LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-11-2011, 09:25 AM   #1
jagerhans
LQ Newbie
 
Registered: Dec 2003
Location: italy
Distribution: debian lenny , lubuntu 11.10
Posts: 10

Rep: Reputation: 0
PSAD reports continuous scans from my LAN ip


hello, i realized that PSAD is reporting a continuous streak of scan attempts, only they are not scans coming from the outside but scans originating from my lan IP (192.168.16.2) and directed to the outside, if i got that right, which makes me seriously think of being compromised.
one recurring ip address points to metasploit.com, which is pretty weird. can this be a false alert due to some legitimate program ? im confused.

below, one sample alert:


=-=-=-=-=-=-=-=-=-=-=-= Tue Jan 11 16:21:56 2011 =-=-=-=-=-=-=-=-=-=-=-=


Danger level: [2] (out of 5)

Scanned UDP ports: [28409: 1 packets, Nmap: -sU]
iptables chain: OUTPUT (prefix "DROPPED"), 1 packets

Source: 192.168.16.2
DNS: [No reverse dns info available]
OS guess: Linux:2.6:8:Linux 2.6.8 and newer (?)

Destination: 72.204.199.142
DNS: ip72-204-199-142.ph.ph.cox.net

Overall scan start: Tue Jan 11 16:07:13 2011
Total email alerts: 7
Complete UDP range: [28409]
Syslog hostname: [my-machine]

Global stats: chain: interface: TCP: UDP: ICMP:
OUTPUT eth0 0 1 0

[+] Whois Information:
Whois data not available!

Last edited by jagerhans; 01-11-2011 at 10:13 AM.
 
Old 01-12-2011, 01:44 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Protocol is UDP (stateless) and port is ephemeral and w/o IANA assignment, so packet inspection (snort or wireshark) might help fish for clues.
 
Old 01-15-2011, 09:20 AM   #3
jagerhans
LQ Newbie
 
Registered: Dec 2003
Location: italy
Distribution: debian lenny , lubuntu 11.10
Posts: 10

Original Poster
Rep: Reputation: 0
a lot of scans are about port 111 being scanned over the whole subnet mask. psad monitoring portmap, maybe ? looks weird, from the point of view of my poor knowledge.

Last edited by jagerhans; 01-15-2011 at 09:21 AM.
 
Old 01-15-2011, 11:36 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
While I appreciate the response it talks about issues while posting cold hard data could be so much more interesting...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Help with psad Andy12 Linux - Software 1 10-06-2008 01:27 PM
psad known-good ns servers kaplan71 Linux - Software 1 12-11-2007 01:54 AM
Psad coolb Linux - Security 3 12-14-2006 02:31 AM
psad says DL5 dominant Linux - Security 3 03-25-2004 02:50 PM
Question on PSAD code? cxel91a Programming 0 09-05-2003 04:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:35 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration