Forum     

Go Back   Digit Technology Discussion Forum > Software > Open Source
Register FAQ Calendar Mark Forums Read

Open Source A place where you can talk to like-minded people about the fastest growing software movement today! Discuss anything and everything about Open Source software and Operating Systems.

Closed Thread
 
LinkBack Thread Tools Display Modes
Old 02-03-2007, 04:47 AM   #1 (permalink)
18 Till I Die............
 
Join Date: Jul 2004
Location: India, Mumbai, Marine Lines
Posts: 5,792
Default

I was checking the logs of firestarter when I saw a few programs I couldn't recognise. One of them was gatecrasher. Google doesn't give any info on that. Other program shown is back orifice, which googling around, told me that it's a kind of trojan. Is this a false positive or has my machine been compromised?
I have attached the log of firestarter. I have removed bittorrent and unknown from the list.

EDIT - I disabled boinc client, now I don't see back orifice. Do they use same ports or something?
The services I see now are - bittorrent, gatecrasher, NTP, pop3s, SSDP and unknown.
netstat shows, pop3s is connecting to google via opera. So, that's safe. Azureus is running, so BitTorrent is also OK. Now, I got ssdp is simple service discovery protocol so that's safe. Is there any connection between ssdp and HAL?
sheesh, gatecrasher is a protocol used in connection with bittorrent. So, it seems lot better now.
Attached Files
File Type: txt firestarter-events.txt (21.6 KB, 10 views)
__________________
http://www.bash.org/?258908

Last edited by mehulved; 02-03-2007 at 05:08 AM.
mehulved is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 02-03-2007, 09:33 AM   #2 (permalink)
18 Till I Die............
 
Join Date: Jul 2004
Location: India, Mumbai, Marine Lines
Posts: 5,792
Default Re: Is my machine compromised?

It's confirmed that it's boinc client using those ports. So, I guess it's all right but still can someone confirm if it's just because of the ports or anything else?
__________________
http://www.bash.org/?258908
mehulved is offline  
Old 02-03-2007, 11:44 AM   #3 (permalink)
In Pursuit of "Happyness"
 
kalpik's Avatar
 
Join Date: May 2005
Location: New Delhi
Posts: 3,404
Default Re: Is my machine compromised?

Yeah.. its just the boinc client.. Nothing to be worried of..
__________________
Whenever you find yourself on the side of the majority, it is time to pause and reflect. - Mark Twain
kalpik is offline  
Old 02-03-2007, 03:36 PM   #4 (permalink)
String Phreak
 
mediator's Avatar
 
Join Date: Mar 2005
Location: In ur Evil Mind!
Posts: 2,453
Default Re: Is my machine compromised?

^+1
__________________
Bad Bad server.....No candy for u!
mediator is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +5.5. The time now is 12:12 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2