Identify client process initiating TCP connection port 113
From my firewall logs, I've got a process n a Centos host attempting to initiate a connection to the auth daemon (which isn't running) on another server. In order to clean things up, I'd like to identify which process is periodically making this attempt, and stop it.
I've been playing around with "watch" and "ss" but so far, to no avail. I can see the calls with tcpdump, but can't track the process ID back to a process.
Has anyone got any ideas for a way to identify the process, given that it's an intermittent attempt?
|