LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-20-2003, 09:35 AM   #1
jarod
LQ Newbie
 
Registered: Jul 2003
Location: .ro
Posts: 10

Rep: Reputation: 0
unexplained traffic


when i do cat /proc/net/ip_conntrack i get o lot of entries like:
---------
tcp 6 359867 ESTABLISHED src=192.168.1.1 dst=192.168.1.184 sport=59975 dport=80 [UNREPLIED]
src=192.168.1.184 dst=192.168.1.1 sport=80 dport=59975 use=1
tcp 6 359867 ESTABLISHED src=192.168.1.1 dst=192.168.1.185 sport=59974 dport=80 [UNREPLIED]
src=192.168.1.185 dst=192.168.1.1 sport=80 dport=59974 use=1
tcp 6 359867 ESTABLISHED src=192.168.1.1 dst=192.168.1.185 sport=59975 dport=80 [UNREPLIED]
src=192.168.1.185 dst=192.168.1.1 sport=80 dport=59975 use=1
tcp 6 359867 ESTABLISHED src=192.168.1.1 dst=192.168.1.186 sport=59974 dport=80 [UNREPLIED]
src=192.168.1.186 dst=192.168.1.1 sport=80 dport=59974 use=1
tcp 6 359867 ESTABLISHED src=192.168.1.1 dst=192.168.1.186 sport=59975 dport=80 [UNREPLIED]
src=192.168.1.186 dst=192.168.1.1 sport=80 dport=59975 use=1
tcp 6 359867 ESTABLISHED src=192.168.1.1 dst=192.168.1.187 sport=59974 dport=80 [UNREPLIED]
src=192.168.1.187 dst=192.168.1.1 sport=80 dport=59974 use=1
tcp 6 359867 ESTABLISHED src=192.168.1.1 dst=192.168.1.187 sport=59975 dport=80 [UNREPLIED]
src=192.168.1.187 dst=192.168.1.1 sport=80 dport=59975 use=1
tcp 6 359867 ESTABLISHED src=192.168.1.1 dst=192.168.1.188 sport=59974 dport=80 [UNREPLIED]
src=192.168.1.188 dst=192.168.1.1 sport=80 dport=59974 use=1
---------
The sport is in the 56000 range and the dst is in the 192.168.1.* range. 192.168.1.1 is a slack 8.1 router with only sshd running, the rest of the lan are win boxes.
i can't figure it out what's generating these requests...
 
Old 07-21-2003, 01:55 AM   #2
Thoreau
Senior Member
 
Registered: May 2003
Location: /var/log/cabin
Distribution: All
Posts: 1,167

Rep: Reputation: 45
You slack box isn't a firewall is it.

You should traceroute the incoming port 80 from the router. It shouldn't be passing those packets to the lan if it was configured correctly. I don't know of any default allow all incoming on port 80 as generic iptables config, so I'll assume it's not allowing it. And that the scan is coming from the router itself.

Since this is something you seem to have just noticed, I'll assume that it was at one time configured correctly. Since that time, two things could have happened. You may have be running wget or another http program on your router- unlikely- or your lil sshd box has been hacked and you need to get that shit off the net.

So in short, u b farkd.
 
Old 07-21-2003, 05:44 AM   #3
jarod
LQ Newbie
 
Registered: Jul 2003
Location: .ro
Posts: 10

Original Poster
Rep: Reputation: 0
It is a firewall (i mean i use iptables, FORWARD default policy DROP, INPUT and OUTPUT ACCEPT, I only allow connections from my LAN to the internet and ESTABLISHED,RELATED back in). There was a powerfail a few days ago and the server restarted. After that I noticed the unexplained traffic and I used wget to download chkrootkit. Not sure though if the bogus traffic started before or after using wget. I have openssh3.6.1p1 which i know is secure.
 
Old 08-11-2003, 10:31 AM   #4
jarod
LQ Newbie
 
Registered: Jul 2003
Location: .ro
Posts: 10

Original Poster
Rep: Reputation: 0
I think those requests appear because of a guy in our LAN that uses kazaa (with that option that enables kazaa to use port 80).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Traffic shaping (limiting outgoing bandwidth of all TCP-traffic except FTP/HTTP) ffkodd Linux - Networking 3 10-25-2008 12:09 AM
Unexplained Compiling Error SlackwareInAZ Slackware 11 06-01-2005 10:46 AM
Unexplained out of memory Issue hiddenbrain Linux - Hardware 4 05-19-2005 05:02 PM
unexplained c++ pointer behaviour vmp Programming 5 10-15-2004 02:04 AM
unexplained Mandrake 8.2 traffic mr.moto Linux - Networking 6 08-27-2002 01:58 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:54 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration