LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 02-18-2012, 06:16 AM   #1
rhklinux
Member
 
Registered: Jan 2010
Location: india/pune
Distribution: Arch Fedora20
Posts: 126

Rep: Reputation: 18
Exclamation connection made to National Internet Development Agency of Korea for unknown reasons


I just netstat to see tcp connections.and found some entries that are not intended to be there.I am using ubuntu.I live in india
here is output of netstat:
Code:
tcp        0      1 192.168.1.3:43331       211.239.150.206:80      SYN_SENT
I have connected to internet through a router.
i used network tool to see the host name of destination ip address(211.239.150.206)
this is what i got:
Code:
# ENGLISH

KRNIC is not an ISP but a National Internet Registry similar to APNIC.

[ Network Information ]
IPv4 Address       : 211.239.128.0 - 211.239.191.255 (/18)
Service Name       : SEJONGNET
Organization Name  : SEJONG TELECOM
Organization ID    : ORG110145
Address            : Hyundai B/D, 646-1, Yeoksam-dong, Gangnam-gu
Zip Code           : 135-080
Registration Date  : 20010419

[ Admin Contact Information ]
Name               : IP Administrator
Phone              : +82-2-1688-7380
E-Mail             : ip@sejongtelecom.net

[ Tech Contact Information ]
Name               : IP Manager
Phone              : +82-2-1688-7380
E-Mail             : ip@sejongtelecom.net

[ Network Abuse Contact Information ]
Name               : Network Abuse
Phone              : +82-2-3415-4320
E-Mail             : abuse@sejongtelecom.net

--------------------------------------------------------------------------------

More specific assignment information is as follows.

[ Network Information ]
IPv4 Address       : 211.239.150.0 - 211.239.151.255 (/23)
Network Name       : ENTERPRISENET-IDC-HOSTWAY
Organization Name  : Hostway
Organization ID    : ORG407396
Address            : 343-1 Hostway, Bundang-gu, Seongnam-si, Gyeonggi
Zip Code           : 463-070
Registration Date  : 20040914
Publishes          : Y

[ Technical Contact Information ]
Name               : Cho, Hanjin
Organization Name  : Hostway
Address            : 343-1Hoseuteuwei Bldg., Bundang-gu, Seongnam-si, Gyeonggi
Zip Code           : 463-070
Phone              : +82-70-8630-1461
E-Mail             : abuse@hostway.co.kr


- KISA/KRNIC Whois Service -
I googled about it and found that its National Internet Development Agency of Korea
thanks for reply
 
Old 02-18-2012, 06:44 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by rhklinux View Post
I just netstat to see tcp connections.and found some entries that are not intended to be there.
And why would that be? How else should applications check WHOIS, ASN or other nfo?


Quote:
Originally Posted by rhklinux View Post
here is output of netstat
If next time you run netstat with '-ntulpe' you get more details like the PID of the application.
 
Old 02-18-2012, 07:01 AM   #3
rhklinux
Member
 
Registered: Jan 2010
Location: india/pune
Distribution: Arch Fedora20
Posts: 126

Original Poster
Rep: Reputation: 18
Thanks for reply I will look for process.
 
Old 02-18-2012, 07:12 AM   #4
malekmustaq
Senior Member
 
Registered: Dec 2008
Location: root
Distribution: Slackware & BSD
Posts: 1,669

Rep: Reputation: 498Reputation: 498Reputation: 498Reputation: 498Reputation: 498
KRNIC is an APNIC register in korea. But why would that korean IP talk directly to your host? I remember another korean IP here.
 
Old 02-18-2012, 07:50 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by malekmustaq View Post
why would that korean IP talk directly to your host?
Note the netstat entry reads SYN_SENT with the non-LAN IP on the right hand. So it is not "KRNIC talking to his host" but his machine contacting 211.239.150.206. And according to ROBTEX db.asia.clamav.net shares the IP address too.
 
Old 02-21-2012, 10:17 PM   #6
rhklinux
Member
 
Registered: Jan 2010
Location: india/pune
Distribution: Arch Fedora20
Posts: 126

Original Poster
Rep: Reputation: 18
sory for late replay unSpawn but what does that mean ?
 
Old 02-21-2012, 11:56 PM   #7
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
It means that if you run ClamAV it uses the IP address to check for updates.
 
Old 02-24-2012, 03:11 AM   #8
rhklinux
Member
 
Registered: Jan 2010
Location: india/pune
Distribution: Arch Fedora20
Posts: 126

Original Poster
Rep: Reputation: 18
Yeh i have ClamAV running !! that must be the case.thanks !!
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: SE: ODF made national standard in Sweden LXer Syndicated Linux News 0 10-09-2008 07:20 AM
LXer: Reasons for National Boards to vote no for OOXML LXer Syndicated Linux News 0 12-18-2007 10:41 PM
LXer: Novell made the right decision even if for the wrong reasons LXer Syndicated Linux News 0 08-02-2006 10:33 PM
NO pages will load after internet connection has been made! aweir14150 Mandriva 2 02-25-2004 12:38 PM
internet connection STOPPED working without a change made! fede_mdk Linux - Networking 11 08-05-2003 10:26 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 11:11 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration