LinuxQuestions.org
View the Most Wanted LQ Wiki articles.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
LinkBack Search this Thread
Old 07-23-2005, 06:18 PM   #1
floppywhopper
Member
 
Registered: Aug 2004
Location: Albany, Western Australia
Distribution: Mageia 1, SME Server
Posts: 598
Blog Entries: 2

Rep: Reputation: 34
repeated attempts at port 800 from inside


If someone can shed some light on this I would be grateful ...

Basically my internet setup is as follows
Modem >>> IP Cop firewall >>> 2 x Windows computers

just last night both computers,( but my wifes more than mine ), started trying to access port 800 on the IP Cop firewall

here is a sample >>
18:38:56 NEW not SYN? eth0 TCP 192.168.0.101 1154
192.168.0.1 800(MDBS_DAEMON)

something, in this case using port 1154 trying to access port 800
but also using ports
1139, 1150, 1153, 1155, 1156, 1157, 1929
to access port 800

is this normal or is something unpleasant happening
I have run ( updated ) virus scanner and do so regularly

floppy

edit
I should also add that both computers have firewalls installed in windows and there doesn't seem to be anything in there that shouldn't be there ???

Last edited by floppywhopper; 07-23-2005 at 06:30 PM.
 
Old 07-25-2005, 05:18 PM   #2
sundialsvcs
Senior Member
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 3,685

Rep: Reputation: 330Reputation: 330Reputation: 330Reputation: 330
Well, port #800 isn't listed in my /etc/services file, but a quick Google search indicates that this port is used by Microsoft's proxy-server, and the equivalent Unix proxy-server, Squid.

There are a lot of explanations of why one might wish to use a proxy, but a good, succint one may be found at http://martybugs.net/smoothwall/squid.cgi.

I suspect that this (innocuous) thing is probably being done in your case.
 
Old 08-16-2005, 07:10 PM   #3
Franklin
Senior Member
 
Registered: Oct 2002
Distribution: Slackware, WinXP, Windows 7
Posts: 1,243

Rep: Reputation: 48
Hey Floppy...

This is the first post I've seen about this.
I'm having a similar issue related to this thread:

http://www.linuxquestions.org/questi...hreadid=353195

Actually more a post than a thread

While I did not mention port 800, it is involved. Google turned up hits re: apache on this port, but it's still active and no apache is running on my machine. Did you ever find out anything regarding the hits on this port from inside?

Steve
 
Old 08-17-2005, 02:01 AM   #4
floppywhopper
Member
 
Registered: Aug 2004
Location: Albany, Western Australia
Distribution: Mageia 1, SME Server
Posts: 598
Blog Entries: 2

Original Poster
Rep: Reputation: 34
Nah haven't figured it out yet

Yeah I knew whatever it was was trying to access the proxy port

but my firewall ( Ip Cop ) is running a transparent proxy
and all my usual apps access the web OK
through the onboard firewall on my Win 98 comp.

Probing further back in the logs
it seems to happen only on Saturdays
so naturally I suspected something trying to update itself
but haven't been able to narrow it down

I must put a bit more effort in to it
At first I thought something very unpleasant might be happening
but now I dont think so
so as I said
I must get onto it

If I find out
I'll post here

floppy
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Iptables help, block port to outside but open to inside. Brian1 Linux - Networking 2 09-27-2005 08:41 PM
Port Scan from inside JZL240I-U Linux - Security 20 02-16-2005 09:09 AM
Repeated, targeted port 1025 ACK RST scottman Linux - Security 2 10-06-2004 01:35 AM
Outside FTP Port 21 redirect to different port inside LAN??? hendrixx Linux - Security 5 06-05-2004 06:42 PM
how do i forward a port to and inside IP parabit Linux - Networking 3 01-09-2002 10:17 AM


All times are GMT -5. The time now is 11:18 AM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration