LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-04-2007, 11:47 AM   #1
slackhack
Senior Member
 
Registered: Jun 2004
Distribution: Arch, Debian, Slack
Posts: 1,016

Rep: Reputation: 47
Why would snort logs show portscan/portsweep


from my computer to an external IP? is that a sure sign that i've been compromised and someone is conducting hacking procedures from my box? Or could it just be some application (e.g., torrent client) scanning for a port to connect to?

Last edited by slackhack; 09-04-2007 at 11:49 AM.
 
Old 09-04-2007, 12:08 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Did you verify the integrity of your box?
Did you check what apps are using the network?
What does Snort report *exactly*?
How is Snort configured?
 
Old 09-04-2007, 05:42 PM   #3
slackhack
Senior Member
 
Registered: Jun 2004
Distribution: Arch, Debian, Slack
Posts: 1,016

Original Poster
Rep: Reputation: 47
I don't see anything unusual in any of the logs. There doesn't seem to be any strange or excessive traffic. Disk space and resources usage looks normal. Apps using the network are ntp, nfs, ssh, and bittornado, with very light apache and ftp usage.

snort is configured for just the services I use. It's reporting like this

Code:
Events from same host to same destination using same method
=========================================================================
 # of  from             to               method
=========================================================================



    4  192.168.0.123    71.203.231.246   (portscan) TCP Portsweep
    3  192.168.0.123    70.160.58.224    (portscan) TCP Portsweep
    2  192.168.0.123    69.143.45.51     (portscan) TCP Portsweep
    2  66.82.16.34      192.168.0.123    ICMP Destination Unreachable Communication
+Administratively Prohibited
    2  192.168.0.123    76.104.218.201   (portscan) TCP Portsweep
I'm thinking it must just be a false positive from the torrents or maybe ntp?

Last edited by slackhack; 09-04-2007 at 05:43 PM.
 
Old 09-05-2007, 11:39 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
No, certainly not NTP. About Bittorrent outbound I don't know, I use a BPF source filter. I do see Snort report scan FP's for Bittorrent but that's only inbound and not those alert ID's. You could run tcpdump for a period and dissect it with Wireshark.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Snort detecting "TCP Portsweep" from local machine to internet IBall Linux - Security 2 10-22-2006 05:46 AM
SNORT - (portscan) UDP Portsweep ddaas Linux - Security 2 07-06-2005 02:24 AM
Reading SNORT Logs WarlockofVirgo Linux - Networking 1 08-13-2004 09:24 AM
Reading Snort logs bigdogg Linux - Software 0 10-27-2003 03:22 PM
What do these snort logs mean? tarballedtux Linux - Security 1 08-31-2002 10:15 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:40 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration