LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-19-2008, 09:29 PM   #1
rickh
Senior Member
 
Registered: May 2004
Location: Albuquerque, NM USA
Distribution: Debian-Lenny/Sid 32/64 Desktop: Generic AMD64-EVGA 680i Laptop: Generic Intel SIS-AC97
Posts: 4,250

Rep: Reputation: 62
Unusual connection on P2P client


Without getting into the ethics of P2P...

On Firestarter I'm seeing an expected connection from IP x.x.x.1 on port 6697.

I sometimes also see a connection that I don't understand, a persistent connection from my PC (192.168.123.151) to the other computer (x.x.x.1) on a random port, in this case port 1120. That outbound connection doesn't go away, according to Firestarter, even if I shut down the P2P client. Firestarter continues to identify it as an active connection.

I'm no kind of expert at checking out this sort of thing, but I did scan the port with nmap:
Code:
# nmap -T Aggressive -A -v -p 1120 192.168.123.151
Scanning 192.168.123.151 [1 port]
Completed SYN Stealth Scan at 20:13, 0.01s elapsed (1 total ports)
Initiating Service scan at 20:13
Initiating OS detection (try #1) against 192.168.123.151
Retrying OS detection (try #2) against 192.168.123.151
SCRIPT ENGINE: Initiating script scanning.
Host 192.168.123.151 appears to be up ... good.
Interesting ports on 192.168.123.151:
PORT     STATE  SERVICE VERSION
1120/tcp closed unknown
Does that look like anything I should be worried about. As I said, the sympthom only shows up occasionally, and only when an uploader is apparently having a troublesome connection.

Last edited by rickh; 03-19-2008 at 09:32 PM.
 
Old 03-19-2008, 09:48 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Why would you scan your *own* LAN address machine if you could use a combo of lsof, netstat, strace and tcpdump to get all sorts of gory process details? Does the remote address change or not? If it changes is it between a few addresses or random?
 
Old 03-20-2008, 12:16 AM   #3
rickh
Senior Member
 
Registered: May 2004
Location: Albuquerque, NM USA
Distribution: Debian-Lenny/Sid 32/64 Desktop: Generic AMD64-EVGA 680i Laptop: Generic Intel SIS-AC97
Posts: 4,250

Original Poster
Rep: Reputation: 62
Quote:
...you could use a combo of lsof, netstat, strace and tcpdump to get all sorts of gory process details?
The problem is that I don't understand what any of those commands do. I just want to know whether a persistent open connection from my machine to the remote is being initialized here.

Quote:
Does the remote address change or not? If it changes is it between a few addresses or random?
Most often it does not change. When it does change, it's usually within a few addresses. On one occasion, it appeared to me that there may have been such a connection created to a random IP, but I could not be sure about that.
 
Old 03-20-2008, 07:33 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by rickh View Post
The problem is that I don't understand what any of those commands do.
With +3K in posts you surely know the nfo is at your fingertips? netstat to easily get the process ID to feed into lsof, lsof to list open files for that process (see what's in use or what something logs to) and connections, strace to attach to the process and see what gets written if nothing gets logged and tcpdump to capture packets before processing them with tools like wireshark, tcpflow or snort.


Quote:
Originally Posted by rickh View Post
I just want to know whether a persistent open connection from my machine to the remote is being initialized here.
Iptables logging?


Quote:
Originally Posted by rickh View Post
Most often it does not change. When it does change, it's usually within a few addresses. On one occasion, it appeared to me that there may have been such a connection created to a random IP, but I could not be sure about that.
Depending on what P2P app you use it may be super leafnodes or whatever else type of intermediates are in use.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
P2p client juanb Linux - Software 1 05-12-2006 04:06 AM
P2P Client b0ng Linux - Newbie 1 01-19-2005 11:45 AM
Which p2p client? theonebeyond Linux - Software 4 11-17-2004 03:56 AM
p2p client Smokey Slackware 14 09-23-2004 04:06 PM
Looking for a P2P-Client Fred Affe Linux - Software 1 08-17-2003 05:38 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:28 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration