You are not logged in.
Pages: 1
Hi all archers,
Since about a month I am suspecting that something wrong/illicit is happening on my system.
About once or twice a day, my Internet connection will almost stop responding. It will be extremely slow even to display a Google search result.
When this happens, I log into my router and notice that it's hitting the limit for maximum number of connections (which I set to 1000). When everything is fine, I usually have between 100-150 connections. Thanks to tomato firmware on the router, i can have a detail view of all those connections. heres a list to what it looked like earlier today when i copy/pasted the list. As you can see its a totally random list of destination IP/port to (from the domain names) what seems like residential ISP addresses. the source, 192.168.1.150 is my arch box.
I have gone as far as i could in identifying what is going on and mostly how to stop that from happening. My fear is that something(like a worm) is trying to make connections to a ton of places without my consent.
I do use Bittorrent occasionally, but I limit the number of outgoing connections in the client to 25 and to a source port range which does not fit with that huge amount of random connection.
I don't have much port opens on that machine, mostly ssh(with a solid password) on a non standard port, and apache mostly for posting stuff on forums and to friends.
If any security person reads this, what would be my next step in resolving that issue ?
Last edited by lio (2010-07-14 18:36:51)
Offline
Do you have ssh port forwarding in your router?
Offline
yes , I need it often from school. but its not showing the standard port to the outside. I checked the auth.log files and they are not showing anything suspicious for ssh. all access are from my school's ip range.
Offline
netstat -a -p
should tell you what processes your currently active connections belong to. Monitoring that should tell you what is causing all of the connections.
lsof -i
might also be interesting.
Last edited by Zeist (2010-07-14 19:00:54)
I haven't lost my mind; I have a tape back-up somewhere.
Twitter
Offline
Thank you for this command, I was not aware of that usage. That should indeed provide me a lot of information. I will update this thread as to what is causing this.
Offline
even if you were not hacked...you should always limit the ammount of retries on ssh login attempts (eg. 3 retries every 5 minutes).
check fail2ban out.
Offline
You should actually disable password logins and use keys.
The day Microsoft makes a product that doesn't suck, is the day they make a vacuum cleaner.
--------------------------------------------------------------------------------------------------------------
But if they tell you that I've lost my mind, maybe it's not gone just a little hard to find...
Offline
Hi again,
Took me a while to get to execute the "netstat -a -p" at the proper time when my issue was happening, but I finally got it. Unfortunately it does not give the expected information ![]()
im pasting the output of the command to which i add a grep with the udp and tcp keywords to get rid of all the not network related lines.
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 *:sunrpc *:* LISTEN 1765/rpcbind
tcp 0 0 localhost.localdom:7634 *:* LISTEN 1827/hddtemp
tcp 0 0 *:2233 *:* LISTEN 28969/sshd
tcp 0 0 *:50011 *:* LISTEN 29757/python
tcp 0 0 *:50012 *:* LISTEN 9237/python
tcp 0 0 *:50014 *:* LISTEN 4985/transmission
tcp 0 0 *:673 *:* LISTEN 1769/famd
tcp 0 0 *:svn *:* LISTEN 1837/svnserve
tcp 0 1 archbox:52083 216.168.1.27:52173 SYN_SENT 4985/transmission
tcp 0 1 archbox:52929 128.113.153.170:53148 SYN_SENT 4985/transmission
tcp 0 1 archbox:59104 75.55.39.205:55165 SYN_SENT 4985/transmission
tcp 0 0 archbox:50016 AStDenis-106-1-97:53208 ESTABLISHED 9237/python
tcp 0 1 archbox:33501 75.80.87.111:58954 SYN_SENT 4985/transmission
tcp 0 1 archbox:51899 84.164.210.211:49155 SYN_SENT -
tcp 0 1 archbox:41883 c-68-32-63-9.hsd1:28106 SYN_SENT -
tcp 0 1 archbox:59437 pool-74-109-124-2:64056 SYN_SENT -
tcp 0 0 archbox:50019 85.28.79.171:63598 ESTABLISHED 9237/python
tcp 0 1 archbox:45720 213-227-221-151.s:52530 SYN_SENT -
tcp 0 0 archbox:50538 baymsg1020427.gate:msnp ESTABLISHED 3363/pidgin
tcp 0 1 archbox:50783 host-196-205-152-:16342 SYN_SENT -
tcp 0 1 archbox:34655 90-227-200-18-no36:6110 SYN_SENT -
tcp 0 1 archbox:39968 c-76-124-87-31.hs:28106 SYN_SENT -
tcp 0 1 archbox:48489 bl11-46-179.dsl.t:54320 SYN_SENT -
tcp 0 1 archbox:34698 84.153.210.78:27005 SYN_SENT -
tcp 0 0 archbox:50019 85.28.79.171:63598 ESTABLISHED 9237/python
tcp 0 0 archbox:50538 baymsg1020427.gate:msnp ESTABLISHED 3363/pidgin
tcp 0 0 archbox:40645 85.236.110.226:ircd ESTABLISHED 11234/irssi
tcp 0 1 archbox:53202 76-241-37-70.ligh:52400 SYN_SENT -
tcp 0 0 archbox:50016 gen92-4-82-235-9-1:6881 ESTABLISHED -
tcp 0 1 archbox:45601 host-196-205-152-:16342 SYN_SENT -
tcp 0 1 archbox:49606 95.105.4.182.dyna:30987 SYN_SENT -
tcp 0 0 archbox:50016 cac94-11-88-178-1:54568 ESTABLISHED 9237/python
tcp 0 1 archbox:52512 71.215.180.208:48440 SYN_SENT -
tcp 0 1 archbox:53019 69.14.223.194:62124 SYN_SENT -
tcp 0 1 archbox:54342 net-93-148-193-67:51413 SYN_SENT -
tcp 0 1 archbox:33144 75.66.168.32:57802 SYN_SENT -
tcp 0 1 archbox:34747 cpe-75-81-0-123.k:42772 SYN_SENT -
tcp 0 1 archbox:46387 79.182.36.47:60557 SYN_SENT -
tcp 0 1 archbox:39449 ppp-70-226-168-24:20394 SYN_SENT -
tcp 0 0 archbox:50012 bar06-4-82-234-18:61992 ESTABLISHED 9237/python
tcp 0 0 archbox:50012 bar06-4-82-234-18:61992 ESTABLISHED 9237/python
tcp 0 1 archbox:57865 p54987049.dip.t-d:61063 SYN_SENT -
tcp 0 0 archbox:50012 ALyon-252-1-95-125:1698 ESTABLISHED 9237/python
tcp 0 1 archbox:40243 artai.wheftbox.ca:61055 SYN_SENT -
tcp 0 0 archbox:50018 85-218-38-111.dcl:26267 ESTABLISHED -
tcp 0 0 archbox:53337 gw-in-f16.1e100.n:imaps ESTABLISHED 2142/thunderbird-bi
tcp 0 1 archbox:42684 ool-44c54ea7.dyn.:33333 SYN_SENT -
tcp 0 0 archbox:50020 geek.noichi.net:47562 ESTABLISHED 9237/python
tcp 0 0 archbox:39285 c-174-52-26-78.hs:33649 TIME_WAIT -
tcp 0 1 archbox:53095 net80.195.109-181:18519 SYN_SENT -
tcp 0 1 archbox:52047 p5499DA34.dip.t-d:27005 SYN_SENT -
tcp 0 1 archbox:53306 216.200.119.70.cf:65000 SYN_SENT -
tcp 0 0 archbox:37661 gw-in-f16.1e100.n:imaps ESTABLISHED 2142/thunderbird-bi
tcp 0 0 archbox:50018 AOrleans-151-1-62:25739 ESTABLISHED -
tcp 0 0 archbox:svn 142.137.235.190:1323 ESTABLISHED 9058/svnserve
tcp 0 1 archbox:43006 64.235.72.252:32282 SYN_SENT -
tcp 0 1 archbox:58878 c-98-199-21-190.h:23965 SYN_SENT -
tcp 0 1 archbox:33293 pool-98-117-151-25:6112 SYN_SENT -
tcp 0 1 archbox:56050 net135.187.188-21:18519 SYN_SENT -
tcp 0 1 archbox:43606 206-248-178-217.ds:1720 SYN_SENT -
tcp 0 0 archbox:50012 rob92-9-88-161-11:63042 ESTABLISHED 9237/python
tcp 0 0 archbox:34696 hosted-by.leaseweb:ircd ESTABLISHED 3338/xchat
tcp 0 1 archbox:50020 ip-129.net-82-216:46545 SYN_SENT -
tcp 0 1 archbox:50018 109.219.77-86.rev:55154 SYN_SENT -
tcp 0 0 archbox:50012 4aa54-1-81-56-1-8:64051 ESTABLISHED -
tcp 0 0 archbox:50020 60.235.219-88.rev:59697 ESTABLISHED -
tcp 0 0 archbox:39643 213.143.121.183:13452 TIME_WAIT -
tcp 0 1 archbox:50019 41.104.68.55:36407 SYN_SENT -
tcp 0 0 archbox:60666 iw-in-f125.:xmpp-client ESTABLISHED 3363/pidgin
tcp 0 0 archbox:50012 dan75-1-81-57-19-:52531 ESTABLISHED 9237/python
tcp 0 0 archbox:50012 lns-bzn-30-82-253:56259 ESTABLISHED 9237/python
tcp 0 0 archbox:50016 modemcable008.172:13706 ESTABLISHED -
tcp 0 0 archbox:50012 4aa54-2-82-224-86:52652 ESTABLISHED 9237/python
tcp 0 0 localhost.localdom:7634 localhost.localdo:58981 TIME_WAIT -
tcp 0 0 archbox:60617 wineasy.se.quakene:ircd ESTABLISHED 3338/xchat
tcp 0 0 archbox:50012 19.77.68-86.rev.g:52098 ESTABLISHED -
tcp 0 0 archbox:50012 ADijon-551-1-74-1:51212 ESTABLISHED 9237/python
tcp 0 0 archbox:50020 75.253.195-77.rev:31108 ESTABLISHED -
tcp 0 0 archbox:50012 bne75-2-82-67-188:58776 ESTABLISHED -
tcp 0 0 archbox:35290 S0106e0cb4e3ba147:57110 TIME_WAIT -
tcp 0 0 archbox:50019 mon75-6-82-226-12:48621 ESTABLISHED -
tcp 0 383 archbox:59975 c-69-254-219-126.:57473 FIN_WAIT1 -
tcp 0 0 archbox:50020 AMontsouris-151-1:12702 ESTABLISHED -
tcp 0 0 archbox:50012 89-159-177-52.rev:52466 ESTABLISHED 9237/python
tcp 0 0 archbox:50016 AToulouse-552-1-2:36500 ESTABLISHED -
tcp 0 0 archbox:50012 41.102.156.170:59253 ESTABLISHED -
tcp 0 0 archbox:50017 ANantes-556-1-165:16518 ESTABLISHED -
tcp 0 0 archbox:50019 bdn33-1-82-66-9-1:57079 ESTABLISHED -
tcp 0 0 archbox:50012 client88-85-21-59.:1303 ESTABLISHED -
tcp 0 0 archbox:32777 cpe-76-172-235-20:22447 TIME_WAIT -
tcp 0 0 archbox:50016 85.28.79.171:63598 ESTABLISHED -
tcp 0 0 *:sunrpc *:* LISTEN 1765/rpcbind
tcp 0 0 *:webcache *:* LISTEN 7325/java
tcp 0 0 *:www *:* LISTEN 1852/httpd
tcp 0 0 *:50011 *:* LISTEN 29757/python
tcp 0 0 *:50012 *:* LISTEN 9237/python
tcp 0 0 *:microsoft-ds *:* LISTEN 1838/smbd
tcp 0 0 *:50014 *:* LISTEN 4985/transmission
tcp 0 0 localhost.localdom:8005 *:* LISTEN 7325/java
tcp 0 0 *:8009 *:* LISTEN 7325/java
tcp 0 0 *:netbios-ssn *:* LISTEN 1838/smbd
tcp 0 0 *:5900 *:* LISTEN 21665/vino-server
tcp 0 0 archbox:netbios-ssn macmini:49390 ESTABLISHED 12288/smbd
tcp 0 0 archbox:43374 105-85-252-216.ds:mysql ESTABLISHED 7325/java
tcp 0 0 archbox:43373 105-85-252-216.ds:mysql ESTABLISHED 7325/java
tcp 0 0 archbox:43371 105-85-252-216.ds:mysql ESTABLISHED 7325/java
tcp 0 0 archbox:43372 105-85-252-216.ds:mysql ESTABLISHED 7325/java
udp 0 0 archbox:54774 p1-ha-inbound-gw.me:ntp ESTABLISHED 1821/ntpd
udp 0 0 *:sunrpc *:* 1765/rpcbind
udp 0 0 192.168.1.25:netbios-ns *:* 1841/nmbd
udp 0 0 archbox:netbios-ns *:* 1841/nmbd
udp 0 0 *:netbios-ns *:* 1841/nmbd
udp 0 0 192.168.1.2:netbios-dgm *:* 1841/nmbd
udp 0 0 archbox:netbios-dgm *:* 1841/nmbd
udp 0 0 *:netbios-dgm *:* 1841/nmbd
udp 0 0 *:665 *:* 1765/rpcbind
udp 0 0 archbox:57772 yike.ca:ntp ESTABLISHED 1821/ntpd
udp 0 0 *:sunrpc *:* 1765/rpcbind
udp 0 0 *:665 *:* 1765/rpcbindI *think* the anormal connections are those in state "SYN sent" but it seems no process can be indentified for them.
Also, since my first post, I have changed my password to an insanely secure one, restricted ssh connection to only my account, closed a few forwarded port that i was not using anymore and gave an eye to the list of user accounts on my computer to make sure that they were all legitimate.
I Welcome anyone who could help me investigate further than this.
thanks,
lio
Last edited by lio (2010-08-01 16:00:33)
Offline
Hm, you have quite a lot there.. (On my machine right now only a running mplayer radio stream, my chat clients and a ssh connection have a connection established, a few (http server, ftp server, mpd are listening).
What are all those "python" entries? And the "java" ones?
Oh and, are you running this command as root? If not, you should, because that should make those "-" entries be actually populated with names...
Ogion
(my-dotfiles)
"People willing to trade their freedom for temporary security deserve neither and will lose both." - Benjamin Franklin
"Enlightenment is man's leaving his self-caused immaturity." - Immanuel Kant
Offline
the python ones are from deluge bittorent client. they should all be in the port range of 50010-50020. The Java are from a tomcat server running as i was working on a web app when the slowdown occurred (those Java ports are not forwarded).
I am running the command as root. I actually made the netstat command sudoable without password and created a script which is triggered with a keyboard shortcut. This to improve my reaction time to get the logging when my issue is happening.
Offline
Maybe "lsof -i" can tell you more? I'm not really sure.
Also you could check pstree and top/htop and just poke around and see if the programs/processes running seem correct to you).
Ogion
(my-dotfiles)
"People willing to trade their freedom for temporary security deserve neither and will lose both." - Benjamin Franklin
"Enlightenment is man's leaving his self-caused immaturity." - Immanuel Kant
Offline
Sooo ... you have transmission _and_ deluge ... working at the same time, one torrent client is enough to bring the network down, two of those will be twice as fun.
Also all those services running either as root or other users (that don't have a process name? even running netstat as root?) might also provide some insight to the problem. The number of connections seems ok for a machine running a torrent client with a few other services .... however that netbios stuff is only needed for windows (correct me if I'm wrong) so if it isn't needed I would try to get rid of it.
Also I think that limiting the port range to use in a torrent client is not the same as limiting the total number of open connections so you might want to check that too.
R00KIE
Tm90aGluZyB0byBzZWUgaGVyZSwgbW92ZSBhbG9uZy4K
Offline
If the system IS hacked, and the attacker isn't too serious, you might get something out of
ps -e usince something unusual has to be running, right? Also, I would reinstall packages, containing coreutils, ps, netstat, ...
Last edited by Leonid.I (2010-08-01 22:24:38)
Arch Linux is more than just GNU/Linux -- it's an adventure
pkill -9 systemd
Offline
Pages: 1