View Full Version : [ubuntu] random high port numbers in jaunty
}SoC{phenix
May 2nd, 2009, 11:43 AM
I recently put ubuntu Intrepid on my laptop, and then updated to jaunty when it became available. I was running a port scan to make sure that there weren't any unwanted ports open when I found several high port numbers open, with their label as unkown. These change every time I do a port scan, and I was wondering if I should be looking for a possible trojan, etc. A sample of some of the port numbers that show up are:
33166
39714
45603
52755
I looked this up elsewhere in the ubuntu forums, and was told to try sudo netstat -plantu. This command doesn't won't list any of these ports when tried. Any help would be greatly appreciated.
-}SoC{phenix
cariboo907
May 2nd, 2009, 03:54 PM
That is a bug in network tools, it has been sent upstream, but hasn't been repaired yet.
Roasted
May 2nd, 2009, 06:59 PM
Is this something Jaunty users should be concerned about?
cariboo907
May 2nd, 2009, 07:38 PM
No, it's actually been around since hardy. I would suggest using a combination of nmap and zenmap for port scanning. They are both in the repositories.
Dr Small
May 2nd, 2009, 08:17 PM
No, it's actually been around since hardy. I would suggest using a combination of nmap and zenmap for port scanning. They are both in the repositories.
It's been around for 3 ubuntu releases ((new release every 6 months) * 3 = 1 1/2 years) and hasn't been fixed? Maybe it's just because it's a low priority.
}SoC{phenix
May 2nd, 2009, 09:16 PM
Thanks a lot for the info, glad to know that it's just a bug.
Darin722
September 26th, 2009, 05:03 PM
I am seeing a similar event while watching traffic with wireshark. My computer appears to be trying a dns lookup on my isp's mail server using random high port numbers??? Is this the same problem that you folks are discussing?
According to wireshark I'm sending a DNS packet: "Standard Query A Mail.clearwire-dns.net
the next packet is a response, DNS "Standard Query Response, No such name"
The source port then changes and the process repeats continuously.
rookcifer
September 26th, 2009, 05:43 PM
That is a bug in network tools, it has been sent upstream, but hasn't been repaired yet.
Link please.
cariboo907
September 26th, 2009, 07:33 PM
Here's the link (https://bugs.launchpad.net/gnome-nettool/+bug/257042) to my bug report, and the Bugzilla (https://bugzilla.gnome.org/show_bug.cgi?id=547598) report.
rookcifer
September 27th, 2009, 04:17 AM
Here's the link (https://bugs.launchpad.net/gnome-nettool/+bug/257042) to my bug report, and the Bugzilla (https://bugzilla.gnome.org/show_bug.cgi?id=547598) report.
If I understand correctly, this seems to be a flaw in Gnome's native port scan tool, right? Not a flaw in nmap I assume?
I use Kubuntu so I have never seen this problem, but I hope they get it fixed soon enough.
cariboo907
September 27th, 2009, 03:14 PM
It is a flaw in gnome network tools, and not nmap. Gnome nettools work without the need to install nmap.
vBulletin® v3.8.4, Copyright ©2000-2012, Jelsoft Enterprises Ltd.