Gentoo Archives: gentoo-user

From: "J. Roeleveld" <joost@××××××××.org>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] [O/T] netstat security puzzle
Date: Sun, 18 Dec 2016 10:55:25
Message-Id: 295AE27F-3898-4065-8FB4-204B003ACDF2@antarean.org
In Reply to: Re: [gentoo-user] [O/T] netstat security puzzle by Mick
1 On December 18, 2016 9:32:25 AM GMT+01:00, Mick <michaelkintzios@×××××.com> wrote:
2 >On Sunday 18 Dec 2016 08:09:06 J. Roeleveld wrote:
3 >> On December 18, 2016 8:26:40 AM GMT+01:00, Mick
4 ><michaelkintzios@×××××.com>
5 >wrote:
6 >> >On Friday 16 Dec 2016 19:19:11 Poison BL. wrote:
7 >> >> On Fri, Dec 16, 2016 at 7:14 PM, Mick <michaelkintzios@×××××.com>
8 >> >
9 >> >wrote:
10 >> >> > I am looking at a Mint 18 installation and noticed when running
11 >> >
12 >> >netstat
13 >> >
14 >> >> > that
15 >> >> > all tcp connections are showing not the PC name, but
16 >> >
17 >> >"Knoppix":<port>.
18 >> >
19 >> >> > What might be the cause of this? The installation was performed
20 >> >
21 >> >using a
22 >> >
23 >> >> > Mint
24 >> >> > LiveCD iso.
25 >> >> > --
26 >> >> > Regards,
27 >> >> > Mick
28 >> >>
29 >> >> My first check would be /etc/hosts for an entry there. That, or
30 >> >
31 >> >lazily
32 >> >
33 >> >> grepping all of /etc for Knoppix.
34 >> >>
35 >> >> It is strange that it's not using either the hostname as given
36 >during
37 >> >> setup, or an auto-generated potentially unique one, wherever it's
38 >> >
39 >> >pulling
40 >> >
41 >> >> that from.
42 >> >
43 >> >I've grep-ped the whole of /etc, no mention of "Knoppix" there.
44 >> >
45 >> >I've also looked in /var/lib/NetworkManager/dhclient-enp6s8.conf to
46 >see
47 >> >what
48 >> >hostname NetworkManager sends to dhclient. No trace of "Knoppix" in
49 >> >there
50 >> >either.
51 >> >
52 >> >What else could it be creating or overriding a Local Address with
53 >one
54 >> >called
55 >> >"Knoppix", rather than what was set at installation time?
56 >>
57 >> There is a hostname option in the kernel config. Maybe that is used
58 >> somewhere?
59 >>
60 >> # zgrep -i knoppix /proc/config.gz
61 >>
62 >> What does ' hostname ' return?
63 >>
64 >> --
65 >> Joost
66 >
67 >hostname returns the correct name of the PC, as set in /etc/hosts.
68 >I'll
69 >investigate Tom H's hint that the local router's dhcp server may be the
70 >
71 >culrpit. I seem to recall this PC had booted with a Knoppix CD some
72 >days ago,
73 >perhaps this was cached by the router.
74
75 I think dhcpcd and co cache the results given in /var.... somewhere.
76 They also can log into /var/log/messages
77
78 --
79 Joost
80 --
81 Sent from my Android device with K-9 Mail. Please excuse my brevity.

Replies

Subject Author
Re: [gentoo-user] [O/T] netstat security puzzle Mick <michaelkintzios@×××××.com>