Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations biv343 on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

How do i find out whois is running this...tcp 0 0 0.0.0.0: 2

Status
Not open for further replies.

farley99

MIS
Feb 12, 2003
413
US
How do i find out whois is running this...
tcp 0 0 0.0.0.0:2339 0.0.0.0:* LISTEN 28561/bnc
 
Also...
nobody 28561 0.0 0.0 2024 648 ? S Oct09 0:01 ./bnc

How does i know who it is?
 
Is that from the output of 'netstat -natp' in the first post and some sort of ps in the second? The 0.0.0.0 means that the service is listening on all interfaces in your system. A daemon called bnc is listening on port 2339. Find out where its located on the disk with 'updatedb && locate bnc', or maybe 'which bnc'.

I googled for bnc and found this...

IRC Session Bouncing Proxy
BouNCe is a daemon designed to allow some people who do not have access to the net in general, but who do have access to another pc that can reach the net, the ability to BouNCe though this pc to IRC.

...and...
Did you install this?

ChrisP
RHCE, LPIC-1, CCNA, CNE, MCSE, +10 others
 
Does this mean anything to you...
cwd -> /var/tmp/.xpl/bnc\ (deleted)
 
ls -l /proc ????

What does "updatedb && locate bnc" return?
 
Farley,
Basically bnc started and changed directory to /var/tmp/.xpl/bnc . Once it started it did an unlink (i.e. remove) of the directory. It's current working dir is still set to the directory even though you would not see it in an ls. This is often used to stealth programs.

Hope that helps.
 
How do i find out who uploaded this...
/var/tmp/.xpl/bnc

It was own as nobody, so it was upload from a php script most likely. Would that be in any of the logs?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top