URN Logo
UNIX Resources » Linux » Linux Forum » Linux Security » Page.7 » Mysterious Reading On Port 32768
announcement The content of this page is collected from Linux Forum, All copyrights and other associated rights are reserved by the original authors of the articles.
Resources
China Linux Forum(finished)
Linux Forum(finished)
FreeBSD China(finished)
linuxforum.com
  LinuxForum General Chat
  Linux Advocacy
  LinuxForum Polls
  Introductions
  Linux Kernel Support
  Patch Management
  Development Release
  Linux Programming
  Linux Security
  Linux Software
  Linux Hardware Problems
    Linux Video Problems
    Linux Sound Problems
  Linux Networking Support
  Linux Printing Support
  Linux Human Interface Devices Support
  Linux Data Storage Support
  Linux Applications Support
  Linux Installation Support
  Linux Laptops Support
  Linux Motherboard, Chipsets, CPU, Memory
  Miscellaneous
  Debian Linux Support
  Ubuntu Linux Support
  LiveCD Discussions
  Gentoo Linux Support
  Mandrake Linux Support
  Redhat / Fedora Linux Support
  Slackware Linux Support
  SuSE Linux Support
  CentOS Linux Support
  Linux Web Servers
  Linux DNS Servers
  Linux Database Servers
  Linux Email Servers
  Linux FTP Servers
  Linux Squid Proxy Server
  Linux Samba Help
  Linux cPanel Help
  Linux Ensim Help
  Linux Plesk Help
  Linux Webmin / Usermin Help
  Qmail Toaster Help
  Linux Games
  Windows Game Emulation
  Linux Discussions
  General Linux Discussions
  Red Hat Linux Discussions
  More Red Hat Linux Discussions
  Mandrake Linux Discussions
  Slackware Linux Discussions
  SuSE Linux Discussions
  Debian Discussions
  Samba Help
  Linux Security
  Linux Networking
  Gentoo Help
  Operating System Rant Forum
  Hardware Rants
   
Mysterious Reading On Port 32768
Subject: Mysterious Reading On Port 32768
Author: americymru    Posted: 2005-01-18 21:07:32    Length: 1,719 byte(s)
[Original] [Print] [Top]
Can anyone help me to understand the following reading:-

[root@localhost root]# netstat -pltu
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name
tcp        0      0 *:http                  *:*                     LISTEN      14826/httpd2
tcp        0      0 *:https                 *:*                     LISTEN      14826/httpd2
udp        0      0 *:32768                 *:*                                 -
I am ruuning Apache on my server and all other services have been disabled. When I run nmap on 127.0.0.1 it gives me the following result:-
PORT    STATE SERVICE
80/tcp  open  http
443/tcp open  https

-: ,,,which is as it should be. I am aware that port 32768 is used by the filenet tms service although I dont know what that is. Also I am aware that the Hackers Paradise Trojan operates on this port. Should I be worried? What is going on on port 32768?Huh?

If it helps I am running Mandrake 10.1.

Best Regards AC
[Original] [Print] [Top]
Subject: Mysterious Reading On Port 32768
Author: phish    Posted: 2005-01-19 11:44:58    Length: 187 byte(s)
[Original] [Print] [Top]
Try running  lsof  | grep 32678
That will tell which process it running on that port

 
[Original] [Print] [Top]
« Previous thread
Shh Login
Linux Security
Page. 7
Next thread »
Login Via Telnet On Linux
     

Copyright © 2007 UNIX Resources Network, All Rights Reserved.      About URN | Privacy & Legal | Help | Contact us
Powered by FreeBSD    webmaster: webmaster@unixresources.net
This page created on 2007-08-01 11:46:30, cost 0.040056943893433 ms.