LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-27-2004, 12:08 PM   #1
allohakdan
LQ Newbie
 
Registered: Sep 2003
Location: The Hills of West Virginia
Distribution: Ubuntu/Debian
Posts: 25

Rep: Reputation: 15
port 80/tcp closes itself?


is it posible for port 80/tcp to close itself w/o me telling it to. Im running Mandrake Linux with Apache to host a personal web site. It has been up and working fine for several months now, but just today when i tried to go to the page, i found that port 80/tcp had been closed. I have a firewall turned on but i left port 80 open. I KNOW that I did not close that port so i dont understand what happened. I just did a portscan and got the result-

PORT STATE SERVICE
1/tcp filtered tcpmux
7/tcp filtered echo
9/tcp filtered discard
11/tcp filtered systat
13/tcp filtered daytime
15/tcp filtered netstat
19/tcp filtered chargen
25/tcp filtered smtp
53/tcp filtered domain
69/tcp filtered tftp
79/tcp filtered finger
80/tcp filtered http
87/tcp filtered priv-term-l
98/tcp filtered linuxconf
110/tcp filtered pop-3
111/tcp open rpcbind
135/tcp filtered msrpc
137/tcp filtered netbios-ns
138/tcp filtered netbios-dgm
139/tcp filtered netbios-ssn
143/tcp filtered imap
220/tcp filtered imap3
411/tcp filtered rmt
412/tcp filtered synoptics-trap
443/tcp open https
445/tcp filtered microsoft-ds
514/tcp filtered shell
593/tcp filtered http-rpc-epmap
631/tcp open ipp
707/tcp filtered unknown
995/tcp filtered pop3s
996/tcp filtered xtreelic
997/tcp filtered maitrd
998/tcp filtered busboy
999/tcp filtered garcon
1214/tcp filtered fasttrack
1234/tcp filtered hotline
1241/tcp open nessus
2301/tcp filtered compaqdiag
4444/tcp filtered krb524
6000/tcp open X11
6346/tcp filtered gnutella
6667/tcp filtered irc
6699/tcp filtered napster
12345/tcp filtered NetBus
12346/tcp filtered NetBus
32771/tcp open sometimes-rpc5
54320/tcp filtered bo2k
65301/tcp filtered pcanywhere

that nessus port is up because i tryed to start the nessus server, but i never actualy managed to make it work( i dont know if that has anything to do with it).

Anyone know why this would happen?

Thanks in advance
 
Old 01-27-2004, 07:16 PM   #2
benjithegreat98
Senior Member
 
Registered: Dec 2003
Location: Shelbyville, TN, USA
Distribution: Fedora Core, CentOS
Posts: 1,019

Rep: Reputation: 45
Have you ensured that appache is still running? Try ps aux to see the local processess. You can also use netstat -nlp to see what programs are listening on what ports. I imagine that apache is still running because port 443 is open. You can also check your firewall rules: iptables -L
 
Old 01-27-2004, 08:27 PM   #3
allohakdan
LQ Newbie
 
Registered: Sep 2003
Location: The Hills of West Virginia
Distribution: Ubuntu/Debian
Posts: 25

Original Poster
Rep: Reputation: 15
apache is still running. i can also see the page from inside my LAN (and the port scan said port 80 is open when i scan the server as 192.168.0.161). but anything on the other side of my router sees the port as closed. i have a D-Link DI-704P router. i have nothing special set up on it except for a DHCP server. i have 192.168.0.161 in the DMZ. so something is really wierd. im not shure this falls under security anymore except that it changed without my permision.

dan
 
Old 01-27-2004, 09:40 PM   #4
benjithegreat98
Senior Member
 
Registered: Dec 2003
Location: Shelbyville, TN, USA
Distribution: Fedora Core, CentOS
Posts: 1,019

Rep: Reputation: 45
I don't know d-link routers, but you'll have to reconfigure it to route incoming port 80 traffic to 192.168.0.161. You have to reference the router documentation for that. If you are sure that is set then you'll need to review your apache configuration for anything weird, like maybe, not accepting traffic from all IPs.... Somethig like that. Sounds like a routing issue, however.
 
Old 01-28-2004, 11:14 AM   #5
allohakdan
LQ Newbie
 
Registered: Sep 2003
Location: The Hills of West Virginia
Distribution: Ubuntu/Debian
Posts: 25

Original Poster
Rep: Reputation: 15
Thank you, I think you are right. It does sound like a routing problem (i think). That means that this thread is in the wrong forum now, but I still have not been able to fix the problem. So if you or anyone else have sugestions as to what i can do- please send them to me. Remember that the page used to work just fine. Thanks for your help.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Process and TCP Port jonty_11 Programming 7 02-22-2005 06:27 PM
tcp port 783 hyd_lin Linux - Networking 6 11-27-2003 07:34 PM
How to know some more about an open TCP port? yuzuohong Linux - General 1 05-12-2003 09:42 PM
how is a tcp port opened? Kayaker Linux - Security 7 05-12-2003 12:47 AM
close port 6000/tcp 515/tcp SchwipSchwap Linux - Newbie 1 09-12-2002 08:24 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:46 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration