LinuxQuestions.org
Visit the LQ Articles and Editorials section
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices

Reply
 
Search this Thread
Old 03-18-2007, 08:37 AM   #1
nakkaya
Guru
 
Registered: Jan 2003
Location: Turkey&USA
Distribution: Emacs and linux is its device driver(Slackware,redhat)
Posts: 1,398

Rep: Reputation: 45
unknown open port 5190 ( no aol running )


i have server that nmap shows port 5190 is open netstat and lsof doesn't list it on iptables everything is closed but a couple of ports in use 80 22 4 other ports my application uses my distro is slackware this machines runs tomcat, java , rmi , jmanage , ssh and nothing else.

Last edited by nakkaya; 03-18-2007 at 09:06 AM.
 
Old 03-18-2007, 09:05 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,398

Rep: Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965
5190 is within the ephemeral port range, as such it's *probably* a client connection to a remote service, not a server. you can always just run tcpdump to capture any packets and inspect them in closer detail in wireshark.

additionally.. don't publicise your public ip addresses...
 
Old 03-18-2007, 11:23 AM   #3
duryodhan
Senior Member
 
Registered: Oct 2006
Distribution: Slackware 12 Kernel 2.6.24 - probably upgraded by now
Posts: 1,054

Rep: Reputation: 46
Hey,
Try running netstat. Read its manual. You can figure out the name of the prog that keeps that port open.
 
Old 03-18-2007, 11:42 AM   #4
barbar
LQ Newbie
 
Registered: Mar 2007
Posts: 15

Rep: Reputation: 0
What is the output of
Code:
lsof -i :5190
 
Old 03-18-2007, 12:48 PM   #5
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,398

Rep: Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965
Quote:
Originally Posted by duryodhan
Hey,
Try running netstat. Read its manual. You can figure out the name of the prog that keeps that port open.
well he did... and he showed the output... then removed it.
 
Old 03-18-2007, 01:38 PM   #6
nakkaya
Guru
 
Registered: Jan 2003
Location: Turkey&USA
Distribution: Emacs and linux is its device driver(Slackware,redhat)
Posts: 1,398

Original Poster
Rep: Reputation: 45
Quote:
Originally Posted by barbar
What is the output of
Code:
lsof -i :5190
it does not show anything thats what ticked me of.

all other open ports return some process except 5190.
 
Old 03-18-2007, 01:42 PM   #7
nakkaya
Guru
 
Registered: Jan 2003
Location: Turkey&USA
Distribution: Emacs and linux is its device driver(Slackware,redhat)
Posts: 1,398

Original Poster
Rep: Reputation: 45
blooby@istanbul:~$ netstat -a
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address Foreign Address State
tcp 0 0 *:1090 *:* LISTEN
tcp 0 0 *:9090 *:* LISTEN
tcp 0 0 *:1091 *:* LISTEN
tcp 0 0 localhost:8005 *:* LISTEN
tcp 0 0 *:time *:* LISTEN
tcp 0 0 *:8006 *:* LISTEN
tcp 0 0 *:8007 *:* LISTEN
tcp 0 0 *:8009 *:* LISTEN
tcp 0 0 *:1099 *:* LISTEN
tcp 0 0 istanbul.blooby.co:9099 *:* LISTEN
tcp 0 0 *:http *:* LISTEN
tcp 0 0 *:auth *:* LISTEN
tcp 0 0 *:ssh *:* LISTEN
tcp 0 0 *:3000 *:* LISTEN
tcp 0 0 *:3001 *:* LISTEN
tcp 0 0 istanbul.blooby.co:1091 istanbul.blooby.c:41731 ESTABLISHED
tcp 0 0 istanbul.blooby.c:41801 istanbul.blooby.co:3001 TIME_WAIT
tcp 0 0 istanbul.blooby.c:41781 istanbul.blooby.co:3000 TIME_WAIT
tcp 0 0 istanbul.blooby.c:41784 istanbul.blooby.co:3000 ESTABLISHED
tcp 0 0 istanbul.blooby.c:41797 istanbul.blooby.co:3000 TIME_WAIT
tcp 0 0 istanbul.blooby.c:41805 istanbul.blooby.co:3000 ESTABLISHED
tcp 0 0 istanbul.blooby.c:41704 istanbul.blooby.co:3001 ESTABLISHED
tcp 0 0 istanbul.blooby.co:3000 istanbul.blooby.c:41784 ESTABLISHED
tcp 0 0 istanbul.blooby.co:3000 istanbul.blooby.c:41805 ESTABLISHED
tcp 0 0 istanbul.blooby.co:1090 istanbul.blooby.c:41795 ESTABLISHED
tcp 0 0 localhost:8007 localhost:52056 ESTABLISHED
tcp 0 0 istanbul.blooby.co:1090 istanbul.blooby.c:41807 ESTABLISHED
tcp 0 0 localhost:8006 localhost:52040 ESTABLISHED
tcp 0 0 localhost:52056 localhost:8007 ESTABLISHED
tcp 0 0 localhost:52040 localhost:8006 ESTABLISHED
tcp 0 0 istanbul.blooby.c:41800 istanbul.blooby.co:1091 TIME_WAIT
tcp 0 0 istanbul.blooby.c:41808 208.101.30.185-sta:http ESTABLISHED
tcp 0 0 istanbul.blooby.c:41809 208.101.30.185-sta:http ESTABLISHED
tcp 0 0 istanbul.blooby.c:41804 208.101.30.185-sta:http TIME_WAIT
tcp 0 0 istanbul.blooby.c:41802 208.101.30.185-sta:http TIME_WAIT
tcp 0 0 istanbul.blooby.c:41803 208.101.30.185-sta:http TIME_WAIT
tcp 0 0 istanbul.blooby.c:41794 208.101.30.185-sta:http TIME_WAIT
tcp 0 0 istanbul.blooby.c:41793 208.101.30.185-sta:http TIME_WAIT
tcp 0 0 istanbul.blooby.c:41731 istanbul.blooby.co:1091 ESTABLISHED
tcp 0 0 istanbul.blooby.c:41798 istanbul.blooby.co:1090 TIME_WAIT
tcp 0 0 istanbul.blooby.c:41792 istanbul.blooby.co:1090 TIME_WAIT
tcp 0 0 istanbul.blooby.c:41795 istanbul.blooby.co:1090 ESTABLISHED
tcp 0 0 istanbul.blooby.c:41807 istanbul.blooby.co:1090 ESTABLISHED
tcp 0 0 istanbul.blooby.c:41787 istanbul.blooby.co:1090 TIME_WAIT
tcp 0 0 istanbul.blooby.c:41733 istanbul.blooby.co:1090 TIME_WAIT
tcp 0 0 istanbul.blooby.co:3001 istanbul.blooby.c:41704 ESTABLISHED
tcp 0 0 192.168.0.1:41789 192.168.0.2:3001 TIME_WAIT
tcp 0 0 192.168.0.1:41761 192.168.0.2:3001 TIME_WAIT
tcp 0 0 192.168.0.1:41810 192.168.0.2:3001 ESTABLISHED
tcp 0 0 192.168.0.1:41799 192.168.0.2:3001 TIME_WAIT
tcp 0 0 192.168.0.1:41796 192.168.0.2:3001 TIME_WAIT
tcp 0 0 192.168.0.1:41806 192.168.0.2:3001 ESTABLISHED
tcp 0 3088 istanbul.blooby.com:ssh 88.245.69.73:58343 ESTABLISHED
tcp 0 0 192.168.0.1:52058 192.168.0.2:8007 ESTABLISHED
tcp 0 0 192.168.0.1:41790 192.168.0.2:ssh TIME_WAIT
tcp 0 0 192.168.0.1:41791 192.168.0.2:ssh TIME_WAIT
tcp 0 0 192.168.0.1:41734 192.168.0.2:1091 ESTABLISHED
tcp 0 0 istanbul.blooby.co:1090 192.168.0.2:44140 ESTABLISHED
tcp 0 0 istanbul.blooby.co:1090 192.168.0.2:44148 ESTABLISHED
udp 0 0 *:biff *:*
udp 0 0 *:time *:*
Active UNIX domain sockets (servers and established)
Proto RefCnt Flags Type State I-Node Path
unix 3 [ ] DGRAM 136 /dev/log
unix 3 [ ] STREAM CONNECTED 13304352
unix 3 [ ] STREAM CONNECTED 13304351
unix 2 [ ] STREAM CONNECTED 12609578
unix 2 [ ] STREAM CONNECTED 12609530
unix 2 [ ] STREAM CONNECTED 11169025
unix 2 [ ] DGRAM 139
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
unknown service controling open port rysio Linux - Security 2 09-13-2005 12:48 PM
unknown port allways open :\ mebae Slackware 7 06-06-2005 06:37 PM
strange service running ... open port shadow.blue Slackware 12 04-16-2004 05:42 PM
nmap shows port 21 open, but no ftp service running ? epoo Linux - Networking 3 12-21-2003 08:16 PM
Unknown Open Port _boris_ Linux - Security 2 12-20-2000 11:27 PM


All times are GMT -5. The time now is 07:42 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration