Suspicious shadow listen port
Kevin Steves
stevesk at sweden.hp.com
Fri Apr 13 07:14:09 EST 2001
On Tue, 10 Apr 2001 Torbjorn.Wictorin at its.uu.se wrote:
: # netstat -an | grep LISTEN
:
: tcp4 0 0 *.32785 *.* LISTEN
: tcp4 0 0 130.238.4.133.22 *.* LISTEN
:
: What in ?@# is 32785 ??
:
: # lsof
: ...
: sshd 11152 root 5u IPv4 0x7003ded8 0t0 TCP *:32785 (LISTEN)
: sshd 11152 root 6u IPv4 0x7004ded8 0t0 TCP xxx.yyy.zzz.hhh:22 (LISTEN)
which platform is this? i can't dup on hp-ux 11. does it come back
when you re-add the bogus listenaddr?
More information about the openssh-unix-dev
mailing list