Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

rpc hack attempts?

Status
Not open for further replies.

redsevens

IS-IT--Management
Aug 11, 2000
40
US
I think somebody may be trying to do bad things to my server! I don't understand how RPC works, so maybe this is way off base and I'm being paranoid, but I thought I'd present it to the masses...

I am occasionally getting messages in /var/log/messages that read:

Code:
Feb  2 11:59:13 milhouse 173>Feb  2 05:59:13 rpc.statd[332]: gethostbyname error for ^Xw^??^Xw^??^Yw^??^Y....
Feb  2 11:59:13 milhouse GF^D/shA0@^HF^G^Iv^L^MV^P^MN^L^Is0^KM

Is this a case where somebody is trying to use malicious commands to screw up the server? Regardless of whether or not it's a hack attempt, I don't think anything is using rpc's so I'm wondering if I should disable it, and if so, how? This is a RH6.2 box with Apache/PHP4, sendmail, PostGreSQL and SSH. Any help would be greatly appreciated!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top