Unix Technical Forum

ports 755 and 757 in netstat ?

This is a discussion on ports 755 and 757 in netstat ? within the Slackware Linux Support forums, part of the Unix Operating Systems category; --> use fuser. ex fuser -n udp 757 that will give you the pid....


Go Back   Unix Technical Forum > Unix Operating Systems > Slackware Linux Support

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-19-2008, 12:16 PM
chris king
 
Posts: n/a
Default ports 755 and 757 in netstat ?

use fuser.
ex
fuser -n udp 757
that will give you the pid.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 02-19-2008, 12:17 PM
Mikhail Zotov
 
Posts: n/a
Default Re: ports 755 and 757 in netstat ?

Greg and Chris, thank you very much.

These ports appeared to be used by inetd.

Regards,
Mikhail
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 02-19-2008, 12:17 PM
Yvan Loranger
 
Posts: n/a
Default Re: ports 755 and 757 in netstat ?

Mikhail Zotov wrote:
> Greg and Chris, thank you very much.
>
> These ports appeared to be used by inetd.


That is suspicious, 755 & 757 are unused according to my copy of the
official list & AFAIK inetd uses no ports itself. Trojan backdoor? rootkit?

--
Merci........Yvan I did not want to repeat other people's mistakes.
So I made new mistakes of my own.
Boy did I invent some good ones!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 02-19-2008, 12:18 PM
Mikhail Zotov
 
Posts: n/a
Default Re: ports 755 and 757 in netstat ?

bq434@freenet.carleton.ca (Yvan Loranger) wrote in message news:<cas0d3$lop$1@freenet9.carleton.ca>...
> Mikhail Zotov wrote:
> > Greg and Chris, thank you very much.
> >
> > These ports appeared to be used by inetd.

>
> That is suspicious, 755 & 757 are unused according to my copy of the
> official list & AFAIK inetd uses no ports itself. Trojan backdoor? rootkit?


Thanks for the reply, Yvan.

A rootkit was the first thing I thought about but chkrootkit
found nothing. Surely, this is not a 100% warranty but...

I still don't know why was inetd listening to these ports but
it doesn't listen anymore after I have upgraded the kernel.
All this took place at a Slackware 9.0 PC. A Slackware 9.1 PC
with the same services opened at inetd.conf doesn't have such
a problem.

Regards,
Mikhail
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 10:11 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
www.UnixAdminTalk.com