Re: Open Ports


Subject: Re: Open Ports
From: Joe Lannom (minstrel@hagbard.40ad.com)
Date: Tue Jan 11 2000 - 22:33:51 MST


> I've been doing some security checks on our network, and servers lately,
> and came across some ports that are open, but are commented out in
> /etc/inetd. Heres the output from a port scan on my G3 running YDL:

[port listing snip]

> And here's my related lines in inetd:
> #imap stream tcp nowait root /usr/sbin/tcpd imapd
> #finger stream tcp nowait root /usr/sbin/tcpd in.fingerd
> #cfinger stream tcp nowait root /usr/sbin/tcpd in.cfingerd
> #systat stream tcp nowait guest /usr/sbin/tcpd /bin/ps -auwwx
> #netstat stream tcp nowait guest /usr/sbin/tcpd /bin/netstat
>
> I have portsentry running

[light goes off]

Portsentry binds to those ports to listen for connection attempts, if
they're defined in your conf file, right?

So, there's something there listening, even if inetd isn't paying
attention to them or the daemons aren't running.

joe



This archive was generated by hypermail 2a24 : Tue Feb 01 2000 - 17:50:57 MST