LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-05-2006, 09:18 AM   #1
ejkeebler
LQ Newbie
 
Registered: May 2004
Posts: 14

Rep: Reputation: 0
a port scan ran from my pc


i noticed that a port scan ran from my pc, what do i need to check for to make sure i fix this security hole?

I reset the user account password they used (mythtv). but not sure if they somehow managed to get my root password. I have a wireless router, with only a few ports opened, for mythtv, remote desktop, etc. I dont broadcast my ssid, and have wep enabled, there does not seem to be any new services running from my linux box. then again, i really have no idea what to look for.

Any help would be greatly appreciated.

Thanks
 
Old 05-05-2006, 01:40 PM   #2
ataraxia
Member
 
Registered: Apr 2006
Location: Pittsburgh
Distribution: Debian Sid AMD64
Posts: 296

Rep: Reputation: 30
Once a machine has been compromised, I wouldn't trust it no matter how much you can check for. Best to just reinstall it, and reinstall your data from backup.
 
Old 05-05-2006, 01:49 PM   #3
raskin
Senior Member
 
Registered: Sep 2005
Location: France
Distribution: approximately NixOS (http://nixos.org)
Posts: 1,900

Rep: Reputation: 69
What is source of confidence that scan was from that machine, and not just masquaraded?
 
Old 05-05-2006, 02:08 PM   #4
ejkeebler
LQ Newbie
 
Registered: May 2004
Posts: 14

Original Poster
Rep: Reputation: 0
when i look in my history i see several entries that i did not type in that are suspect i.e

./start 80.52
./start 80.53
./start 80.54
./start 62.40
./start 62.41

etc, etc, etc and also an entry of paypal.php, i can also see a website where the app seems to have been downloaded. etc.
 
Old 05-05-2006, 02:12 PM   #5
raskin
Senior Member
 
Registered: Sep 2005
Location: France
Distribution: approximately NixOS (http://nixos.org)
Posts: 1,900

Rep: Reputation: 69
Then I tend to agree with the idea to reinstall.
 
Old 05-05-2006, 02:14 PM   #6
ejkeebler
LQ Newbie
 
Registered: May 2004
Posts: 14

Original Poster
Rep: Reputation: 0
thanks

not the answer i was hoping for, but thats what i get for being lazy! thanks againg for the advice.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
mysqld running and reading for connections on port 3306, no port 3306 found from scan darkenigmaa Linux - Networking 10 07-13-2016 11:53 AM
Port Scan: Closed Port instead of Stealth unihiekka Linux - Security 9 12-26-2005 08:51 PM
Ran a virus scan, please look at.. webwolf70 Linux - Security 3 01-29-2005 11:54 PM
port scan Tigger Linux - Security 18 06-08-2003 05:44 PM
Port scan luser Linux - Networking 4 10-11-2002 01:37 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:26 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration