LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-19-2006, 04:09 AM   #1
gabsik
Member
 
Registered: Dec 2005
Location: This planet
Distribution: Debian,Xubuntu
Posts: 567

Rep: Reputation: 30
113 danger ???


Somewhere i found packets generated by 113 identd are of some danger.Can someone point me details about this also because i often get this in my logs:
Code:
Jul 19 10:20:08 argo NOPASSARAN: IN=eth0 OUT= MAC=00:40:f4:7a:58:25:00:09:5b:b0:3c:a2:08:00  SRC=x.x.x.x DST=192.168.0.2 LEN=71 TOS=00 PREC=0x00 TTL=49 ID=51326 CE DF PROTO=TCP SPT=113 DPT=35345 SEQ=4220458516 ACK=281092887 WINDOW=5840 ACK PSH URGP=0
Jul 19 10:20:08 argo NOPASSARAN: IN=eth0 OUT= MAC=00:40:f4:7a:58:25:00:09:5b:b0:3c:a2:08:00  SRC=x.x.x.x DST=192.168.0.2 LEN=40 TOS=00 PREC=0x00 TTL=49 ID=51328 CE DF PROTO=TCP SPT=113 DPT=35345 SEQ=4220458547 ACK=281092887 WINDOW=5840 ACK FIN URGP=0
Jul 19 10:20:11 argo NOPASSARAN: IN=eth0 OUT= MAC=00:40:f4:7a:58:25:00:09:5b:b0:3c:a2:08:00  SRC=x.x.x.x DST=192.168.0.2 LEN=71 TOS=00 PREC=0x00 TTL=49 ID=51330 CE DF PROTO=TCP SPT=113 DPT=35345 SEQ=4220458516 ACK=281092887 WINDOW=5840 ACK PSH FIN URGP=0
Thanks !!!!

Last edited by gabsik; 07-19-2006 at 04:10 AM.
 
Old 07-20-2006, 06:09 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Somewhere i found packets generated by 113 identd are of some danger.
Where's that?

Identd could be used to disclose information about users on the system and old distribution releases contained an identd that could be compromised or DoSsed (check CVE/NVD vulnerability databases). Generally the service is considered deprecated and AFAIK is only used by MTA's and for IRC. If TCP/113 is needed for MTA then AFAIK a --reject-with tcp-reset rule could speed up auth. Else there are identd that are hardened and only hand out fake information. See your distributions repo's, SecurityFocus, Linuxsecurity or Freshmeat or Sourceforge.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Danger, Danger, Danger. Dead Rat Killed My Slack vdemuth General 2 07-12-2004 03:54 PM
xhost + am I in danger? arpi Linux - Software 2 06-12-2004 09:38 PM
Will my Windows XP be in danger? J_angel2000 Linux - Newbie 4 02-22-2004 09:06 PM
Free linux is in danger! Swift&Smart Linux - Software 2 11-20-2003 10:30 AM
Danger newbie about Dailydesign Linux - Software 6 06-08-2003 06:24 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:08 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration