09:48 AM.
|
|
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.
|
Latest Threads
LQ News
|
|