From owner-freebsd-security Thu Sep 6 7:53:56 2001 Delivered-To: freebsd-security@freebsd.org Received: from peitho.fxp.org (peitho.fxp.org [209.26.95.40]) by hub.freebsd.org (Postfix) with ESMTP id AACBC37B405 for ; Thu, 6 Sep 2001 07:53:46 -0700 (PDT) Received: by peitho.fxp.org (Postfix, from userid 1501) id B67801361D; Thu, 6 Sep 2001 10:53:45 -0400 (EDT) Date: Thu, 6 Sep 2001 10:53:45 -0400 From: Chris Faulhaber To: Fernan Aguero Cc: security@freebsd.org Subject: Re: some weird stuff found Message-ID: <20010906105345.A8026@peitho.fxp.org> References: <08705D38.78FF6AC2.00A48379@netscape.net> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="vkogqOf2sHV7VnPd" Content-Disposition: inline In-Reply-To: <08705D38.78FF6AC2.00A48379@netscape.net> User-Agent: Mutt/1.3.20i Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org --vkogqOf2sHV7VnPd Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Thu, Sep 06, 2001 at 10:34:12AM -0400, Fernan Aguero wrote: > In the last few days I started noticing strange things. Some of them > I do not understand and perhaps are normal things (such as being scanned) > and others may be more critical. > I appreciate any help and insight you can give me. >=20 > I am running FreeBSD-4.3.0p15 (RELENG_4_3). >=20 > 1 - I have been receiving some messages at the console that I would like > to understand better: > arp: unknown hardware address format (0x0800) >=20 > Lately I have many of these messages per day. What could be > causing this? >=20 This is a FAQ. Basically a machine on your network is sending out invalid arps. Search the mailing list archives for details. > 2 - I also notice this in /var/log/messages =20 > Sep 6 06:00:34 iib005 rpc.statd: invalid hostname to sm_stat: > ^X=F7=FF=BF^X=F7=FF=BF^Y=F7=FF=BF^Y > Sep 6 06:00:35 iib005 /kernel: -^PM-^PM-^P >=20 > The messages in the console appear a little different, with a lot > of gibberish after sm_stat: and /kernel: >=20 Probably a Linux or Solaris rpc attack/exploit. Doesn't affect FreeBSD machines (except for annoying log entries). > 3 - If I run 'nmap -v localhost' I can see a few ports open *snip* > What services run on 1020 and 1021? I am not aware of having enabled > those, and they do not appear in /etc/services. > =20 Run sockstat (or lsof, etc) to see what is bound to those ports. > And relating to this, do i need sendmail listening on 25 and 587 if > I only need to send mail to a smart host? You can probably just use -q30m for sendmail flags if you are not accepting email which will not opening listening sockets. > Also: I need to print to a network printer but I'm not a print server. > Do I need 515 open? Nope. See the lpd(8) man page (-p option). > How do I close those ports (25,587,515)? First see what programs are bound to those ports (see above). 25 =3D=3D telnetd (run from inetd) 515 =3D=3D lpd (see above) > And last, I am running xdm but I only allowed connections from > localhost. Is this in any way related to X11 being on port 6000? > (/etc/services shows xdm on port 177) >=20 Probably. 6000 range of ports are usually X listening. > 4 - I normally run tripwire each night on the system and I never noticed > anything strange. But every time I update my system (cvsup, make worl= d) > I have to go over lots of new files that I need to tell tripwire to > update. > The last time I did this I noticed a strange thing under /bin: > -r-xr-xr-x 2 root wheel 50868 Sep 3 13:27 /bin/[ /bin/[ is a hard link to /bin/test (normal); 'man [' for details. --=20 Chris D. Faulhaber - jedgar@fxp.org - jedgar@FreeBSD.org -------------------------------------------------------- FreeBSD: The Power To Serve - http://www.FreeBSD.org --vkogqOf2sHV7VnPd Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (FreeBSD) Comment: FreeBSD: The Power To Serve iEYEARECAAYFAjuXjfkACgkQObaG4P6BelAipgCfUQ94+V4A117wsgUyXBBz1d+g QO8An3Xba68Sdqy72BIVQMQBti5k89jj =VbW7 -----END PGP SIGNATURE----- --vkogqOf2sHV7VnPd-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message