Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 298267 - ssh established to unknown ip
Summary: ssh established to unknown ip
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: x86 Linux
: High trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2009-12-24 21:58 UTC by Mat Ferry
Modified: 2009-12-24 22:04 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Mat Ferry 2009-12-24 21:58:32 UTC
I have the suspicion my system gets hacked, as I found one ssh session established to an unknown user. Please give your opinion whether am I right to doubt about the security of my system. What checks should I run?
My system has been up and running for ~3months with ssh and some other ports open to receive traffic.  

tcp        0      0 192.168.1.9:ssh         92.48.70.236:43214      SYN_RECV   
tcp        0      0 192.168.1.9:ssh         192.168.1.4:38755       ESTABLISHED
tcp        0      0 192.168.1.9:ssh         92.48.70.236:42746      CLOSE_WAIT 
tcp        0      0 192.168.1.9:ssh         92.48.70.236:33846      TIME_WAIT  
Active UNIX domain sockets (w/o servers)
Proto RefCnt Flags       Type       State         I-Node   Path
unix  2      [ ]         DGRAM                    980      @/org/kernel/udev/udevd
unix  3      [ ]         STREAM     CONNECTED     368421   
unix  3      [ ]         STREAM     CONNECTED     368420   
tcp        0      0 192.168.1.9:ssh         192.168.1.4:38755       ESTABLISHED
tcp        0    720 192.168.1.9:ssh         92.48.70.236:38074      ESTABLISHED
tcp        0      0 192.168.1.9:ssh         92.48.70.236:56129      TIME_WAIT
Comment 1 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-12-24 22:04:44 UTC
We don't give end-user support via bugzilla.
Try #gentoo or the Gentoo Forums.