Unusual NTP / other connections?
I'm seeing a number of questionable NTP / other connections. Here's what I see using netstat -a:
udp 0 0 liXX.:37147 disorder.primate.ne:ntp ESTABLISHED
udp 0 0 liXX.:40025 173-203-122-111.vds:ntp ESTABLISHED
udp 0 0 liXX..:37540 dp.cx:ntp ESTABLISHED
udp 0 0 liXX.:34798 sulfur.mednor.net:ntp ESTABLISHED
I'm also seeing connections to localhost.localdom from / to port 4369. This is the port opened by eJabberD, and is expected, but the notes say that it should not be accessible outside the firewall. How can I block access to that port externally. And, I'm guessing the localhost.localdomain bindings are probably normal given that circumstance, correct?
Are these normal? If not, what is the vulnerability, and what can I do about that?
5 Replies
If 4369 is only listening on localhost, then it's only listening on localhost and isn't accessible externally. The -l option to netstat will specifically tell you what's listening where.
Also, the -n and -p options to netstat are quite handy.
I'll check out the netstat -l / -n / -p options as well.
Thanks!
server 0.pool.ntp.org
server 1.pool.ntp.org
server 2.pool.ntp.org
(or something else involving pool.ntp.org). If so, those particular servers are somewhat randomly picked from a pool of ~2600 public NTP servers
If you do "ntpq -p" and all of the numbers under the "st" column are not 16 and the "refid" values are not .STEP., everything's working OK and there's probably nothing to worry about.