I installed Portsentry and LogCheck
I get lots of Security Violations.
Today, things did not seem right so I did the following:
rpm -Uhv portsentry-1.0-14.src.rpm
portsentry ##################################################
[root@e-smith portsentry]# rpm -q port*
package portsentry-1.0-14.src.rpm is not installed
package portsentry-1.0.tar.gz is not installed
package portsentry-1.0.tar.gz.asc is not installed
Why does it say "not installed"?
[root@e-smith portsentry]# rpm -K port*
portsentry-1.0-14.src.rpm: md5 OK
portsentry-1.0.tar.gz: rpmReadSignature failed
portsentry-1.0.tar.gz.asc: rpmReadSignature failed
Is this bad?
[root@e-smith portsentry]# nmap -sS -O -P0 63.216.139.91
Starting nmap V. 2.53 by fyodor@insecure.org (
www.insecure.org/nmap/ )
Interesting ports on structuralsupport.net (63.216.139.91):
(The 1511 ports scanned but not shown below are in state: closed)
Port State Service
21/tcp open ftp
25/tcp open smtp
80/tcp open http
110/tcp open pop-3
113/tcp open auth
143/tcp open imap2
389/tcp open ldap
443/tcp open https
515/tcp open printer
980/tcp open unknown
3128/tcp open squid-http
3306/tcp open mysql
TCP Sequence Prediction: Class=random positive increments
Difficulty=1640572 (Good luck!)
Remote operating system guess: Linux 2.1.122 - 2.2.14
Nmap run completed -- 1 IP address (1 host up) scanned in 2 seconds
[root@e-smith portsentry]#
Is my self-scan showing anything weird?
The following is additional information which may help.
[root@e-smith portsentry]# rpm -q nmap
nmap-2.53-1
[root@e-smith portsentry]# rpm -q telnet
telnet-0.17-7
[root@e-smith portsentry]# rpm -q e-smith
e-smith-4.2.0-02
[root@e-smith portsentry]# rpm -q e-smith*
package e-smith* is not installed
[root@e-smith portsentry]# rpm -q portsentry
portsentry-1.0-11
[root@e-smith portsentry]# rpm -q port*
package portsentry-1.0-14.src.rpm is not installed
package portsentry-1.0.tar.gz is not installed
package portsentry-1.0.tar.gz.asc is not installed
[root@e-smith portsentry]# rpm -K portsentry
portsentry: open failed: No such file or directory
[root@e-smith portsentry]# ls
portsentry-1.0-14.src.rpm portsentry-1.0.tar.gz portsentry-1.0.tar.gz.asc
[root@e-smith portsentry]# rpm -K port*
portsentry-1.0-14.src.rpm: md5 OK
portsentry-1.0.tar.gz: rpmReadSignature failed
portsentry-1.0.tar.gz.asc: rpmReadSignature failed
[root@e-smith portsentry]#
Since I get "not installed" AND "rpmReadSignature failed" has someone broken in and played with stuff?
I also need help understanding what these reports are:
Security Violations
=-=-=-=-=-=-=-=-=-=
Jul 3 19:19:52 e-smith kernel: Packet log: denylog DENY eth1 PROTO=6 209.9.193.78:2269 63.216.139.91:515 L=60 S=0x00 I=35186 F=0x4000 T=53 SYN (#1)
Jul 3 19:19:55 e-smith kernel: Packet log: denylog DENY eth1 PROTO=6 209.9.193.78:2269 63.216.139.91:515 L=60 S=0x00 I=36722 F=0x4000 T=53 SYN (#1)
Thanks
Richard Emory
jrejr@structuralsupport.net