LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-19-2003, 07:51 AM   #1
gbg
Member
 
Registered: Aug 2003
Location: Lisbon Portugal
Distribution: Red Hat 9
Posts: 55

Rep: Reputation: 15
Angry about 4 requests/sec on port 4662


Hello There!

I'm running a firewall software on my redhat 9 machine (Firestarter) and I've noticed that i have about 4 requests per second on port 4662 from internet. That should not be a problem, but this causes a consuption of about 10% of CPU and more. Any any to prevent this?

10x.
 
Old 08-19-2003, 10:08 PM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
I would just use Firestarter to add a firewall rule to block that traffic. Port 4662 is eDonkey traffic, so you can safely DROP all the packets destined for port 4662 without being too worried about losing legitimate traffic. Blocking ~4requests/s shouldn't really consume alot of resources.
 
Old 08-21-2003, 11:47 AM   #3
gbg
Member
 
Registered: Aug 2003
Location: Lisbon Portugal
Distribution: Red Hat 9
Posts: 55

Original Poster
Rep: Reputation: 15
yeh. that worked fine, but now I have another 1000 requests to another 1000 ports... GRRR.
10x!
 
Old 08-21-2003, 05:24 PM   #4
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Hmmmmm. Are they all from the same ip address(es)? It could be that you have some P2P software somewhere on your network. Alot of the newer ones can be nasty in that if the default ports are blocked they will scan all your ports looking for an open alternative. Check and see if you have any users behind the firewall that have installed any P2P clients. If the requests come from a few unique ip addresses then you can specifically DROP traffic from those ip addresses.
 
Old 08-21-2003, 06:09 PM   #5
gbg
Member
 
Registered: Aug 2003
Location: Lisbon Portugal
Distribution: Red Hat 9
Posts: 55

Original Poster
Rep: Reputation: 15
yep. i have a client on the network running kazaa. i'll do that. thanx.
 
Old 08-21-2003, 06:14 PM   #6
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Damn users. Can't admin with them and you can't beat them to death with their keyboard.
Good Luck!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Mandrake 10 Internet very slow (<1kb/sec) while windows got 50k/sec SafeTechs Mandriva 13 09-01-2006 04:07 PM
Proxy server flodded by requests on port 53 & port 25 saurabh_sahni Linux - Security 5 04-26-2005 10:35 PM
Proxy server flodded by requests on port 53 & port 25 saurabh_sahni Linux - Networking 1 04-26-2005 03:01 PM
web page accessing port 4662 before allowing connect? skog Slackware 2 03-12-2004 02:38 PM
4662 port? Rex_chaos Linux - Networking 2 03-17-2003 02:56 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:41 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration