Suspicious shadow listen port

Kevin Steves stevesk at sweden.hp.com
Fri Apr 13 07:14:09 EST 2001


On Tue, 10 Apr 2001 Torbjorn.Wictorin at its.uu.se wrote:
: # netstat -an  | grep LISTEN
:
: tcp4       0      0  *.32785                *.*                    LISTEN
: tcp4       0      0  130.238.4.133.22       *.*                    LISTEN
:
: What in ?@# is 32785 ??
:
: # lsof
: ...
: sshd 11152    root 5u  IPv4 0x7003ded8 0t0    TCP *:32785 (LISTEN)
: sshd 11152    root 6u  IPv4 0x7004ded8 0t0    TCP xxx.yyy.zzz.hhh:22 (LISTEN)

which platform is this?  i can't dup on hp-ux 11.  does it come back
when you re-add the bogus listenaddr?





More information about the openssh-unix-dev mailing list