LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-04-2004, 04:14 AM   #1
DrNeil
Member
 
Registered: Aug 2004
Location: Scotland
Distribution: Debian, Suse, Knoppix, Dyna:bolic, Mandrake [couple of years ago], Slackware [1993 or so]
Posts: 150

Rep: Reputation: 15
What's this? LBC-Watchdog cesdcdtrn


Hi I noticed this in my Firewall logs:

Google doesnt tell me much:

It's listed as

http://www.google.com/search?q=%22lb...&start=10&sa=N
LBC Watchdog
google -> define:LBC nothing really either
locate lbc on my server nothing either

The same Question marks for cesdcdtrn
Contents Delivery Management ??? Listed as port but WTF is it.



From us - 19 packets
To 61.173.0.251 - 1 packet
Service: lbc-watchdog (tcp/2816) (fp=TCP:1 a=DROP,none,eth0) - 1 packet
To 147.31.184.207 - 10 packets
Service: cesdcdtrn (tcp/2922) (fp=TCP:1 a=DROP,none,eth0) - 10 packets


Can anyone shed more light on this? Thanks


Opps forgot Suse 8.2, Kernel 2.4.x standalone no X, attched to a Serverbank with remote controls and ttyS0 console logins case your server goes awol.



Last edited by DrNeil; 09-04-2004 at 04:46 AM.
 
Old 09-25-2004, 07:28 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quite possibly the portnames where resolved using the /etc/services database (try "getent services <portname>" to see how).
This common way of resolving ports is worthless in these cases. When a process is running, try "lsof -lMnP -i tcp:<portnumber>" or "fuser -n tcp <portnumber>". If the process is not running, and no processname/PID/portnumber data is recorded you're out of luck AFAIK.
 
Old 09-25-2004, 08:58 AM   #3
DrNeil
Member
 
Registered: Aug 2004
Location: Scotland
Distribution: Debian, Suse, Knoppix, Dyna:bolic, Mandrake [couple of years ago], Slackware [1993 or so]
Posts: 150

Original Poster
Rep: Reputation: 15
yeah, that's mostly the problem that /etc/services is used. Not much use on the more esoteric ports.
 
Old 09-25-2004, 12:53 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
yeah, that's mostly the problem that /etc/services is used. Not much use on the more esoteric ports.
No, it's no use in general for this type of thing because it's a static mapping.
 
Old 09-25-2004, 07:44 PM   #5
DrNeil
Member
 
Registered: Aug 2004
Location: Scotland
Distribution: Debian, Suse, Knoppix, Dyna:bolic, Mandrake [couple of years ago], Slackware [1993 or so]
Posts: 150

Original Poster
Rep: Reputation: 15
http://www.mynetwatchman.com/LID.asp?IID=120114642

This list was partly useful for the Sasser and Dabber Backdoor scans listed as monkeycom and sgi.* .
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Hardware watchdog in BIOS and Linux watchdog driver are different? travishein Linux - Hardware 1 12-22-2008 09:41 PM
Watchdog daemon and drivers sigma957 Debian 1 04-08-2005 09:32 PM
How do you use the software watchdog? werkyo Linux - Software 1 03-30-2004 10:57 AM
A software watchdog Gandilf Linux - Software 0 07-24-2003 09:26 AM
netdev watchdog emanners Linux - Networking 2 08-17-2001 02:16 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:44 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration