Connection to Port 21026, tethereal to analyze

From: Sally Shears (sshears_at_theWorld.com)
Date: 09/30/03


Date: Mon, 29 Sep 2003 18:37:57 -0400

I see a continuous (or at least regular) connection from an unknown
host to post 21026 on my machine.

What is port 21026? Should I worry about this?

Also, I tried to start tethereal to look at the traffic on this port. I
typed tehtereal as root. The result is a process I cannot stop. How can
I stop this process? It's status is "D" for uninterruptible sleep.

USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND
root 29755 0.0 1.7 8168 4484 pts/1 D 17:44 0:00 tethereal

Finally, what would be the right ethereal command to look at this
network traffic?

  -- Sally

p.s. SuSE 8.1, a server, command-line only.

-- 
Sally Shears (a.k.a. "Molly")
sshears@theWorld.com -or- Sally@Shears.org
http://theWorld.com/~sshears


Relevant Pages

  • Re: Port 80 open without WebServer
    ... listening in port 80. ... are not private IPs so you could be scanning a host outside your net. ... > with nessus and nmap. ... I ran the same command of the ...
    (Security-Basics)
  • Re: Emails stuck in queue error 451 4.4.0 Primary target IP addres
    ... Your Exchange server is unable to connect to host smtp.surfdsl.net using SMTP--that's what the telnet to port 25 tests. ... > Well if you look in my post I posted the command prompt and the> reposnse I ...
    (microsoft.public.exchange.misc)
  • Re: SSH attacks?
    ... Now that my host is out of focus, ... > non-standard port. ... Worry is only a part of the story - I'm awfully curious. ... I want to worry about system security as ...
    (Incidents)
  • [EXPL] MailEnable SMTP Service VRFY/EXPN Command Buffer Overflow
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... MailEnable SMTP Service VRFY/EXPN Command Buffer Overflow ... help="Target Host") ... help="Target Port") ...
    (Securiteam)
  • Re: [opensuse] Results of moving ssh to a high port - Zero script kiddies in a 24 hour period.
    ... Less than 300 entries in the logs in _total_ for an entire 24 hour period. ... Last note on moving ssh to a higher port. ... ports and you eliminate the need to specify the new port on the command line ... Host alchemy.3111skyline.com alchemy ...
    (SuSE)