LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-29-2002, 11:03 AM   #1
haknot
LQ Newbie
 
Registered: Feb 2001
Location: South Carolina
Distribution: Redhat 7.1, 6.2
Posts: 16

Rep: Reputation: 0
subseven port 1234 firewall hits


I just recently got a firewall configured and am trying to learn what the info it provides really means. The last day or two I've gotten a series of hits id'd in the log as sub7 on port 1234. This mornings series were reported as from host bama-live.webnet.advance.net. Is this a common thing? Does it mean that a server at that location is infected with the trojan sub7? How to interpret this info? I've searched the internet, got some info about what sub7 is and does. But how would you know if you were infected/invaded by the thing?
 
Old 01-29-2002, 11:57 AM   #2
kill-hup
Member
 
Registered: Aug 2000
Location: NY - USA
Distribution: Slackware
Posts: 109

Rep: Reputation: 15
As long as your box isn't listening for connections on port 1234 (or any out of the oridinary ports), it's more likely that the remote host was just checking to see if your box was running sub7 and the firewall caught the probe.
 
Old 01-30-2002, 03:22 AM   #3
raz
Member
 
Registered: Apr 2001
Location: London
Posts: 408

Rep: Reputation: 31
Show me an example of the firewall log and I'll translate it for you.

/Raz
 
Old 01-30-2002, 04:33 PM   #4
haknot
LQ Newbie
 
Registered: Feb 2001
Location: South Carolina
Distribution: Redhat 7.1, 6.2
Posts: 16

Original Poster
Rep: Reputation: 0
Like this?

1234 207.155.252.9 subseven Jan 30 10:48:29
1234 207.155.252.9 subseven Jan 30 10:48:31
1234 207.155.252.9 subseven Jan 30 10:48:33

This is a sample from the hit list. I don't know if that's what you meant. The firewall is Firestarter.
 
Old 01-31-2002, 08:35 AM   #5
raz
Member
 
Registered: Apr 2001
Location: London
Posts: 408

Rep: Reputation: 31
Your firewall log doesn't seem to give much info.
but kill-hup's correct looks like a subseven scan.

/raz
 
Old 01-31-2002, 09:16 AM   #6
haknot
LQ Newbie
 
Registered: Feb 2001
Location: South Carolina
Distribution: Redhat 7.1, 6.2
Posts: 16

Original Poster
Rep: Reputation: 0
thanks for your info

These sub7 scans and another set that are id'd as trin00 come from the server for a set of forums that I visit. Would they be scanning these ports for some good reason, or does this indicate someone using their servers for malicious purposes? Oh yes, another set of hits from the same server is on the nfs port. All are suspect, eh?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Why So Many Hits on port 25 Tonight ?!? opioid General 1 08-14-2004 02:18 AM
subseven opening ports saag Linux - Security 3 03-16-2004 09:06 AM
Linux SubSeven? radnix Linux - Security 16 10-07-2003 06:22 AM
firewall port forwarding manthram Linux - Networking 0 04-01-2002 07:08 PM
firewall.rc.config says :"open port 8080" but nmap says port is closed saavik Linux - Security 2 02-14-2002 12:16 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:25 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration