Connection to Port 21026, tethereal to analyze

From: Sally Shears (sshears_at_theWorld.com)
Date: 09/30/03


Date: Mon, 29 Sep 2003 18:37:57 -0400

I see a continuous (or at least regular) connection from an unknown
host to post 21026 on my machine.

What is port 21026? Should I worry about this?

Also, I tried to start tethereal to look at the traffic on this port. I
typed tehtereal as root. The result is a process I cannot stop. How can
I stop this process? It's status is "D" for uninterruptible sleep.

USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND
root 29755 0.0 1.7 8168 4484 pts/1 D 17:44 0:00 tethereal

Finally, what would be the right ethereal command to look at this
network traffic?

  -- Sally

p.s. SuSE 8.1, a server, command-line only.

-- 
Sally Shears (a.k.a. "Molly")
sshears@theWorld.com -or- Sally@Shears.org
http://theWorld.com/~sshears


Relevant Pages

  • Re: Port 80 open without WebServer
    ... listening in port 80. ... are not private IPs so you could be scanning a host outside your net. ... > with nessus and nmap. ... I ran the same command of the ...
    (Security-Basics)
  • Re: SSH attacks?
    ... Now that my host is out of focus, ... > non-standard port. ... Worry is only a part of the story - I'm awfully curious. ... I want to worry about system security as ...
    (Incidents)
  • [EXPL] MailEnable SMTP Service VRFY/EXPN Command Buffer Overflow
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... MailEnable SMTP Service VRFY/EXPN Command Buffer Overflow ... help="Target Host") ... help="Target Port") ...
    (Securiteam)
  • How to shorten timeout for connection to a non-existing IP
    ... This command ... Connecting To 123.45.67.89...Could not open connection to the host, ... port 1521: Connect failed ...
    (microsoft.public.windows.server.general)
  • Re: A firewall wont stop this one
    ... On top of that I implement IPF on each host ... >> for further access control to limit NFS, ... By restricting access to the NFS server. ... >> via port filtering that only allowed specific hosts rather than all. ...
    (alt.computer.security)