Gentoo Archives: gentoo-user

From: Hinnerk van Bruinehsen <h.v.bruinehsen@×××××××××.de>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Strange outbound requests
Date: Sat, 21 Jan 2012 01:51:27
Message-Id: 4F1A19A6.6050901@fu-berlin.de
In Reply to: Re: [gentoo-user] Strange outbound requests by Michael Mol
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 On 21.01.2012 02:39, Michael Mol wrote:
5 > On Fri, Jan 20, 2012 at 6:34 PM, Grant <emailgrant@×××××.com>
6 > wrote:
7 >>>>>>>> My firewall is blocking periodic outbound connections
8 >>>>>>>> to port 3680 on a Rackspace IP. How can I find out
9 >>>>>>>> more about what's going on? Maybe which program is
10 >>>>>>>> generating the connection requests?
11 >>>>>>>
12 >>>>>>> Uh, a packet sniffer?
13 >>>>>>>
14 >>>>>>> I have an old laptop here that I have a second
15 >>>>>>> (cardbus) network card in. Really cheap and cheerful -
16 >>>>>>> the sort of thing you can pick up on freecycle. It's
17 >>>>>>> been a while since I've done anything like this, but
18 >>>>>>> you should be able to stick a box like that between the
19 >>>>>>> router and the rest of your network, run Wireshark and
20 >>>>>>> filter on that port. If the connection is encrypted
21 >>>>>>> then at least you'll see the originating IP.
22 >>>>>>
23 >>>>>> I've actually got the originating local IP from the
24 >>>>>> shorewall log. I'm just trying to figure out which
25 >>>>>> program and maybe which user on that system is generating
26 >>>>>> the outbound requests to port 3680. Is there any way to
27 >>>>>> get more info without setting up a new box?
28 >>>>>>
29 >>>>>>> I don't think it's relevant that the IP belongs to
30 >>>>>>> Rackspace - don't they just hire (virtual) servers to
31 >>>>>>> anyone that wants one?
32 >>>>>>
33 >>>>>> Yeah I just meant the request could be going to
34 >>>>>> "anyone".
35 >>>>>>
36 >>>>>> - Grant
37 >>>>>
38 >>>>> Are you running NPDS in your LAN and is it configured to
39 >>>>> access any sites on rackspace? -- Regards, Mick
40 >>>>
41 >>>> I am not running NPDS. I looked it up when I was researching
42 >>>> port 3680 and read about it for the first time. I know which
43 >>>> machine is making the requests. Any way to drill down
44 >>>> further?
45 >>>
46 >>> If the machine is running linux, then 'watch "lsof -n|grep
47 >>> TCP|grep 3680"' as root is a sloppy but effective way to find
48 >>> it. There's probably some way to set up a firewall rule on the
49 >>> host in question that logs out the user and (possibly) PID of
50 >>> the connection, but I don't know.
51 >>
52 >> All of my systems run Gentoo. :) Where does watch come from?
53 >
54 > shortcircuit@saffron ~ $ equery b `which watch`
55 > /usr/lib64/portage/pym/portage/package/ebuild/config.py:353:
56 > UserWarning: 'cache.metadata_overlay.database' is deprecated:
57 > /etc/portage/modules (user_auxdbmodule, modules_file)) * Searching
58 > for /usr/bin/watch ... sys-process/procps-3.2.8_p11
59 > (/usr/bin/watch) shortcircuit@saffron ~ $
60 >
61 > Incidentally, does anyone know why all my portage-related
62 > executions get that 'cache.metadata_overlay.database' warning? I've
63 > been seeing it for weeks, even on fresh installs. I would have
64 > assumed a bug like that would have been fixed by now.
65 >
66 >
67
68 You get the warning, because you hat a directory /etc/portage/modules
69 - - simply remove it (or move it, if you are afraid to break something).
70 -----BEGIN PGP SIGNATURE-----
71 Version: GnuPG v2.0.18 (GNU/Linux)
72 Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
73
74 iQEcBAEBAgAGBQJPGhmmAAoJEJwwOFaNFkYcBFQIAJlWjVqACiqCSxwNnigFvXfa
75 olRedLttuzZUGcJKsx59gptBeaRxSc/kQ7oEai6QSmFzY7nq5bsz3QMtJEB5QJpo
76 rOwD844f6pKRKv4GWjCg++1W6LJJcbMs4s0TARLM1+o+uaTC8Lgb/tjdJCov6cWF
77 Hhl/KxRpdy/mCL/QB7/kOQRL/lDryy23xoxCln8S60xzD8pWQ/HsPdMNKg2LDpOL
78 RxKyywJQ/y35OTJU60w6vgkPhJnhQQ4WgzrruvsNCSS60t1Mr51XXdmj5ATEChCw
79 qaxml/3x1eHc4L2j5GekjED0PL2fROOTYujoDlpuTHGTUy5tHNvww+/2upqLf9U=
80 =t8zl
81 -----END PGP SIGNATURE-----