Results 1 to 5 of 5

Thread: Foreign IP address in hosts .allow

  1. #1
    Join Date
    May 2007
    Location
    UK near Bedford
    Beans
    3,483
    Distro
    Ubuntu Development Release

    Foreign IP address in hosts .allow

    I found this IP address in my hosts.allow

    ALL: 119.42.68.232
    Anyone any thoughts on this. I cannot find any other evidence of intrusion.
    PC

    To get a terminal command to put its output into a file use this format
    {terminal command} > {filename}

  2. #2
    Join Date
    Nov 2007
    Location
    London, England
    Beans
    7,703

    Re: Foreign IP address in hosts .allow

    That's scary. I looked it up:
    inetnum: 119.42.64.0 - 119.42.79.255
    netname: CAT-BB-NET
    descr: 10 Fl. 72. CAT TELECOM TOWER Bangrak Bangkok Thailand
    I would be inclined to assume the worst. Have you installed any servers? I wonder if sudo netstat -plantu shows anything unexpected, or sudo lsof -i -n -P, although if you have been got at, then these programs can't really be trusted to tell you the whole truth.
    .

  3. #3
    Join Date
    May 2007
    Location
    UK near Bedford
    Beans
    3,483
    Distro
    Ubuntu Development Release

    Re: Foreign IP address in hosts .allow

    I'm going to rebuild the server
    PC

    To get a terminal command to put its output into a file use this format
    {terminal command} > {filename}

  4. #4
    Join Date
    Dec 2008
    Location
    USA
    Beans
    528
    Distro
    Ubuntu 18.10 Cosmic Cuttlefish

    Re: Foreign IP address in hosts .allow

    Hypothetically...
    If someone had cracked the server and one of those inputs returns a malicious listening or sending port, What do you do?
    I don' really like coffee. I guess I'll give my Ubuntu beans to my wife.

    Luke

  5. #5
    Join Date
    Sep 2006
    Beans
    8,627
    Distro
    Ubuntu 14.04 Trusty Tahr

    Re: Foreign IP address in hosts .allow

    Quote Originally Posted by wlraider70 View Post
    Hypothetically...
    If someone had cracked the server and one of those inputs returns a malicious listening or sending port, What do you do?
    You back up the data and do a fresh install of the system. That is an additional reason to keep programs and data separate: it's easier to back up and restore.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •