3 msgDebian suggestion on File Deletion
2 msgSquid Proxy Cache Security Update Advisory SQUI...
6 msgRe: [SECURITY] [DSA 1430-1] New libnss-ldap pac...
4 msgRe: [SECURITY] [DSA 1481-1] New Linux 2.6.18 pa...
8 msgRe: [SECURITY] [DSA 1422-1] New e2fsprogs packa...

nmap Xmas scans and unrecognized outcoming conn...
\ Martín Peluso (7 Dec 2007)
. \ Maximilian Wilhelm (7 Dec 2007)

1 msgExport business of electrical equipments (pleas...
3 msg'Debian hardened' ;-)
1 msg(intet emne)
1 msgChatting online
1 msgDaniel Pressler/Heilbronn/Bechtle-Gruppe/DE ist...
2 msgRe: [SECURITY] [DSA 1409-2] New samba packages ...
1 msgRe: [SECURITY] [DSA 1400-1] New perl packages f...
2 msgPermission changes with rsync
3 msg[SECURITY] [DSA 1409-1] New samba packages fix ...
1 msgthis bug/#438871 - jabber: do not run as group:adm
1 msgRe: Security Servers down ???
4 msgQA needed for insecure LD_LIBRARY_PATH in many ...
1 msgOldrich Melski je mimo kancelář.
2 msgRe: perl regex vulnerability - debian - pcre only?
Subject:nmap Xmas scans and unrecognized outcoming connections
Group:Debian-security
From:Martín Peluso
Date:7 Dec 2007


 
Hello everybody

Two days ago one of my machines started to receive several nmap Xmas
scans from 73.23.32.79. Later, in another machine which is running under
Debian etch, Firestarter showed me four outcoming connections to the
same ip address with destination ports 80, 44285, 41182 and 43275. Those
connections are not used by any client application and they are not
recognized by netstat. In addition, the target ip address (a comcast
range address) don't seem to be giving http access, and it have all of
its ports filtered.
I don't know how to proceed in order to determine what application is
using those connections or what are they used for. They are still active
since two days ago.
Any suggestion?

Thanks in advance.

Martin Peluso


--
To UNSUBSCRIBE, email to debian-security-REQUEST
with a subject of "unsubscribe". Trouble? Contact listmaster



© 2004-2008 readlist.com