How vulnerable is RPC (port 1025) on Linux?

From: Joshua Davies (jdaviestx_at_comcast.net)
Date: 06/23/04


Date: 23 Jun 2004 07:06:44 -0700

I just recently did a fresh Debian installation and, since my computer
was connected to the cable modem, it recognized the connection, DHCP'd
me, gave me an IP address and hooked me up as part of the install. As
soon as I logged in, I ran a netstat to figure out what ports might be
open and I noticed that Debian (for some reason) installs a default
inetd.conf file that includes an RPC service that's listening on port
1025. Sure enough, when I looked for open connections, somebody had
already established a connection to port 1025. I shut down the RPC
statd and portmapper immediately, found the offending process and
killed it, but I'm not sure if I should be worried about any damage he
might have done in the few minutes between the time I started up and
the time I noticed the connection. A quick google search shows that
most port 1025 vulnerabilities are related to Microsoft's DCOM
protocol, which I'm obviously not using... are there any other known
RPC vulnerabilities? Any known worms that try to replicate on port
1025?



Relevant Pages

  • What will we pop after Betty returns the consistent oceans initiative?
    ... then we properly flash Orin and ... it will even grant the installation. ... The guarantee in connection with the permanent yacht is the dilemma that ... He may point surprised traffics, ...
    (sci.crypt)
  • Re: [kde] seeking tips for setting up a home office...
    ... and handles NAT (Internet sharing). ... >> much use if your running a webserver), or ethernet connection to an ADSL ... I briefly went through the smoothwall site ... > installation on linux but installs with linux. ...
    (KDE)
  • Re: Returning to Restore Point
    ... device was not really satisfactory in that I lost connection quite ... may be your best option - you might consider a clean installation if you ... What AntiVirus software do you maintain (is it current release and current ... CHKDSK and updating the hardware device drivers from the manufacturer's web ...
    (microsoft.public.windows.vista.general)
  • Re: Long delay before the updates appear
    ... That's just the connection side. ... Each folder ... (whether the system should reboot after installation), ... and I see the update downloading one at a time. ...
    (microsoft.public.windowsupdate)
  • Re: Long delay before the updates appear
    ... That's just the connection side. ... Each folder ... (whether the system should reboot after installation), ... and I see the update downloading one at a time. ...
    (microsoft.public.windowsupdate)