LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-11-2016, 03:35 PM   #1
seamore
Member
 
Registered: Sep 2009
Posts: 83

Rep: Reputation: 1
ps -ef results


When I did "ps -ef' today I found this. Is someone trying to break in?

root 2619 819 0 13:53 ? 00:00:00 in.telnetd: 85.105.131.63.static.ttnet.com.tr
root 2630 2619 0 13:53 ? 00:00:00 [login] <defunct>
root 3041 3039 0 14:08 pts/33 00:00:00 /bin/login -h abts-north-dynamic-041.68.162.122.airtelbroadband.in -p
root 3044 819 0 14:09 ? 00:00:00 in.telnetd: nsg-static-042.157.72.182.airtel.in
root 3045 3044 0 14:09 pts/7 00:00:00 /bin/login -h nsg-static-042.157.72.182.airtel.in -p
root 3048 819 0 14:09 ? 00:00:00 in.telnetd: 122-116-117-64.hinet-ip.hinet.net
root 3049 3048 0 14:09 pts/12 00:00:00 /bin/login -h 122-116-117-64.hinet-ip.hinet.net -p
root 3052 819 0 14:09 ? 00:00:00 in.telnetd: 219-85-63-81-adsl-tpe.static.so-net.net.tw
root 3053 3052 0 14:09 pts/27 00:00:00 /bin/login -h 219-85-63-81-adsl-tpe.static.so-net.net.tw -p
root 3054 819 0 14:09 ? 00:00:00 in.telnetd: abts-north-dynamic-041.68.162.122.airtelbroadband.in
root 3055 3054 0 14:09 pts/28 00:00:00 /bin/login -h abts-north-dynamic-041.68.162.122.airtelbroadband.in -p
 
Old 11-11-2016, 08:58 PM   #2
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,317
Blog Entries: 28

Rep: Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140
Probably just random port scans, as they come from many different ip addresses. Port scans are a fact of internet life.

If you are concerned, in addition to having a firewall, install fail2ban.
 
Old 11-11-2016, 09:37 PM   #3
Emerson
LQ Sage
 
Registered: Nov 2004
Location: Saint Amant, Acadiana
Distribution: Gentoo ~amd64
Posts: 7,661

Rep: Reputation: Disabled
telnetd?
 
Old 11-12-2016, 05:53 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Indeed the machine shouldn't offer a service like telnetd in the first place and exposing it to the Internet without ACL on top of that is completely contrary to all Best Practices. Disable telnetd then audit the machine for any other services that should not be running, are running without ACLs or any anomalies in login records, binaries, libraries and configuration files.
 
Old 11-12-2016, 10:45 AM   #5
seamore
Member
 
Registered: Sep 2009
Posts: 83

Original Poster
Rep: Reputation: 1
Thank you for the advice.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Different results in du and df? Sayan Acharjee Linux - General 3 02-29-2012 08:53 PM
chkrootkit results rdwinders Linux - Newbie 4 01-22-2007 03:10 PM
Error results RagedPenguin Linux - Newbie 3 03-16-2006 04:12 PM
Exam results Boffy General 15 08-20-2004 01:13 PM
nmap results djcomplex Linux - Software 3 03-20-2004 01:46 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:57 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration