store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Tue May 21, 2013 5:31 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 77 posts ]  Go to page 1, 2, 3, 4, 5, 6  Next
Author Message
 Post subject: Listening ports status has changed
Unread postPosted: Wed Jun 20, 2012 5:45 am 
Offline
Forum Regular
Forum Regular

Joined: Sat Dec 11, 2004 2:33 pm
Posts: 195
Location: South Africa
Hello,

I updated ASL + OSSEC this morning and now I am getting flooded by this message in the ASL Log (every 5 odd sec)
xxx.xxx.xxx.xxx = server ip.

ossec: output: `netstat -ultn |grep -v 127.0.0.1`:
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State
tcp 0 0 0.0.0.0:3306 0.0.0.0:* LISTEN
tcp 0 0 xxx.xxx.xxx.xxx:53 0.0.0.0:* LISTEN
tcp 0 0 xxx.xxx.xxx.xxx:53 0.0.0.0:* LISTEN
tcp 0 0 xxx.xxx.xxx.xxx:53 0.0.0.0:* LISTEN
tcp 0 0 xxx.xxx.xxx.xxx:53 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:12443 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:9022 0.0.0.0:* LISTEN
tcp 0 0 :::993 :::* LISTEN
tcp 0 0 :::995 :::* LISTEN
tcp 0 0 :::106 :::* LISTEN
tcp 0 0 :::587 :::* LISTEN
tcp 0 0 :::110 :::* LISTEN
tcp
Previous output:
ossec: output: `netstat -ultn |grep -v 127.0.0.1`:
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State

info:

ASL Version 3.0.25: CentOS 6 (SUPPORTED
ossec-hids-server-2.6-14.el6.art.x86_64
ossec-hids-2.6-14.el6.art.x86_64

_________________
Mark Brindley
2Large Networks - Web solutions that work


Top
 Profile  
 
 Post subject: Re: Listening ports status has changed
Unread postPosted: Wed Jun 20, 2012 6:03 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Jul 15, 2008 2:38 pm
Posts: 704
Location: Sweden
I just started reporting the same. Came with the latest update.

Code:
Jun 20 11:16:02 Updated: 1:asl-3.0.25-2.el5.art.i386
Jun 20 11:16:03 Updated: 1:asl-waf-module-3.0.25-2.el5.art.i386
Jun 20 11:16:05 Updated: ossec-hids-server-2.6-14.el5.art.i386
Jun 20 11:16:08 Updated: 1:asl-web-3.0.25-2.el5.art.i386


Top
 Profile  
 
 Post subject: Re: Listening ports status has changed
Unread postPosted: Wed Jun 20, 2012 6:08 am 
Offline
Forum Regular
Forum Regular

Joined: Wed Jan 02, 2008 3:21 pm
Posts: 515
Location: United Kingdom
Just came to report same issue. Slightly different ports/services though.


Top
 Profile  
 
 Post subject: Re: Listening ports status has changed
Unread postPosted: Wed Jun 20, 2012 6:12 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Jul 15, 2008 2:38 pm
Posts: 704
Location: Sweden
Yeah, slightly different ports for me as well. Strnage thing is that another server, that I upgraded first, does not report any incidents...


Top
 Profile  
 
 Post subject: Re: Listening ports status has changed
Unread postPosted: Wed Jun 20, 2012 6:37 am 
Offline
Forum Regular
Forum Regular

Joined: Sat Dec 11, 2004 2:33 pm
Posts: 195
Location: South Africa
Just checked on my new server it is running ASL 3.0.24

Looking through the yum log I see ossec updates was applied yesterday.

Jun 19 12:53:25 Updated: ossec-hids-2.6-13.el6.art.x86_64
Jun 19 12:53:29 Updated: ossec-hids-server-2.6-13.el6.art.x86_64
Jun 19 19:11:32 Updated: ossec-hids-2.6-14.el6.art.x86_64
Jun 19 19:11:35 Updated: ossec-hids-server-2.6-14.el6.art.x86_64

ASL Log

ossec: output: `netstat -ultn |grep -v 127.0.0.1`:
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State
tcp 0 0 0.0.0.0:3306 0.0.0.0:* LISTEN
tcp 0 0 xxx.xxx.xxx.xxx:80 0.0.0.0:* LISTEN
tcp 0 0 xxx.xxx.xxx.xxx:80 0.0.0.0:* LISTEN
tcp 0 0 xxx.xxx.xxx.xxx:53 0.0.0.0:* LISTEN
tcp 0 0 xxx.xxx.xxx.xxx:53 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN
tcp 0 0 xxx.xxx.xxx.xxx:443 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:12443 0.0.0.0:* LISTEN
tcp 0 0 :::993 :::* LISTEN
tcp 0 0 :::995 :::* LISTEN
tcp 0 0 :::7080 :::* LISTEN
tcp 0 0 :::7081 :::* LISTEN
tcp
Previous output:
ossec: output: `netstat -ultn |grep -v 127.0.0.1`:
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State

_________________
Mark Brindley
2Large Networks - Web solutions that work


Top
 Profile  
 
 Post subject: Re: Listening ports status has changed
Unread postPosted: Wed Jun 20, 2012 9:04 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Nov 23, 2010 7:30 am
Posts: 247
Location: Glasgow, UK
Exact same for me - dozens of reports since the update this morning.

I've submitted it as a "false positive" (don't know if it would come under that though!) - no response yet.


Top
 Profile  
 
 Post subject: Re: Listening ports status has changed
Unread postPosted: Wed Jun 20, 2012 10:10 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Jul 15, 2008 2:38 pm
Posts: 704
Location: Sweden
Lucky you. I turned of the reporting when it reached 2k+ reports...


Top
 Profile  
 
 Post subject: Re: Listening ports status has changed
Unread postPosted: Wed Jun 20, 2012 10:29 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Jul 15, 2008 2:38 pm
Posts: 704
Location: Sweden
There is an update out now. Testing...


Top
 Profile  
 
 Post subject: Re: Listening ports status has changed
Unread postPosted: Wed Jun 20, 2012 10:29 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Nov 23, 2010 7:30 am
Posts: 247
Location: Glasgow, UK
Update now available from ASL - just had my ticket updated and applying the update now.


Top
 Profile  
 
 Post subject: Re: Listening ports status has changed
Unread postPosted: Wed Jun 20, 2012 10:36 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Jul 15, 2008 2:38 pm
Posts: 704
Location: Sweden
chris: beat you to it :wink:


Top
 Profile  
 
 Post subject: Re: Listening ports status has changed
Unread postPosted: Wed Jun 20, 2012 10:37 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Nov 23, 2010 7:30 am
Posts: 247
Location: Glasgow, UK
Haha... well it has happened again a few times after the update - hopefully just clearing itself out.


Top
 Profile  
 
 Post subject: Re: Listening ports status has changed
Unread postPosted: Wed Jun 20, 2012 10:43 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Jul 15, 2008 2:38 pm
Posts: 704
Location: Sweden
Seems to be working for me. No more reports from here (yea, I have re-enabled logging.. :wink: )


Top
 Profile  
 
 Post subject: Re: Listening ports status has changed
Unread postPosted: Wed Jun 20, 2012 11:17 am 
Offline
Forum Regular
Forum Regular

Joined: Sat Dec 11, 2004 2:33 pm
Posts: 195
Location: South Africa
Ran the update - enabled logging
:(
Still Getting tons of reports

_________________
Mark Brindley
2Large Networks - Web solutions that work


Top
 Profile  
 
 Post subject: Re: Listening ports status has changed
Unread postPosted: Wed Jun 20, 2012 12:07 pm 
Offline
Forum Regular
Forum Regular

Joined: Tue Jul 15, 2008 2:38 pm
Posts: 704
Location: Sweden
Back for me as well. Not the same high frequency though...


Top
 Profile  
 
 Post subject: Re: Listening ports status has changed
Unread postPosted: Wed Jun 20, 2012 4:10 pm 
Offline
Forum Regular
Forum Regular

Joined: Sat Dec 11, 2004 2:33 pm
Posts: 195
Location: South Africa
Hi,

Just ran the latest update & the "problem" persists.

asl-3.0.25-3.el6.art.x86_64.rpm
asl-waf-module-3.0.25-3.el6.art.x86_64.rpm
asl-web-3.0.25-3.el6.art.x86_64.rpm

_________________
Mark Brindley
2Large Networks - Web solutions that work


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 77 posts ]  Go to page 1, 2, 3, 4, 5, 6  Next

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 4 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group