Mailing List Archive

Support open source code!


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Unidentified subject!



Sorry, got to make a correction here
xinetd uses libwrap (tcpwrap) to block connections; and by default local
loop
connections are allow on (tcpwrap).
But if you close the service (ie. kill -9) then nothing should be listening
on the port
you can do either "ps -A" or "pstree" to find out the current runnning
daemons.
one good way to test it is to have "tail -f /var/log/messages" or run
tcpdump on one of the term in the linux box
And try to telnet into the port (in this case would be 514") from another
box..
And you can look at the result of that from "tail -f /var/log/messages"  (or
tcpdump)







----- Original Message -----
From: "roylo" <roylo@example.com>
To: <tlug@example.com>
Cc: <davidgn@example.com>
Sent: Sunday, August 19, 2001 7:15 PM
Subject: Re: Unidentified subject!


> That's exactly what I'm talking about.
> localhost is set to 127.0.0.1 [check in /etc/hosts]
> (Please correct me if I'm wrong) but xinetd "allow" all traffic on
127.0.0.1
> so that is why you see the results like that.
>
>
>
> ----- Original Message -----
> From: "David Eduardo Gomez Noguera" <davidgn@example.com>
> To: <tlug@example.com>
> Cc: <davidgn@example.com>
> Sent: Sunday, August 19, 2001 5:50 PM
> Subject: Re: Unidentified subject!
>
>
> > Reply.
> >
> > I actually used no options, and did it on localhost.
> >
> > but the output about open ports is the same.
> > Complete output is:
> > Port       State       Service
> > 7/tcp      open        echo
> > 21/tcp     open        ftp
> > 22/tcp     open        ssh
> > 25/tcp     open        smtp
> > 80/tcp     open        http
> > 110/tcp    open        pop-3
> > 111/tcp    open        sunrpc
> > 113/tcp    open        auth
> > 515/tcp    open        printer
> > 587/tcp    open        submission
> > 1024/tcp   open        kdm
> > 1026/tcp   open        nterm
> > 3128/tcp   open        squid-http
> > 5432/tcp   open        postgres
> > 5680/tcp   open        canna
> > 6000/tcp   open        X11
> >
> > Some of them are controlled by xinetd, but some are not, and some i had
> never heard of (kdm, nterm).
> > Just wondering if someone know where can i block each of them, besides
> with iptables?
> >
> > --
> > ICQ: 15605359 Bicho
> >                                   =^..^=
> > First, they ignore you. Then they laugh at you. Then they fight you.
Then
> you win. Mahatma Gandhi.
> > ........Por que no pensaran los hombres como los animales? Pink
> Panther........
> > -------------------------------気検体の一
> 致------------------------------------
> > 暑さ寒さも彼岸まで。
> > アン アン アン とっても大好き
> >
> > -----------------------------------------------------------------------
> > Next Technical Meeting:  Sat, Sep 15 13:30-  (Location to be announced)
> > Next Nomikai Meeting:    Fri, Oct 19 19:30-  Tengu Tokyo Eki-Mae
> > -----------------------------------------------------------------------
> > more info: http://www.tlug.gr.jp           Sponsor: Global Online Japan
>

Home | Main Index | Thread Index

Home Page Mailing List Linux and Japan TLUG Members Links