LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-28-2018, 09:05 AM   #1
hifi100
Member
 
Registered: Sep 2016
Location: India
Distribution: Arch Linux
Posts: 357

Rep: Reputation: Disabled
Torrent client and open ports


Hi,

I am using Ubuntu. I have configured ufw like this

Code:
 sudo ufw default deny
but still when I open a torrent client like transmission


and do a port scan I get this

Code:
$ nmap 192.168.0.100 -p51413

Starting Nmap 7.60 ( https://nmap.org ) at 2018-01-28 20:33 IST
Nmap scan report for xubuntu (192.168.0.100)
Host is up (0.000062s latency).

PORT      STATE SERVICE
51413/tcp open  unknown

Nmap done: 1 IP address (1 host up) scanned in 0.05 seconds
How come the port is open ? Isn't ufw suppose to block that port

unless I add an "allow" rule ?
 
Old 01-29-2018, 04:34 AM   #2
hifi100
Member
 
Registered: Sep 2016
Location: India
Distribution: Arch Linux
Posts: 357

Original Poster
Rep: Reputation: Disabled
Nobody ?
 
Old 01-29-2018, 08:33 AM   #3
camp0
Member
 
Registered: Dec 2016
Location: Dublin
Distribution: Fedora
Posts: 70

Rep: Reputation: 4
Hi, I think you need to describe the issue better, for example: are you executing nmap from the same machine? Can you check with lsof who is listening on that port? also you can have a port listening on a port and block the income packets in the same machine. Where do you have the firewall?
 
Old 01-29-2018, 08:41 AM   #4
hifi100
Member
 
Registered: Sep 2016
Location: India
Distribution: Arch Linux
Posts: 357

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by camp0 View Post
Hi, I think you need to describe the issue better, for example: are you executing nmap from the same machine? Can you check with lsof who is listening on that port? also you can have a port listening on a port and block the income packets in the same machine. Where do you have the firewall?
Yes I am running nmap from the same machine.

Please give me the exact lsof command.

The firewall (ufw) is on the same machine which is running

the torrent client.
 
Old 01-29-2018, 09:56 AM   #5
camp0
Member
 
Registered: Dec 2016
Location: Dublin
Distribution: Fedora
Posts: 70

Rep: Reputation: 4
lsof -p <pid> or even better https://linux.die.net/man/8/lsof
 
Old 01-31-2018, 02:17 AM   #6
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
...also might help clarify:

Code:
ufw status verbose
 
Old 01-31-2018, 07:16 AM   #7
hifi100
Member
 
Registered: Sep 2016
Location: India
Distribution: Arch Linux
Posts: 357

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by ondoho View Post
...also might help clarify:

Code:
ufw status verbose
Code:
$ sudo ufw status verbose
[sudo] password for xubuntu: 
Status: active
Logging: on (low)
Default: deny (incoming), allow (outgoing), disabled (routed)
New profiles: skip

To                         Action      From
--                         ------      ----
51413                      DENY IN     Anywhere                  
51413 (v6)                 DENY IN     Anywhere (v6)             

$ nmap 192.168.0.102 -p51413

Starting Nmap 7.60 ( https://nmap.org ) at 2018-01-31 18:44 IST
Nmap scan report for xubuntu (192.168.0.102)
Host is up (0.000062s latency).

PORT      STATE SERVICE
51413/tcp open  unknown

Nmap done: 1 IP address (1 host up) scanned in 0.03 seconds
Still port 51413 is open (with Transmission open).
 
Old 02-01-2018, 01:59 AM   #8
Trihexagonal
Member
 
Registered: Jul 2017
Posts: 362
Blog Entries: 1

Rep: Reputation: 334Reputation: 334Reputation: 334Reputation: 334
I have never used torrents, but is it possible it's wanting to use you as a peer to seed the files you downloaded and is keeping the port open?

Apparently the Transmission client uses that port.
 
Old 12-20-2020, 06:43 PM   #9
zeebra
Senior Member
 
Registered: Dec 2011
Distribution: Slackware
Posts: 1,834
Blog Entries: 17

Rep: Reputation: 642Reputation: 642Reputation: 642Reputation: 642Reputation: 642Reputation: 642
Are you perhaps running other things on your computer that might open ports as "necessary"? (on demand)

Ps. I don't know anything about ufw and how it works

Last edited by zeebra; 12-20-2020 at 06:45 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: BiglyBT: A ‘New’ Open Source Torrent Client Launched By Former Vuze Developers LXer Syndicated Linux News 0 08-06-2017 02:25 PM
How to open closed ports on torrent clients? Randicus Draco Albus Slackware 6 08-14-2014 01:53 AM
transmission bt client showing ports closed, while deluge shows them open ? daudiam Linux - Software 0 04-08-2011 10:40 AM
Cannot install Bit Torrent client Flush client on Sabayon 4.2 dj1120 Linux - Software 0 08-11-2009 03:20 PM
how to block torrent ports? LinuxNewbie999 Linux - Networking 1 09-04-2007 08:30 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:53 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration