Re: Back Orifice - RedHat 7 [Update]
From: Neophyte (neophyte@news.snel.net)Date: 06/27/02
- Next message: Sundial Services: "Re: Back Orifice 2K - RedHat 7.1/7.2"
- Previous message: Kasper Dupont: "Re: Preventing uploads on a specific port to internet."
- In reply to: Gad: "Re: Back Orifice - RedHat 7 [Update]"
- Next in thread: Mike: "Re: Back Orifice - RedHat 7 [Update]"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "Neophyte" <neophyte@news.snel.net> Date: Thu, 27 Jun 2002 23:13:52 +0200
Hello again Gad,
Yes, I installed PortSentry on SuSE and then ran nmap again...what do you
know...bo2k on port 54320...just as you suggested. I understand a little
more about how PortSentry works thanks to your suggestion and a little
reading on my part.
While this puts me somewhat more at ease, I still want to understand more
before I actually put my Linux box online. I'm sure you can appreciate that.
If you're interested, I'll let you know how I get on.
Thanks again,
Gabriel
"Gad" <chookiesNOSPAM@tpg.com.au> wrote in message
news:3D1B0C6D.5020002@tpg.com.au...
> Hi,
> I was also alarmed of all the daemons on my system until I found out 90%
> was portsentry....
>
> The fact that _nmap_ reports that port 54320 (or any for that matter) is
> open, doesn't mean that it actually knows what process is listening on
> it - nmap just _suggests_ what the port is _typically_ used for (e.g.
> you could run Apache on port 54320 and nmap would report port 54320
> running with bo2k on it).
>
> Two suggestions -
> A. su to root, then do 'nestat -lutp' and check the process listening on
> the port (some data won't show in normal user mode, so you have to su).
> B. It might very well be portsentry, which is installed by default on RH
> 7.x. So do 'ps -aux | grep portsentry' and check if it's running.
>
> Good luck,
> Gad
>
- Next message: Sundial Services: "Re: Back Orifice 2K - RedHat 7.1/7.2"
- Previous message: Kasper Dupont: "Re: Preventing uploads on a specific port to internet."
- In reply to: Gad: "Re: Back Orifice - RedHat 7 [Update]"
- Next in thread: Mike: "Re: Back Orifice - RedHat 7 [Update]"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|