From owner-freebsd-security Thu May 30 1:23:13 2002 Delivered-To: freebsd-security@freebsd.org Received: from obsecurity.dyndns.org (adsl-64-169-107-187.dsl.lsan03.pacbell.net [64.169.107.187]) by hub.freebsd.org (Postfix) with ESMTP id D13FB37B409 for ; Thu, 30 May 2002 01:23:04 -0700 (PDT) Received: by obsecurity.dyndns.org (Postfix, from userid 1000) id C88E666B8B; Thu, 30 May 2002 01:22:46 -0700 (PDT) Date: Thu, 30 May 2002 01:22:45 -0700 From: Kris Kennaway To: nathan skains Cc: freebsd-security@FreeBSD.ORG Subject: Re: Nmap/Snort Message-ID: <20020530012244.B18923@xor.obsecurity.org> References: <000f01c207ad$8f215c20$0200a8c0@logical> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-md5; protocol="application/pgp-signature"; boundary="wzJLGUyc3ArbnUjN" Content-Disposition: inline User-Agent: Mutt/1.2.5.1i In-Reply-To: <000f01c207ad$8f215c20$0200a8c0@logical>; from nskains@comcast.net on Thu, May 30, 2002 at 02:42:32AM -0500 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org --wzJLGUyc3ArbnUjN Content-Type: text/plain; charset=us-ascii Content-Disposition: inline On Thu, May 30, 2002 at 02:42:32AM -0500, nathan skains wrote: > yep i am scanning my self via root. the port that was up on the first scan > then i scan again seconds later and it was gone. This is a FAQ, and it's already been answered in an earlier message. > not really sure. but i am also concern about these ports > 113/tcp open auth > 587/tcp open submission sockstat shows you which process owns sockets. In this case it's inetd's builting auth service, and sendmail. Kris --wzJLGUyc3ArbnUjN Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (FreeBSD) iD8DBQE89eFTWry0BWjoQKURAoGsAKDJZxM+6k65vYPyCtlNFCiw67gGtACg6K/s mt5UCNfaftx46gSe7fFipOE= =X6ZK -----END PGP SIGNATURE----- --wzJLGUyc3ArbnUjN-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message