Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 19th December 2005, 03:49 PM
meslick Offline
Registered User
 
Join Date: Feb 2005
Posts: 101
Getting dirty with ports

Hello:

What can I do so that I can monitor all the ports on my Fedora box that are being access/probed/used?

I would like to be able to say, hmmm, why is that ip accessing that port? Or why is that daemon/service communicating with some ip, and what is that ip?

I also don't want to run Ethereal all the time. Is that log at /var/log/messagse the best way to monitor things? There are too many messages in there, and too many odd IP stuff going on. And I hear that certain SYN commands aren't logged there.

Basically, I want to know what's going on. If tehre's a few fools snooping around my property I want to know about it so that possibly I can club them.

Teak
Reply With Quote
  #2  
Old 19th December 2005, 04:05 PM
giulix's Avatar
giulix Offline
"Fixed" by (vague) request
 
Join Date: Oct 2005
Location: GMT+ 1
Posts: 2,950
Run snort in IDS mode.
Reply With Quote
  #3  
Old 19th December 2005, 04:21 PM
Quella's Avatar
Quella Offline
Registered User
 
Join Date: May 2004
Location: Boston, MA (USA)
Posts: 474
I could also recommend an old tool called PortSentry. It would sit and monitor your active ports, and any request to a closed port would create a firewall rule to blackhole the scanner. Only if one hits the open ports woudl you know the machine exists. I used this on many of my Internet facing machies. I was amazed how quickly the firewall rules grew.

Quella
__________________
"The eyes of the LORD are in every place, Watching the evil and the good." Proverbs 15:3
Reply With Quote
  #4  
Old 19th December 2005, 04:36 PM
ssaady Offline
Registered User
 
Join Date: Jun 2004
Location: VA
Age: 47
Posts: 63
netstat -an|more
lsof|grep -i estab
lsof|grep -i listen
Reply With Quote
  #5  
Old 19th December 2005, 05:09 PM
meslick Offline
Registered User
 
Join Date: Feb 2005
Posts: 101
Quote:
Originally Posted by giulix
Run snort in IDS mode.
This seems cool, so I did some research and found this up to date info-bit on Red Hat: <http://www.redhat.com/magazine/013nov05/features/snort/>

This is exactly the kind of thing I was looking for. Thanks.

Perhaps there are better programs, but this seems like a good start.

Teak
Reply With Quote
  #6  
Old 19th December 2005, 05:15 PM
giulix's Avatar
giulix Offline
"Fixed" by (vague) request
 
Join Date: Oct 2005
Location: GMT+ 1
Posts: 2,950
Well, snort is pretty much standard, nowadays. The only problem is one has to tweak it to filter out false positives and, yes, it needs regular updates to be effective... check oinkmaster, too.
Reply With Quote
Reply

Tags
dirty, ports

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
HDD win xp flagged dirty LT72884 Wibble 6 2nd January 2009 07:57 PM
Fedora 9 - Dirty GTK on KDE sudhirb Using Fedora 2 4th July 2008 01:58 AM
Evolution Ports Default change needed - Yahoo changes ports MitchellR Using Fedora 0 23rd May 2008 05:26 PM
More MS dirty tricks? Wayne Linux Chat 7 3rd November 2007 03:12 AM


Current GMT-time: 10:23 (Saturday, 25-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat