zle1979
Jan 20 2003, 12:40 PM
I recieved some emails today stating that my Linux Server is scanning their servers, can anyone help me on how to stop this? Thank you in advance.
Corey
Jan 20 2003, 01:56 PM
Did they give you any additional information like what ports it was scanning on? This will greatly help investigating what is causing it. As well, maybe even checking your process list to see if there's anything out of the ordinary there might be causing this.
zle1979
Jan 20 2003, 01:59 PM
The port that it is scanning is 443. I hope this helps some. Thanks again
Corey
Jan 20 2003, 02:05 PM
Port 443 is for https connections. Basically websites that use SSL encyptions. This could easily be caused by you hitting a website with "https://" instead of "http://". SSL encrypted sites are usually sites that use secure online transactions with credit cards, or banks, or any paranoid web admins. This doesn't really seem like a big deal to me, and I don't know why you would get emailed regarding it. I would just ignore it unless you are 100% sure that it's not you doing it, then I would attempt to find out who is. You could set up a firewall that blocks outgoing connections to port 443, and redirect it to a log so you can see when the connections are happening.
chrisw
Jan 20 2003, 04:28 PM
could also be the ssl bug that affects the secure connections
in apache...there was an advisory about it a while back
maybe that is what is happening
what the bug creates is the ability to use any server that has
an ssl server running to be used in DOS attacks creating
chaos on the internet thus would possibly cause the scanning...
i would updated your ssl packages on your server, reboot
and see if it continues....that is if you absolutely need an ssl
server...if not just stop the ssl server and just run regular http
on port 80
alex_123_sk
Jan 21 2003, 10:44 AM
This could also be a trick. People would tell you that your host is scanning their server and then ask you information on your host. They can then use those info to attack your host.
chrisw
Jan 22 2003, 02:00 PM
i honestly think .....why would someone go through the trouble
of doing such a thing....just ignore it like tourettes mentioned..
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.