LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-11-2003, 01:39 AM   #1
ivanatora
Member
 
Registered: Sep 2003
Location: Bulgaria
Distribution: Ubuntu 9.10, FreeBSD 7.2
Posts: 459

Rep: Reputation: 32
Strange port opened


I have a firewall, that filters almost all of my open ports.. It may be better just to stop the appropriate services that require these porst, but I didn't find how to. Today when I nmaped myself I got the following:
Code:
Interesting ports on  (192.168.1.115):
(The 1592 ports scanned but not shown below are in state: closed)
Port       State       Service
21/tcp     filtered    ftp
22/tcp     open        ssh
37/tcp     filtered    time
79/tcp     filtered    finger
111/tcp    filtered    sunrpc
113/tcp    filtered    auth
1024/tcp   filtered    kdm
1387/tcp   open        cadsi-lm
6000/tcp   filtered    X11
What is that 1387 port? What is cadsi-lm? Where did it appeared from!?
 
Old 11-11-2003, 02:02 AM   #2
markus1982
Senior Member
 
Registered: Aug 2002
Location: Stuttgart (Germany)
Distribution: Debian/GNU Linux
Posts: 1,467

Rep: Reputation: 46
Do you really require finger, sunrpc? I would suggest you disable those services.
 
Old 11-11-2003, 07:13 AM   #3
ivanatora
Member
 
Registered: Sep 2003
Location: Bulgaria
Distribution: Ubuntu 9.10, FreeBSD 7.2
Posts: 459

Original Poster
Rep: Reputation: 32
How? By commenting them in /etc/services? Will that really disable them?
Btw, after reboot the strange port didn't appear.. strange..
 
Old 11-11-2003, 10:18 AM   #4
cyph3r7
Member
 
Registered: Apr 2003
Location: Silicon Valley East, Northern Virginia
Distribution: FreeBSD,Debian, RH, ok well most of em...
Posts: 238

Rep: Reputation: 30
yes and by checking your rc.X and removing them...also

cadsi-lm 1387/tcp Computer Aided Design Software Inc LM
cadsi-lm 1387/udp Computer Aided Design Software Inc LM

not sure if a trojan runs on these also but this is what that port is known for.
 
Old 11-11-2003, 10:57 AM   #5
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
One thing to keep in mind. The ports over 1024 are often dynamically assigned, meaning that any number of services could be using that port. Nmap simply uses a list of common port assignments to designate which service is using that port (unless you have recently upgraded to the brand new version of nmap). It could very well have been something like an established ssh or http connection. If you continue to see that port open after subsequent reboots or other strange activity, then you should be concerned. If your still paranoid about rootkits, try running chkrootkit.

Also, using nmap to scan yourself isn't the most reliable way to check your security, try using nmap from another machine outside your LAN for a more accurate scan.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Strange port scan results sbogus Linux - Security 16 06-29-2004 02:25 AM
strange service running ... open port shadow.blue Slackware 12 04-16-2004 05:42 PM
strange vmlinuz when opened in pico mipia Slackware 5 07-23-2003 03:31 AM
how is a tcp port opened? Kayaker Linux - Security 7 05-12-2003 12:47 AM
Can port 25 be opened without a SMTP server installed? greenranger Linux - Networking 2 04-05-2003 05:26 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:56 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration