Linux Netfilter discussions
 help / color / mirror / Atom feed
* ip_conntrack vs netstat
@ 2003-08-30 12:37 Jonas Lindborg
  2003-09-02 20:04 ` Eric Constantineau
                   ` (2 more replies)
  0 siblings, 3 replies; 5+ messages in thread
From: Jonas Lindborg @ 2003-08-30 12:37 UTC (permalink / raw)
  To: netfilter

Hello,

When comparing the output of /proc/net/ip_conntrack with the "netstat"
command, I'm seeing a few established connections in ip_conntrack that are
not presented by netstat.

These are familiar connections (ssh, imap) to known hosts that could very
well have been done by me but not in the last 24 hrs so they should have
timed out a long time ago.

"ps" shows no such processes running so this immediately raises the
suspicion that the machine could be compromised and connections are hidden
from netstat and ps.
But if this was the case there should be some connections to unknown hosts
showing in ip_conntrack as well so I should be able to rule out that
possibility (?).

Now for my question:
Can anyone confirm that ip_conntrack can show "ghost" connections like
these?


^ permalink raw reply	[flat|nested] 5+ messages in thread
* Re: ip_conntrack vs netstat
@ 2003-09-04 18:07 Kevin Smith
  0 siblings, 0 replies; 5+ messages in thread
From: Kevin Smith @ 2003-09-04 18:07 UTC (permalink / raw)
  To: netfilter

[-- Attachment #1: Type: text/plain, Size: 250 bytes --]

No, we won't let you. So there. 

--

Message: 3
From: "Eric Constantineau" <mekanik@nerim.net>
To: "Jonas Lindborg" <jools@apollo.nu>,
	<netfilter@lists.netfilter.org>
Subject: 
Date: Tue, 2 Sep 2003 22:04:53 +0200

I want to unsubscribe !
thanks



[-- Attachment #2: winmail.dat --]
[-- Type: application/ms-tnef, Size: 1608 bytes --]

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2003-09-04 18:07 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-08-30 12:37 ip_conntrack vs netstat Jonas Lindborg
2003-09-02 20:04 ` Eric Constantineau
2003-09-02 20:19 ` Ralf Spenneberg
2003-09-02 20:31 ` James Mullens
  -- strict thread matches above, loose matches on Subject: below --
2003-09-04 18:07 Kevin Smith

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox