Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Ramsy
    Guest

    Exclamation Strange ....

    All of a sudden i get these email from LSM Alert:

    Code:
    This is an automated alert generated from eclipse.crystalcore.nl. This alert is to
    notify the addressed users of new server sockets. New server sockets can
    indicate server-software that has been started on your host, or otherwise
    be an indication to malicious activity. It is advised to review this alert
    and investigate if needed.
    
    Following is a summary of new Internet Server Sockets:
    
    >> tcp        0      0 62.41.26.100:35728          0.0.0.0:*                   LISTEN      -                   
    
    
    Following is a summary of a new Unix Domain Sockets:
    no changes to Unix Domain Sockets
    Code:
    This is an automated alert generated from eclipse.crystalcore.nl. This alert is to
    notify the addressed users of new server sockets. New server sockets can
    indicate server-software that has been started on your host, or otherwise
    be an indication to malicious activity. It is advised to review this alert
    and investigate if needed.
    
    Following is a summary of new Internet Server Sockets:
    
    >> tcp        0      0 62.41.26.100:35574          0.0.0.0:*                   LISTEN      -                   
    
    
    Following is a summary of a new Unix Domain Sockets:
    no changes to Unix Domain Sockets
    Code:
    This is an automated alert generated from eclipse.crystalcore.nl. This alert is to
    notify the addressed users of new server sockets. New server sockets can
    indicate server-software that has been started on your host, or otherwise
    be an indication to malicious activity. It is advised to review this alert
    and investigate if needed.
    
    Following is a summary of new Internet Server Sockets:
    
    >> tcp        0      0 62.41.26.100:35483          0.0.0.0:*                   LISTEN      -                   
    
    
    Following is a summary of a new Unix Domain Sockets:
    no changes to Unix Domain Sockets
    Code:
    This is an automated alert generated from eclipse.crystalcore.nl. This alert is to
    notify the addressed users of new server sockets. New server sockets can
    indicate server-software that has been started on your host, or otherwise
    be an indication to malicious activity. It is advised to review this alert
    and investigate if needed.
    
    Following is a summary of new Internet Server Sockets:
    
    >> tcp        0      0 62.41.26.100:35727          0.0.0.0:*                   LISTEN      -                   
    
    
    Following is a summary of a new Unix Domain Sockets:
    no changes to Unix Domain Sockets
    Four mails with suspicious times, first one 0:00, 2nd 0:10, 3rd 2:10 and 4d at 2:20.
    Can't find any running processes for them, run rkhunter and it didnt find anything, nor did chkrootkit (besides a false error to my knowledge: Checking `bindshell'... INFECTED (PORTS: 114 465)).

    Anybody got an idea an what this could be ?

  2. #2
    Member
    Join Date
    Jan 2005
    Posts
    1,880

    Default

    From SSH try netstat -l

    This will list all ports that are listening and might give you an indication as to what is listening on the relevant ports.

  3. #3
    Member
    Join Date
    Oct 2003
    Posts
    92

    Default

    I bet you get them whenever someone logs into ftp on your server (when someone is using passive ftp mode and your FTPd opens a new port for their passive connection)

  4. #4
    Ramsy
    Guest

    Default

    i think so yeah, because it matches my passive range list

Similar Threads & Tags
Similar threads

  1. Strange !
    By linux-image in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 11-27-2004, 03:00 AM
  2. Strange
    By Deltax in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 05-24-2003, 02:20 PM
  3. strange ls and strange msg
    By Sopos in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 05-16-2003, 10:50 AM
  4. Something strange
    By Jontxu in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 11-29-2002, 08:13 AM
  5. Help!!! Something very strange
    By AbeFroman in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 04-14-2002, 11:00 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube