LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-08-2009, 09:16 AM   #1
satishmali1983
LQ Newbie
 
Registered: Mar 2009
Distribution: Mandriva 2008.0
Posts: 21

Rep: Reputation: 16
My IP address get Blacklisted


Hello
I ma mandriva 2008.0 Linux system
Before few days My IP get blacklisted
I am new in linux & don't know how to analysis this problem
plz help me to sort out this problem.
My linux server is NAT server from which we are using internet to other m/c, qmail server is there but it is for local use within subnet only.

This is my nmap output, plz help me to analysis this issue & guide what port need to close to avoid any attacks or spams.

tarting Nmap 4.20 ( http://insecure.org ) at 2009-04-08 17:56 IST
Initiating SYN Stealth Scan at 17:56
Scanning livetekindia.com (192.168.10.2) [1697 ports]
Discovered open port 22/tcp on 192.168.10.2
Discovered open port 21/tcp on 192.168.10.2
Discovered open port 53/tcp on 192.168.10.2
Discovered open port 23/tcp on 192.168.10.2
Discovered open port 25/tcp on 192.168.10.2
Discovered open port 443/tcp on 192.168.10.2
Discovered open port 80/tcp on 192.168.10.2
Discovered open port 106/tcp on 192.168.10.2
Discovered open port 3128/tcp on 192.168.10.2
Discovered open port 993/tcp on 192.168.10.2
Discovered open port 445/tcp on 192.168.10.2
Discovered open port 6000/tcp on 192.168.10.2
Discovered open port 143/tcp on 192.168.10.2
Discovered open port 8080/tcp on 192.168.10.2
Discovered open port 110/tcp on 192.168.10.2
Discovered open port 139/tcp on 192.168.10.2
Discovered open port 1241/tcp on 192.168.10.2
Completed SYN Stealth Scan at 17:56, 0.11s elapsed (1697 total ports)


PORT STATE SERVICE VERSION
21/tcp open ftp ProFTPD 1.3.2
22/tcp open ssh OpenSSH 4.7 (protocol 2.0)
23/tcp open telnet BSD-derived telnetd
25/tcp open smtp qmail smtpd
53/tcp open domain ISC Bind dnsmasq-2.39
80/tcp open http Apache httpd 2.2.6 ((Mandriva Linux/PREFORK-8.2mdv2008.0))
106/tcp open tcpwrapped
110/tcp open pop3 qmail pop3d
139/tcp open netbios-ssn Samba smbd 3.X (workgroup: LINUXRT)
143/tcp open imap Courier Imapd (released 2005)
443/tcp open ssl/http Apache httpd 2.2.6 ((Mandriva Linux/PREFORK-8.2mdv2008.0))
445/tcp open netbios-ssn Samba smbd 3.X (workgroup: LINUXRT)
993/tcp open ssl/imap Courier Imapd (released 2005)
1241/tcp open ssl/unknown
3128/tcp open http-proxy Squid webproxy 2.6.STABLE16
6000/tcp open X11 (access denied)
8080/tcp open http Apache httpd 2.2.6 ((Mandriva Linux/PREFORK-8.2mdv2008.0))
 
Old 04-08-2009, 09:30 AM   #2
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,636

Rep: Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965
Quote:
Originally Posted by satishmali1983 View Post
Hello
I ma mandriva 2008.0 Linux system
Before few days My IP get blacklisted
I am new in linux & don't know how to analysis this problem
plz help me to sort out this problem.
My linux server is NAT server from which we are using internet to other m/c, qmail server is there but it is for local use within subnet only.

This is my nmap output, plz help me to analysis this issue & guide what port need to close to avoid any attacks or spams.
Please write and spell clearly...your question is very hard to understand, especially with the 'shorthand' words.

You say your system gets blacklisted...from what, by whom? What are you running on the system? Is it blacklisted totally, and won't connect to ANYTHING, or are you just denied some sites? Or is it just blacklisted for email?

Also, you say "we are using internet to other m/c"? What does that mean?
 
Old 04-08-2009, 09:47 AM   #3
satishmali1983
LQ Newbie
 
Registered: Mar 2009
Distribution: Mandriva 2008.0
Posts: 21

Original Poster
Rep: Reputation: 16
Thanks to give attention to problem. r u there to help me on line?
 
Old 04-08-2009, 10:02 AM   #4
farslayer
LQ Guru
 
Registered: Oct 2005
Location: Northeast Ohio
Distribution: linuxdebian
Posts: 7,249
Blog Entries: 5

Rep: Reputation: 191Reputation: 191
All help here is done through the forums..
You could start by clarifying the issue/question as TBOne requested..
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Ip blacklisted ayush1440 Linux - Server 3 05-05-2008 06:04 AM
gcc is blacklisted? xbill311x Linux - Software 2 12-22-2005 02:58 PM
Blacklisted Mail Server IP dlublink Linux - Networking 1 02-02-2005 01:47 PM
blacklisted slack66 Linux - Security 2 09-29-2003 04:20 AM
Is Linuxconf Blacklisted????? naveed Programming 2 05-01-2001 08:15 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:26 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration