1 |
I ran 'netstat -lp' on a system of mine and found a couple of strange things. |
2 |
|
3 |
tcp 0 0 1.2.3.4.st:https *:* LISTEN |
4 |
2929/apache2 |
5 |
udp 0 0 1.2.3.4.stat:ntp *:* |
6 |
3203/ntpd |
7 |
|
8 |
1.2.3.4 is not the IP address that actually appeared, but I don't |
9 |
recognize the one that did appear. An IP lookup says it is in the |
10 |
Czech Republic and I'm in the US. I did a grep of my system looking |
11 |
for the IP and found two recent "Relay access denied" messages in the |
12 |
mail log from a sender with an email address like |
13 |
"user@×××××××××××××××××××××××××××××.com" where myhost.com is my host's |
14 |
domain. |
15 |
|
16 |
The other strange item was the following entry repeated over and over |
17 |
under UNIX sockets: |
18 |
|
19 |
warning, got bogus unix line. |
20 |
|
21 |
Can anyone shed some light on either of these? |
22 |
|
23 |
- Grant |