Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: Weirdness in Sunos 4.1.3ui/ a cracker in the libs?
From: spaf () cs purdue edu (Gene Spafford)
Date: Tue, 01 Nov 1994 11:02:46 -0500


Those open UDP ports are most probably connections for the syslog.
For a process to send UDP packets, it needs to open a UDP socket.
Once "openlog" runs, it opens a socket for later use.  

I saw "probably" because it is always possible that someone has
subverted the code and is using the socket for more than syslog, but
that would be far more clever than anything I've ever seen a real
intruder do.

--spaf



  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]