Re: Nmap/Snort

From: Kris Kennaway (kris@obsecurity.org)
Date: 05/30/02


Date: Thu, 30 May 2002 01:22:45 -0700
From: Kris Kennaway <kris@obsecurity.org>
To: nathan skains <nskains@comcast.net>


On Thu, May 30, 2002 at 02:42:32AM -0500, nathan skains wrote:
> yep i am scanning my self via root. the port that was up on the first scan
> then i scan again seconds later and it was gone.

This is a FAQ, and it's already been answered in an earlier message.

> not really sure. but i am also concern about these ports
> 113/tcp open auth
> 587/tcp open submission

sockstat shows you which process owns sockets. In this case it's
inetd's builting auth service, and sendmail.

Kris



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Relevant Pages

  • Re: Hardening a Solaris system.
    ... > I know files that execute with root permissions by normal users (e.g. ... > I've set up a web server, running Apache, so are thinking about what I ... thing to leave enabled in here might be a backup port. ... there are security steps here. ...
    (comp.unix.solaris)
  • Re: Hardening a Solaris system.
    ... > I know files that execute with root permissions by normal users (e.g. ... > I've set up a web server, running Apache, so are thinking about what I ... thing to leave enabled in here might be a backup port. ... there are security steps here. ...
    (comp.security.unix)
  • Re: Safe practices
    ... Assume I'm logged in to my Linux system as a normal user. ... System is stand-alone, non-networked, but connected to internet via ... Someone might try to get to you through a port used for other purposes ... Your 'su root' at your console:- You are in a different thread to the rest ...
    (alt.os.linux)
  • A new model for ports and kernel security?
    ... why do we have this requirement that only root ... made to a low port to be "secure". ... clearly it has outlived its usefulness as a "security" feature. ... So I would like to propose the following improvement to kernel security ...
    (Linux-Kernel)
  • Enforce SSH Login Delay
    ... ::ffff:211.171.191.106 port 11328 ssh2 ... Dec 10 13:18:28 turf sshd: Failed password for root from ...
    (comp.os.linux.misc)