LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-13-2011, 09:13 AM   #1
dman777
Member
 
Registered: Dec 2010
Distribution: Gentoo
Posts: 232

Rep: Reputation: 8
Is my system being hacked with port switch/fowarded?


Code:
localhost one # lsof -i
COMMAND   PID     USER   FD   TYPE DEVICE SIZE/OFF NODE NAME
irssi    6950      one    3u  IPv4   6103      0t0  TCP 192.168.1.23:45636->card.freenode.net:ircd (ESTABLISHED)
java     7378 subsonic   68u  IPv4  11795      0t0  UDP *:1901 
java     7378 subsonic   72u  IPv4  11812      0t0  TCP *:43167 (LISTEN)
java     7378 subsonic   73u  IPv4  11813      0t0  TCP *:bzr (LISTEN)
java     7378 subsonic   76u  IPv4  11815      0t0  TCP *:9412 (LISTEN)
java     7378 subsonic   77u  IPv4  11816      0t0  TCP *:35443 (LISTEN)
java     7378 subsonic   78u  IPv4  13506      0t0  TCP 192.168.1.23:bzr->216-82-212-222.static.grandenetworks.net:47115 (ESTABLISHED)
java     7378 subsonic   79u  IPv4  13508      0t0  TCP 192.168.1.23:bzr->216-82-212-222.static.grandenetworks.net:47742 (ESTABLISHED)
localhost one #
I run a music server on my pc called Subsonic that runs in java. With it I can stream music from my pc to my phone through 3g.

Why is there a name called bzr listed as a port in:
Code:
java     7378 subsonic   73u  IPv4  11813      0t0  TCP *:bzr (LISTEN)
and I have:

Code:
java     7378 subsonic   78u  IPv4  13506      0t0  TCP 192.168.1.23:bzr->216-82-212-222.static.grandenetworks.net:47115 (ESTABLISHED)
java     7378 subsonic   79u  IPv4  13508      0t0  TCP

It kinda looks like my system is hacked with a port switch/forwarded.
 
Old 05-13-2011, 09:25 AM   #2
nomb
Member
 
Registered: Jan 2006
Distribution: Debian Testing
Posts: 675

Rep: Reputation: 58
Do you have something called bazaar installed?
 
Old 05-14-2011, 01:53 AM   #3
dman777
Member
 
Registered: Dec 2010
Distribution: Gentoo
Posts: 232

Original Poster
Rep: Reputation: 8
Ya, and I see that port 4155 is used for bzr which I sat my port number to for subsonic. Strange that wasn't listed in /etc/services. I guess this explains it. I never manually installed bazaar though(gentoo)...so I wonder why it's on my system.
 
Old 05-14-2011, 02:16 AM   #4
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682
It might not be installed. lsof may have it's own internal list of well known ports and substitute it for the port number. The command listed is 'java'.
 
Old 05-14-2011, 03:40 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by jschiwal View Post
lsof may have it's own internal list of well known ports and substitute it for the port number.
The standard "database" system utilities query for resolving port names is /etc/services. Running listings with at least the "-n" flag (as in 'netstat -an', 'lsof -Pwln', 'ls -aln') provides cleaner output, can less easily be misinterpreted and avoids any speed issues due to any form of resolution.
 
1 members found this post helpful.
Old 05-14-2011, 05:28 AM   #6
dman777
Member
 
Registered: Dec 2010
Distribution: Gentoo
Posts: 232

Original Poster
Rep: Reputation: 8
That's what is kind of throwing me off...bzr isn't listed in /etc/services. Seems like it should be.
 
Old 05-14-2011, 05:44 AM   #7
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Odd (but not as odd as me not reading the thread right, sorry ;-p). Revision 2830 of trunk/etc/services states TCP/4155 was added back in 2007...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: LD Port Report Project aka Switch Port Mapper Tool LXer Syndicated Linux News 0 05-10-2009 07:11 PM
my system has been hacked, please advise ? fenrire Linux - Security 4 04-14-2007 12:38 PM
Got Hacked... fedora is keep sending stuff out at port 6664 woranl Linux - Security 19 12-26-2005 05:31 PM
log system hacked? mikechao Linux - Security 3 09-14-2005 10:46 PM
RH 8.0 system hacked sandalblady Linux - Security 4 07-03-2004 02:59 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:42 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration