LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-22-2009, 01:47 PM   #1
thedoobie
LQ Newbie
 
Registered: Jul 2009
Distribution: Ubuntu
Posts: 5

Rep: Reputation: 0
unhide complains about hidden ports not found in netstat


I have an Ubuntu server that is only accessible on my home network (i.e., no port forwarding from router and iptables restricts to local network ip addresses). I recently installed chkrootkit, rkhunter, and unhide. I just received an email notification from unhide with the following:
Code:
Starting TCP checking

Found Hidden port that not appears in netstat: 1
Found Hidden port that not appears in netstat: 2
Found Hidden port that not appears in netstat: 3
Found Hidden port that not appears in netstat: 4
Found Hidden port that not appears in netstat: 5
...
I do not know what this means and can not find any good information about hidden ports. I have iptables that basically only allows ssh from local network ip addresses, outgoing mail, and apt-get. Should I be concerned about this and what should I do to solve this problem? Any ideas?
 
Old 07-22-2009, 04:24 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Unhide basically runs 'netstat' to get a list of ports in use then tries to figure out if a port is already in use. Did you compile "unhide" yourself or did you install a binary (and then from where)? If you installed a binary, does running a self compiled version improve? Did you ran 'unhide-tcp' under an earlier kernel version without problems? What kernel version do you run now? Else, are all your ports marked as hidden? What networked services is the machine running? What happens if you shut them down one at a time and eacht time after you shut it down run 'unhide-tcp'? If after you shut down all networked services (webserver, any network filesystem sharing, SSH, FTP, caching nameserver, nscd) there still is no difference, does also shutting down your network connection show a difference? If nothing makes a difference I suggest you email yjesus at security-projects dot com your strace.log from running 'strace -v -o /tmp/strace.log /path/to/unhide-tcp', he usually responds back pretty quick.
 
Old 07-28-2009, 12:22 PM   #3
benteveo
LQ Newbie
 
Registered: Jul 2009
Distribution: Ubuntu
Posts: 2

Rep: Reputation: 0
The reason you get this is that ports 1 to 1023 are privileged ports and accessible only to root (superuser).

Try to run unhide-tcp as superuser:

$ sudo unhide-tcp

To get rid of these alerts.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to unhide hidden partitions? Larry Webb Linux - General 6 06-04-2007 03:29 PM
inetd is running but netstat show no listening ports shroc Linux - Networking 1 01-31-2006 04:30 PM
NTFS partition got hidden, how to unhide? Whyaken Linux - Newbie 4 03-22-2005 07:44 PM
pygtk install found 2 versions of glib and complains Kanaflloric Linux - Software 1 09-28-2004 04:46 AM
netstat did not display ports used ethanchic Linux From Scratch 2 08-06-2002 05:23 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:19 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration