LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Closed Thread
  Search this Thread
Old 07-28-2008, 01:43 PM   #1
jfroot
LQ Newbie
 
Registered: Jul 2008
Posts: 3

Rep: Reputation: 0
XPOST: Ports between 59873 and 60000 used by mystery process.


This was originally posted in the Red Hat sub-forum. However I do not think this is a 'Red Hat' issue anymore and something more general.

For some reason I cannot bind any listening process to any port between 59872 and 60001.

I'll use nc for an example:

# nc -l 59872
.. works and listens ...

# nc -l 59873
nc: Address already in use

... < all ports in between> ...

# nc -l 60000
nc: Address already in use

# nc -l 60001
.. works and listens ...

So the obvious thing to check is netstat -nap.. Nothing on any of those ports listed. Next.. lsof.. also shows nothing on those ports listed.

So I thought maybe some trojan has taken over 128 of my ports.. so I ran rkhunter and chkrootkit and they had no results. This box is not even on the net so trojaning is unlikely. And I've never seen or heard of a trojan that takes over 128 ports. But maybe I'm uninformed?

SeLinux is disabled also.

Now I'm at a loss.. does anyone have any ideas? Is it some kernel thing holding onto some high ports for outgoing use?

# cat /proc/sys/net/ipv4/ip_local_port_range
32768 55000
(I lowered it to 55000 just to make sure that wasnt the issue)

BOX is: Red Hat Enterprise Linux Server release 5.1 (Tikanga)
Kernel: 2.6.18-53.1.14.el5 #1 SMP Tue Feb 19 07:18:46 EST 2008 x86_64 x86_64 x86_64 GNU/Linux

Rebooting has no effect, ports are still used. Even un runlevel 1 the ports are used.
 
Old 07-28-2008, 01:55 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Please post your thread in only one forum. Posting a single thread in the most relevant forum will make it easier for members to help you and will keep the discussion in one place. This thread is being closed because it is a duplicate of http://www.linuxquestions.org/questi...-60000-658298/.

You're relatively new to LQ so you may not know that by using the report button you can request moving a thread to another forum if you find it would be more appropriate there. So next time please use that procedure. Since your previous thread has replies already which are not completely acted upon (at least not posted back wrt LKML) I would appreciate it if you continue there for the time being, this post will then serve as a redirect there.
 
  


Closed Thread

Tags
help, trojan



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Cannot bind to any port between 59873 and 60000 jfroot Red Hat 4 07-28-2008 12:12 PM
how to know what are all the ports are available and which process is using that cyber.juggernaut Linux - Networking 2 02-21-2006 12:48 PM
Mystery process appearing: CROND The MCP Linux - Security 3 10-12-2005 06:57 PM
Internet-Process Id,ports related jared78 Linux - Networking 6 05-19-2005 02:44 AM
mystery process sopiaz57 Linux - Security 3 11-12-2003 12:36 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:32 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration