LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-18-2003, 04:00 AM   #1
ohcysp
LQ Newbie
 
Registered: Aug 2003
Location: Lund, Sweden
Distribution: slackware 9.0
Posts: 9

Rep: Reputation: 0
wierd port open


Hi!

Using nmap to scan my computer, I get these results

"[...]
Interesting ports on localhost (127.0.0.1):
(The 1597 ports scanned but not shown below are in state: closed)
Port State Service
22/tcp open ssh
242/tcp open direct
970/tcp open unknown
6000/tcp open X11
[...]"

I know what every port except 970 is for, and I'm not able to find which program or whatever, opens it.

socklist gives me

"[...]
type port inode uid pid fd name
tcp 970 440 0 0 0
tcp 6000 518 0 0 0
tcp 242 451 0 0 0
tcp 22 453 0 0 0
tcp 22 139149 0 0 0
[...]"

Again, I don't see what port 970 is for.

Is my box compromised?

Please help.

Regards
Kristoffer
 
Old 08-18-2003, 07:41 AM   #2
sandy
Member
 
Registered: Aug 2002
Location: Mumbai,India
Distribution: Linux Mint 12, Gentoo
Posts: 230

Rep: Reputation: 30
type lsof and look for the files opened / accessed by the port. This may give you a clue about the service that uses the port
 
Old 08-18-2003, 08:23 AM   #3
ohcysp
LQ Newbie
 
Registered: Aug 2003
Location: Lund, Sweden
Distribution: slackware 9.0
Posts: 9

Original Poster
Rep: Reputation: 0
Thanks.

Ok, so LSOF gives me this when grepping for "970":

"[...]
inetd 370 root 4u IPv4 439 TCP *:970 (LISTEN)
[...]"

Well, looks like inetd to me (which i also found out by killing process after process and trying to determine which one it was that kept port 970 open).


Though, from here I'm clueless. I didn't find any reference to port 970 in my inetd.conf or /etc/rc.d ...


Somewhat annoying.
 
Old 08-18-2003, 08:29 AM   #4
ohcysp
LQ Newbie
 
Registered: Aug 2003
Location: Lund, Sweden
Distribution: slackware 9.0
Posts: 9

Original Poster
Rep: Reputation: 0
Ok, so, problem resolved. Turned out to be fam listening on that port. Found it out after going through a bundle of nestled configfiles referring to each other.

Thanks for the tip about lsof


Regards
Kristoffer - a now happy person again.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
cannot SFTP to SUSE 9.2 box, port 22 open, can putty in though using same port. jgrady Linux - Networking 6 03-29-2005 08:44 AM
how do i open a port ? raminn Linux - Networking 4 03-28-2005 12:31 AM
font looks wierd in open office santasballz Linux - Software 1 03-08-2004 03:36 PM
port 25 not open westrant Linux - Networking 2 03-20-2002 04:09 PM
firewall.rc.config says :"open port 8080" but nmap says port is closed saavik Linux - Security 2 02-14-2002 12:16 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:24 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration