Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
trojan alert?
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
flarius
n00b
n00b


Joined: 11 Mar 2003
Posts: 14

PostPosted: Tue Apr 19, 2005 1:10 pm    Post subject: trojan alert? Reply with quote

Hello gentoo-users,

please help me. I don´t know what happens here!
After typing:

$netstat | grep local

i got a connection to

manganese.bos.dyndns.org

but i haven´t init any connection manually. Thats the problem!
The connection is startup when i start my dhcpcd daemon.
My AntiVir-Program found a java based trojan and i haved killed him.
I used mozilla-firefox-1.0.2, gentoo-2005.0, kernel 2.6.11

For what is standing for this network connection?
I`m under attack by trojan? How can i removed this connection?
Back to top
View user's profile Send private message
mekong
Tux's lil' helper
Tux's lil' helper


Joined: 23 Apr 2004
Posts: 93
Location: Rdam - NL - EU

PostPosted: Tue Apr 19, 2005 1:30 pm    Post subject: Reply with quote

If you use "netstat -p", you could see the pid of the process which start the connection.
Back to top
View user's profile Send private message
flarius
n00b
n00b


Joined: 11 Mar 2003
Posts: 14

PostPosted: Tue Apr 19, 2005 3:07 pm    Post subject: Reply with quote

$netstat -pe

shows this:

tcp 0 0 localhost:40869 manganese.bos.dynd:smtp TIME_WAIT root 0 -

i got no pid - any ideas to kill this process?

I wondering because under the domain "manganese.bos.dyndns.org" is working an dyndns administator.
He is writing messages in mailgroups. But i not working with an exists dyndns account.

Is there still hope for me?
Back to top
View user's profile Send private message
mekong
Tux's lil' helper
Tux's lil' helper


Joined: 23 Apr 2004
Posts: 93
Location: Rdam - NL - EU

PostPosted: Tue Apr 19, 2005 4:05 pm    Post subject: Reply with quote

smtp is port 25 for sending mail, how do you know he is admin writting message in mailgroups? :lol: Are you on the same mailgroup? Probably harmless, you're sending him email
Back to top
View user's profile Send private message
flarius
n00b
n00b


Joined: 11 Mar 2003
Posts: 14

PostPosted: Tue Apr 19, 2005 4:22 pm    Post subject: Reply with quote

hi,
this information i found at
https://forums.gentoo.org/viewtopic-t-189980-highlight-manganese.html
and by google the web...

but i still haven't any idea what happens here...

the connection is always starting and ending together with my cron daemon. when i kill him, the connection died. when i start cron daemon then the connection start up too. i watch that the localports are dynamically grow up to connect the server outside...

i still thinking it's a spyware-program (?)
Back to top
View user's profile Send private message
mekong
Tux's lil' helper
Tux's lil' helper


Joined: 23 Apr 2004
Posts: 93
Location: Rdam - NL - EU

PostPosted: Tue Apr 19, 2005 4:44 pm    Post subject: Reply with quote

Okay, this is a serious problem, you cron daemon is trying to sending email to dyndns email server, because you misconfigure your cron daemon. When a cron job exists with an error it will try to send an email to the root user. Check your cron daemon configuration again. And maybe your server's domain name too. Maybe you chose one happen to be one of dyndns domains (homelinux.com perhaps? from your link). If you don't have a full qualified domainname, choose something like myserver.localdomain, make sure it's a non-existant domain.
Back to top
View user's profile Send private message
flarius
n00b
n00b


Joined: 11 Mar 2003
Posts: 14

PostPosted: Tue Apr 19, 2005 4:55 pm    Post subject: Reply with quote

@ mekong

that is a good message!
i will try to setup the configuration correctly...
thank you for your support ! cu !
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum