logo       

Re: Ktorrent, firewall and blocked connections: msg#00455

Subject: Re: Ktorrent, firewall and blocked connections
Neil Greenwood wrote:
> On 28/03/07, alan c 
> <aeclist-MURppvFVPpEgIZxP67a6fdBPR1lH4CV8@xxxxxxxxxxxxxxxx> wrote:
>> I am mystified though about the service names (and associated ports)
>> at the time. For example one was Gatecrasher (service name) and this
>> was trying to go out on port 6969 and google indicates this is a
>> (windows) trojan.
> 
> Hi Alan,
> 
> I can't answer your question about the blocked connections on the firewall.
> 
> 
> Regarding the mystery service names: for something like BitTorrent or
> FTP (yes I know you're not using it, but the same argument applies)
> that opens multiple connections, the local port number that is opened
> will quite probably flag up as something that is registered to a high
> number. Service names are mainly for listening ports.
> 
> It doesn't actually mean that you have a trojan - it's unlikely unless
> you've managed to infect a Wine installation with one!
> 
> You might be able to identify the connection more reliably using
> something like Wireshark (formerly known as ethereal), which looks at
> the traffic passing over the connection rather than just looking for
> the port number.
> 
> 
> Hopefully, I've put your mind at rest. If you're still confused, let
> me know and I'll try to clear it up further.

thanks Neil. The fact that these are being blocked by the firewall is 
basically reassuring (!)
I do not run wine, wanting to get a best distance from winworld.

Service names being mainly listening ports - useful thanks. So I guess 
that for some reason, activity associated with ktorrent, which I see 
is getting connected very properly via its allocated port/s 6881 or 
6882 it seems that something, maybe ktorrent, is causing outbound 
(attempts?) listening on some occasions. The blocked connections have 
various port numbers.

a selection is:

port            service
13086           unknown
16545           unknown
30169           unknown
4550            unknown
32882           Sun-RPC Portmap
5866            unknown
512              exec
50505           Sockets de Troi
6969            Gatecrasher

the final three look suspicious (from google responses), I have no 
idea about the others.

Maybe if I could find the reasons I could patent it and M$ would buy 
the patent from me for a large sum?? :-)
-- 
alan cocks
Kubuntu user#10391



<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

Recently Viewed:
boot-loaders.gr...    php.pear.genera...    debugging.valgr...    kde.redhat.user...    text.xml.xsl.ge...    culture.languag...    hardware.microc...    java.servicemix...    redhat.release....    web.zope.plone....    user-groups.lin...    opendarwin.webk...    video.mjpeg.use...    sysutils.bcfg2....    encryption.gpg....    lx-office.devel...    xfree86.forum/2...    mail.mutt.devel...    acpi.devel/2003...    qnx.openqnx.dev...    network.irc.irs...    freebsd.devel.m...   
Home | blog view | USPTO Patent Archive | advertise | OSDir is an inevitable website. super tiny logo

Free Magazines

Cisco News
Receive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business.
subscribe

Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field.
subscribe

The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business.
subscribe

Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company.
subscribe

Total Telecom Total Telecom is "The Economist of the communications industry".
subscribe