Gentoo Archives: gentoo-user

From: Mick <michaelkintzios@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] [O/T] netstat security puzzle
Date: Sun, 18 Dec 2016 08:32:54
Message-Id: 2209597.gOQeWudCIC@dell_xps
In Reply to: Re: [gentoo-user] [O/T] netstat security puzzle by "J. Roeleveld"
1 On Sunday 18 Dec 2016 08:09:06 J. Roeleveld wrote:
2 > On December 18, 2016 8:26:40 AM GMT+01:00, Mick <michaelkintzios@×××××.com>
3 wrote:
4 > >On Friday 16 Dec 2016 19:19:11 Poison BL. wrote:
5 > >> On Fri, Dec 16, 2016 at 7:14 PM, Mick <michaelkintzios@×××××.com>
6 > >
7 > >wrote:
8 > >> > I am looking at a Mint 18 installation and noticed when running
9 > >
10 > >netstat
11 > >
12 > >> > that
13 > >> > all tcp connections are showing not the PC name, but
14 > >
15 > >"Knoppix":<port>.
16 > >
17 > >> > What might be the cause of this? The installation was performed
18 > >
19 > >using a
20 > >
21 > >> > Mint
22 > >> > LiveCD iso.
23 > >> > --
24 > >> > Regards,
25 > >> > Mick
26 > >>
27 > >> My first check would be /etc/hosts for an entry there. That, or
28 > >
29 > >lazily
30 > >
31 > >> grepping all of /etc for Knoppix.
32 > >>
33 > >> It is strange that it's not using either the hostname as given during
34 > >> setup, or an auto-generated potentially unique one, wherever it's
35 > >
36 > >pulling
37 > >
38 > >> that from.
39 > >
40 > >I've grep-ped the whole of /etc, no mention of "Knoppix" there.
41 > >
42 > >I've also looked in /var/lib/NetworkManager/dhclient-enp6s8.conf to see
43 > >what
44 > >hostname NetworkManager sends to dhclient. No trace of "Knoppix" in
45 > >there
46 > >either.
47 > >
48 > >What else could it be creating or overriding a Local Address with one
49 > >called
50 > >"Knoppix", rather than what was set at installation time?
51 >
52 > There is a hostname option in the kernel config. Maybe that is used
53 > somewhere?
54 >
55 > # zgrep -i knoppix /proc/config.gz
56 >
57 > What does ' hostname ' return?
58 >
59 > --
60 > Joost
61
62 hostname returns the correct name of the PC, as set in /etc/hosts. I'll
63 investigate Tom H's hint that the local router's dhcp server may be the
64 culrpit. I seem to recall this PC had booted with a Knoppix CD some days ago,
65 perhaps this was cached by the router.
66 --
67 Regards,
68 Mick

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-user] [O/T] netstat security puzzle "J. Roeleveld" <joost@××××××××.org>