LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-25-2004, 04:56 PM   #1
Kovacs
Member
 
Registered: Jul 2003
Distribution: FreeBSD 8.2 RELEASE
Posts: 607

Rep: Reputation: 32
What does this netstat output mean?


I am a complete security newb and have been very lax about learning so far, possibly now to my detriment. Perhaps I am being a drama queen, but I was talking to someone on icq last night who started threatening to haxor me. Shortly after that, the date on my kde clock started saying "moscow" instead of the date, and this was the output of netstat -tl:

Code:
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address           Foreign Address         State
tcp        0      0 192.168.1.181:aol       *:*                     LISTEN
tcp        0      0 *:x11                   *:*                     LISTEN
tcp        0      0 192.168.1.181:4443      *:*                     LISTEN
I realise that the second line is X11 but it's the first and last that concern me, as they come and go. I use this PC to earn a living so I'm sure you can see why I'm concerned.
 
Old 01-25-2004, 05:49 PM   #2
darklogik_org
Member
 
Registered: Jan 2004
Distribution: freebsd 5.3, openbsd 3.6, slackware 10
Posts: 96

Rep: Reputation: 15
Well, I'm guessing you're an AOL user for a start!

Port 4443 is the port that AOL Instant Messenger uses and

$ cat /etc/services | grep "aol"

tells us that "aol" uses tcp port 5190. If you're NOT an aol user, I'd be concerned. Check your /etc/rc.d/ directory for anything suspicious (particuarly rc.local).

I'm afraid without further details, I can't be of much help.

mark
 
Old 01-25-2004, 06:32 PM   #3
Kovacs
Member
 
Registered: Jul 2003
Distribution: FreeBSD 8.2 RELEASE
Posts: 607

Original Poster
Rep: Reputation: 32
No I'm not an aol user, and not in the US. I just realised that the first and last two lines appear when I'm connected to icq in kopete, but I don't have aim configured in kopete (nor do I use it) so I don't see why I should have a connection to aol.

One thing that is also concerning is that the output of users when I first boot and log on (on the command line) is:

username

Once I startx, the output of users is:

username username

And at some point (like right now) that changes to:

username username username

When I exit x, log out and log in as root, it still says:

root username username

I can't say I've had much reason to ever use this command before but it doesn't look right to me.

I'm frantically trying to read up on security but any further input would be greatly appreciated.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Netstat output Raafi Linux - Security 4 05-24-2005 10:14 PM
netstat -r command output juanb Linux - Networking 1 10-28-2004 02:30 PM
unfamiliar netstat output TreeHugger Linux - Security 4 02-28-2004 11:33 AM
netstat -l output help dai Linux - Security 2 07-02-2003 03:40 PM
netstat output... WeNdeL Linux - Networking 3 03-20-2003 09:45 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:39 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration