LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-21-2004, 05:24 AM   #1
J_Szucs
Senior Member
 
Registered: Nov 2001
Location: Budapest, Hungary
Distribution: SuSE 6.4-11.3, Dsl linux, FreeBSD 4.3-6.2, Mandrake 8.2, Redhat, UHU, Debian Etch
Posts: 1,126

Rep: Reputation: 58
Portscan to port 6000?


There is a forum at a reputed Hungarian portal which suddenly became unavailable to our users.

Digging into the problem, I found that the reason why the Hungarian forum became unreachable is that my portscan detection script automatically denied IP address 128.59.19.58 as it sent us a tcp SYN package to port 6000.

The port scanning IP address belongs to a university, in the US.

Do you know any legal reasons why a foreign computer in the US scans yours port 6000 when you visit a forum in Hungary?
(and the Hungarian forum becomes unreachable when you deny that IP address)

What can be the reason?

Last edited by J_Szucs; 09-21-2004 at 05:37 AM.
 
Old 09-21-2004, 10:46 AM   #2
joe83
Member
 
Registered: Sep 2003
Location: Kennesaw GA
Distribution: Slackware-current , Slack81Zip, Smoothwall v2
Posts: 427

Rep: Reputation: 31
Thumbs down

Port 6000 if I'm not mistaken is for remote access to the X server.
So apparently someone is trying to access your system.
Everything I have read about security regarding this port is that it is a good idea to keep it closed . Don't know any specific legalities
regarding this, but my personal policy regarding people who scan/ try to access my system without permission is to assume they are doing so with bad intentions and respond accordingly.



 
Old 09-21-2004, 11:27 AM   #3
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
Yes, port 6000/TCP is the default port for display :0 when listening for TCP connections. If some site automatically tries to probe your IP when you connect to it, the intentions are almost certainly bad. The one case where this routinely happens is when connecting to IRC. Because of all the IRC wars, many ircd operators have modified their daemons to initiate a portscan against an IP before allowing the connection. If the IP has any exploitable services running, it won't allow the connection (because either the user is going to get owned by IRC kiddies, or because the host could very well be a zombie that's already owned and is dialing home).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Disable port 6000 hegrunt Linux - Software 4 09-08-2003 12:49 PM
port 6000 pottsie Linux - Security 6 04-23-2003 04:06 AM
port 6000, how to close it? neo77777 Linux - Security 2 05-16-2002 10:41 PM
Port 6000 sitrus Linux - Security 4 12-15-2001 03:25 AM
Port 6000 an xwindows saavik Linux - Networking 8 11-09-2001 12:08 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:55 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration