hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : !!LSM Alert!! / !!PMON Alert!! (port / socket monitor)
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

!!LSM Alert!! / !!PMON Alert!! (port / socket monitor)

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 09-29-2004, 10:38 PM
besthost00 besthost00 is offline
New Member
 
Join Date: Sep 2004
Posts: 1

!!LSM Alert!! / !!PMON Alert!! (port / socket monitor)


I have the following problem on one of my servers. I keep receiving lsm alerts for different ports. Like this:

This is an automated alert generated from . This alert is to
notify the addressed users of new server sockets. New server sockets can
indicate server-software that has been started on your host, or otherwise
be an indication to malicious activity. It is advised to review this alert
and investigate if needed.

Following is a summary of new Internet Server Sockets:
> tcp 0 0 server.ip:46917 0.0.0.0:* LISTEN -
> tcp 0 0 server.ip:46918 0.0.0.0:* LISTEN -
> tcp 0 0 server.ip:46921 0.0.0.0:* LISTEN -
> tcp 0 0 server.ip:46922 0.0.0.0:* LISTEN -

Following is a summary of a new Unix Domain Sockets:
no changes to Unix Domain Sockets

more:

> tcp 0 0 server.ip:42799 0.0.0.0:* LISTEN 2964/italy006.jpg

another:

> tcp 0 0 server.ip:33363 0.0.0.0:* LISTEN 2501/ny036.jpg


How can jpegs open ports?

Are these false alarms? Thank you!!

Reply With Quote


Sponsored Links
  #2  
Old 09-30-2004, 12:17 AM
dotSecurity dotSecurity is offline
WHT Addict
 
Join Date: Sep 2004
Posts: 161
Hmmm, could have something to do with the new JPEG bug:

http://www.security-talk.com/about7.html

__________________
Security Talk

Reply With Quote
  #3  
Old 09-30-2004, 10:01 AM
Lem0nHead Lem0nHead is offline
Web Hosting Master
 
Join Date: Feb 2004
Posts: 1,226
some people may save compiled/interpreted files as .jpg, chmod them 755 and execute (on shell)
or add handler for them with .htaccess and execute via web

it will work

try opening this file with a text editor
if it just show weird chars, it may be a compiled program... try opening with an image viewer... if you don't get to, it probably is

BTW: your firewall should block ALL ports, EXCEPT the ones that are really used by some program


Last edited by Lem0nHead; 09-30-2004 at 10:04 AM.
Reply With Quote
Sponsored Links
  #4  
Old 10-27-2004, 10:59 PM
Dacsoft Dacsoft is offline
Web Hosting Master
 
Join Date: May 2003
Location: Florida
Posts: 877
Re: !!LSM Alert!! / !!PMON Alert!! (port / socket monitor)

Quote:
Originally posted by besthost00
Following is a summary of new Internet Server Sockets:
> tcp 0 0 server.ip:46917 0.0.0.0:* LISTEN -
> tcp 0 0 server.ip:46918 0.0.0.0:* LISTEN -
> tcp 0 0 server.ip:46921 0.0.0.0:* LISTEN -
> tcp 0 0 server.ip:46922 0.0.0.0:* LISTEN -
Did you ever find what the cause of this is? The link above is for a windows server. What about Linux?

thanks in advance.

Reply With Quote
  #5  
Old 10-28-2004, 12:17 AM
linux-tech linux-tech is offline
<?require_once("life")?>
 
Join Date: Sep 2002
Location: inside your network
Posts: 9,548
The first thing I do when I get an LSM monitor is CHECK the port of the server that is being reported. Occasionally it's a false report, but not usually.
to check:
ssh into the server
telnet to the port (found after ip
If you get no response, then usually(usually) it's a false alarm.
Why is this caused?
HTTP and some other utilities utilize random ports for security. I know pure_ftpd does this for a fact, and I have seen these alerts generated from http as well.
Is this cause for alarm?
If there is no response from the server, then I'd say no, there isn't.
There's another thing you can do.
take this for example
Quote:
Following is a summary of new Internet Server Sockets:
> tcp 0 0 insertiphere:53 0.0.0.0:* LISTEN 12947/named
You can go to the process number (found just before the binary). In this case it would be /proc/12947 and verify that this is indeed a real process and should be running. By looking at the output in there (ls -la * ) you can get everything you (don't) want to know about the process.

__________________
Linux Tech Networks Reliable, Affordable Linux administration and monitoring since 2002

Reply With Quote
  #6  
Old 10-28-2004, 08:24 PM
Dacsoft Dacsoft is offline
Web Hosting Master
 
Join Date: May 2003
Location: Florida
Posts: 877
Thanks for the reply. I just recently switched to pure-ftpd, so maybe that is the cause. The ports are closed at the firewall (both in and out).

thanks again,

Reply With Quote
  #7  
Old 10-28-2004, 09:49 PM
Lem0nHead Lem0nHead is offline
Web Hosting Master
 
Join Date: Feb 2004
Posts: 1,226
i use proftpd and get those messages too

as far as I investigated, it's opened by passive FTP, or something like that

Reply With Quote
  #8  
Old 10-28-2004, 10:05 PM
Dacsoft Dacsoft is offline
Web Hosting Master
 
Join Date: May 2003
Location: Florida
Posts: 877
Quote:
Originally posted by Lem0nHead
i use proftpd and get those messages too

as far as I investigated, it's opened by passive FTP, or something like that
Again, this fits. When I went to pure-ftpd, I also enabled passive FTP.

Reply With Quote
  #9  
Old 01-23-2005, 11:47 PM
Snowman30 Snowman30 is offline
Junior Guru
 
Join Date: Mar 2002
Location: Horsham, Victoria, Aust
Posts: 210
Ive just started getting the same warnings on one of our servers, we use pure-ftpd but have it on the ignore list so im not sure whats goign on...

anyone have any suggestions on how to track this one down as the warnings are annoying

__________________
Alpine Hosting - Australian & US General and Reseller Hosting - Dual Xeon Servers - 24/7 Support
Dedicated Servers Australia -Australian Managed and Unmanaged Servers and Co-Location

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Cloud Security Firm Alert Logic Closes $12.2 Million Round of Financing Web Hosting News 2012-06-05 16:19:54
Alert Logic Adds Cloud Computing Security Tools for Amazon EC2 Customers Web Hosting News 2012-03-21 11:24:05
Cloud Security Firm Alert Logic Q4 Revenue up 45 Percent Over 2010 Web Hosting News 2012-01-20 15:15:38
Inside Alert Logic and Datapipe's Fully Managed Network Security for AWS Web Hosting News 2011-10-26 15:09:29
Web Host SunGard Offers Alert Logic Security Solutions Web Hosting News 2011-08-04 17:33:45


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?