mattmiller |
08-05-2004 02:08 PM |
Okay, thanks for being patient. I was stuck on the idea that tcpdump
was just for filtering my netstat output. Since my netstat output is small
I figured I didn't need tcpdump.
When I run tcpdump I see activity stir as the rogue connection initiates,
but I don't see that output pointing me to any particular line in my netstat
output.
Here is a 'script' of tcpdump as the connection starts and for a few seconds
afterward:
Code:
Script started on Thu Aug 5 11:17:45 2004
debian3:/home/mmiller# pon
debian3:/home/mmiller# pontcpdump -n -i ppp0[Ktcpdump -n -i ppp0
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on ppp0, link-type LINUX_SLL (Linux cooked), capture size 96 bytes
11:20:14.013287 IP 10.64.64.64.32863 > 209.244.0.3.53: 53675+ AAAA? debian. (24)
11:20:19.014370 IP 10.64.64.64.32864 > 209.244.0.4.53: 53675+ AAAA? debian. (24)
11:20:24.014943 IP 10.64.64.64.32863 > 209.244.0.3.53: 53675+ AAAA? debian. (24)
11:20:29.016146 IP 10.64.64.64.32864 > 209.244.0.4.53: 53675+ AAAA? debian. (24)
11:20:53.640407 IP 4.240.51.251.1073 > 209.244.0.3.53: 59610+ AAAA? debian3. (25)
11:20:53.805745 IP 209.244.0.3.53 > 4.240.51.251.1073: 59610 NXDomain 0/1/0 (100)
11:20:55.465780 IP 218.170.54.45.4794 > 4.240.51.251.445: S 959094122:959094122(0) win 16384 <mss 1440,nop,nop,sackOK>
11:20:58.375797 IP 218.170.54.45.4794 > 4.240.51.251.445: S 959094122:959094122(0) win 16384 <mss 1440,nop,nop,sackOK>
11:21:01.645751 IP 63.215.26.146 > 224.0.0.1: igmp query v2
11:21:04.345768 IP 218.170.54.45.4794 > 4.240.51.251.445: S 959094122:959094122(0) win 16384 <mss 1440,nop,nop,sackOK>
11:21:11.645784 IP 63.215.26.146 > 224.0.0.1: igmp query v2
11:21:21.645807 IP 63.215.26.146 > 224.0.0.1: igmp query v2
11:21:44.965914 IP 4.240.90.11 > 4.240.51.251: icmp 8: echo request seq 60637
11:21:51.655947 IP 63.215.26.146 > 224.0.0.1: igmp query v2
11:21:54.517850 IP 4.240.51.251.32864 > 209.244.0.3.53: 57582+ AAAA? debian. (24)
11:21:54.665955 IP 209.244.0.3.53 > 4.240.51.251.32864: 57582 NXDomain 0/1/0 (99)
11:22:01.516021 IP 81.226.131.165.3480 > 4.240.51.251.445: S 1489231286:1489231286(0) win 64240 <mss 1460,nop,nop,sackOK>
11:22:21.666051 IP 63.215.26.146 > 224.0.0.1: igmp query v2
11:22:34.336168 IP 4.10.225.234.1181 > 4.240.51.251.135: S 893852055:893852055(0) win 64240 <mss 1460,nop,nop,sackOK>
11:22:37.106098 IP 4.10.225.234.1181 > 4.240.51.251.135: S 893852055:893852055(0) win 64240 <mss 1460,nop,nop,sackOK>
11:22:51.676167 IP 63.215.26.146 > 224.0.0.1: igmp query v2
21 packets captured
21 packets received by filter
0 packets dropped by kernel
debian3:/home/mmiller# poff
debian3:/home/mmiller#
Script done on Thu Aug 5 11:23:00 2004
Now here's a netstat script generated at the same time. I just kept re-executing the netstat
command, once before the connection started and a few times after. I'm not seeing any useful
foreign address info.
Code:
Script started on Thu Aug 5 11:18:02 2004
debian3:/home/mmiller# netstat. -anp
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 0.0.0.0:37 0.0.0.0:* LISTEN 316/inetd
tcp 0 0 0.0.0.0:968 0.0.0.0:* LISTEN 362/rpc.statd
tcp 0 0 0.0.0.0:9 0.0.0.0:* LISTEN 316/inetd
tcp 0 0 0.0.0.0:13 0.0.0.0:* LISTEN 316/inetd
tcp 0 0 0.0.0.0:111 0.0.0.0:* LISTEN 197/portmap
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 328/sshd
tcp 0 0 127.0.0.1:8118 0.0.0.0:* LISTEN 322/privoxy
tcp 0 0 127.0.0.1:25 0.0.0.0:* LISTEN 2201/exim4
tcp 0 0 192.168.1.3:22 192.168.1.1:33099 ESTABLISHED3434/1
tcp 0 0 192.168.1.3:22 192.168.1.1:33052 ESTABLISHED3416/sshd: mmiller
udp 0 0 0.0.0.0:9 0.0.0.0:* 316/inetd
udp 0 0 0.0.0.0:962 0.0.0.0:* 362/rpc.statd
udp 0 0 0.0.0.0:965 0.0.0.0:* 362/rpc.statd
udp 0 0 0.0.0.0:111 0.0.0.0:* 197/portmap
Active UNIX domain sockets (servers and established)
Proto RefCnt Flags Type State I-Node PID/Program name Path
unix 5 [ ] DGRAM 10909 1938/syslogd /dev/log
unix 2 [ ] DGRAM 14197 3474/pppd
unix 2 [ ] DGRAM 13924 3419/0
unix 3 [ ] STREAM CONNECTED 13923 3416/sshd: mmiller
unix 3 [ ] STREAM CONNECTED 13922 3419/0
unix 2 [ ] DGRAM 10802 1889/klogd
unix 2 [ ] DGRAM 482 362/rpc.statd
debian3:/home/mmiller# netstat -anp
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 0.0.0.0:37 0.0.0.0:* LISTEN 316/inetd
tcp 0 0 0.0.0.0:968 0.0.0.0:* LISTEN 362/rpc.statd
tcp 0 0 0.0.0.0:9 0.0.0.0:* LISTEN 316/inetd
tcp 0 0 0.0.0.0:13 0.0.0.0:* LISTEN 316/inetd
tcp 0 0 0.0.0.0:111 0.0.0.0:* LISTEN 197/portmap
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 328/sshd
tcp 0 0 127.0.0.1:8118 0.0.0.0:* LISTEN 322/privoxy
tcp 0 0 127.0.0.1:25 0.0.0.0:* LISTEN 2201/exim4
tcp 0 0 192.168.1.3:22 192.168.1.1:33099 ESTABLISHED3434/1
tcp 0 0 192.168.1.3:22 192.168.1.1:33052 ESTABLISHED3416/sshd: mmiller
udp 0 0 0.0.0.0:9 0.0.0.0:* 316/inetd
udp 0 0 0.0.0.0:962 0.0.0.0:* 362/rpc.statd
udp 0 0 0.0.0.0:965 0.0.0.0:* 362/rpc.statd
udp 0 0 0.0.0.0:111 0.0.0.0:* 197/portmap
Active UNIX domain sockets (servers and established)
Proto RefCnt Flags Type State I-Node PID/Program name Path
unix 5 [ ] DGRAM 10909 1938/syslogd /dev/log
unix 2 [ ] DGRAM 14197 3474/pppd
unix 2 [ ] DGRAM 13924 3419/0
unix 3 [ ] STREAM CONNECTED 13923 3416/sshd: mmiller
unix 3 [ ] STREAM CONNECTED 13922 3419/0
unix 2 [ ] DGRAM 10802 1889/klogd
unix 2 [ ] DGRAM 482 362/rpc.statd
debian3:/home/mmiller# netstat -anp
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 0.0.0.0:37 0.0.0.0:* LISTEN 316/inetd
tcp 0 0 0.0.0.0:968 0.0.0.0:* LISTEN 362/rpc.statd
tcp 0 0 0.0.0.0:9 0.0.0.0:* LISTEN 316/inetd
tcp 0 0 0.0.0.0:13 0.0.0.0:* LISTEN 316/inetd
tcp 0 0 0.0.0.0:111 0.0.0.0:* LISTEN 197/portmap
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 328/sshd
tcp 0 0 127.0.0.1:8118 0.0.0.0:* LISTEN 322/privoxy
tcp 0 0 127.0.0.1:25 0.0.0.0:* LISTEN 2201/exim4
tcp 0 0 192.168.1.3:22 192.168.1.1:33099 ESTABLISHED3434/1
tcp 0 0 192.168.1.3:22 192.168.1.1:33052 ESTABLISHED3416/sshd: mmiller
udp 0 0 0.0.0.0:9 0.0.0.0:* 316/inetd
udp 0 0 0.0.0.0:962 0.0.0.0:* 362/rpc.statd
udp 0 0 0.0.0.0:965 0.0.0.0:* 362/rpc.statd
udp 0 0 0.0.0.0:111 0.0.0.0:* 197/portmap
Active UNIX domain sockets (servers and established)
Proto RefCnt Flags Type State I-Node PID/Program name Path
unix 5 [ ] DGRAM 10909 1938/syslogd /dev/log
unix 2 [ ] DGRAM 14197 3474/pppd
unix 2 [ ] DGRAM 13924 3419/0
unix 3 [ ] STREAM CONNECTED 13923 3416/sshd: mmiller
unix 3 [ ] STREAM CONNECTED 13922 3419/0
unix 2 [ ] DGRAM 10802 1889/klogd
unix 2 [ ] DGRAM 482 362/rpc.statd
debian3:/home/mmiller# netstat -anp
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 0.0.0.0:37 0.0.0.0:* LISTEN 316/inetd
tcp 0 0 0.0.0.0:968 0.0.0.0:* LISTEN 362/rpc.statd
tcp 0 0 0.0.0.0:9 0.0.0.0:* LISTEN 316/inetd
tcp 0 0 0.0.0.0:13 0.0.0.0:* LISTEN 316/inetd
tcp 0 0 0.0.0.0:111 0.0.0.0:* LISTEN 197/portmap
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 328/sshd
tcp 0 0 127.0.0.1:8118 0.0.0.0:* LISTEN 322/privoxy
tcp 0 0 127.0.0.1:25 0.0.0.0:* LISTEN 2201/exim4
tcp 0 0 192.168.1.3:22 192.168.1.1:33099 ESTABLISHED3434/1
tcp 0 0 192.168.1.3:22 192.168.1.1:33052 ESTABLISHED3416/sshd: mmiller
udp 0 0 0.0.0.0:9 0.0.0.0:* 316/inetd
udp 0 0 0.0.0.0:962 0.0.0.0:* 362/rpc.statd
udp 0 0 0.0.0.0:965 0.0.0.0:* 362/rpc.statd
udp 0 0 0.0.0.0:111 0.0.0.0:* 197/portmap
Active UNIX domain sockets (servers and established)
Proto RefCnt Flags Type State I-Node PID/Program name Path
unix 5 [ ] DGRAM 10909 1938/syslogd /dev/log
unix 2 [ ] DGRAM 14197 3474/pppd
unix 2 [ ] DGRAM 13924 3419/0
unix 3 [ ] STREAM CONNECTED 13923 3416/sshd: mmiller
unix 3 [ ] STREAM CONNECTED 13922 3419/0
unix 2 [ ] DGRAM 10802 1889/klogd
unix 2 [ ] DGRAM 482 362/rpc.statd
debian3:/home/mmiller# netstat -anp
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 0.0.0.0:37 0.0.0.0:* LISTEN 316/inetd
tcp 0 0 0.0.0.0:968 0.0.0.0:* LISTEN 362/rpc.statd
tcp 0 0 0.0.0.0:9 0.0.0.0:* LISTEN 316/inetd
tcp 0 0 0.0.0.0:13 0.0.0.0:* LISTEN 316/inetd
tcp 0 0 0.0.0.0:111 0.0.0.0:* LISTEN 197/portmap
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 328/sshd
tcp 0 0 127.0.0.1:8118 0.0.0.0:* LISTEN 322/privoxy
tcp 0 0 127.0.0.1:25 0.0.0.0:* LISTEN 2201/exim4
tcp 0 0 192.168.1.3:22 192.168.1.1:33099 ESTABLISHED3434/1
tcp 0 0 192.168.1.3:22 192.168.1.1:33052 ESTABLISHED3416/sshd: mmiller
udp 0 0 0.0.0.0:9 0.0.0.0:* 316/inetd
udp 0 0 0.0.0.0:962 0.0.0.0:* 362/rpc.statd
udp 0 0 0.0.0.0:965 0.0.0.0:* 362/rpc.statd
udp 0 0 0.0.0.0:111 0.0.0.0:* 197/portmap
Active UNIX domain sockets (servers and established)
Proto RefCnt Flags Type State I-Node PID/Program name Path
unix 5 [ ] DGRAM 10909 1938/syslogd /dev/log
unix 2 [ ] DGRAM 14197 3474/pppd
unix 2 [ ] DGRAM 13924 3419/0
unix 3 [ ] STREAM CONNECTED 13923 3416/sshd: mmiller
unix 3 [ ] STREAM CONNECTED 13922 3419/0
unix 2 [ ] DGRAM 10802 1889/klogd
unix 2 [ ] DGRAM 482 362/rpc.statd
debian3:/home/mmiller#
Script done on Thu Aug 5 11:23:02 2004
|