From mboxrd@z Thu Jan 1 00:00:00 1970 From: Arnt Karlsen Subject: Re: port 389 Date: Sat, 24 Jan 2004 10:57:39 +0100 Sender: netfilter-admin@lists.netfilter.org Message-ID: <20040124105739.1922d8ff.arnt@c2i.net> References: <200401230827.13331.mrakotom@free.fr> <200401230838.05694.Antony@Soft-Solutions.co.uk> <200401231336.07836.mrakotom@free.fr> Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Return-path: In-Reply-To: <200401231336.07836.mrakotom@free.fr> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="iso-8859-1" To: netfilter@lists.netfilter.org On Fri, 23 Jan 2004 13:36:07 +0100,=20 Rakotomandimby Mihamina wrote in message=20 <200401231336.07836.mrakotom@free.fr>: > On Friday 23 January 2004 09:38, Antony Stone wrote: > > TCP port 389 is used for LDAP. >=20 > i knew it with a "grep 389 /etc/services" >=20 > > (There is no such thing as an "answer" port. =A0 Services answer from > > whatever port they listen on.) >=20 > uh ! that's the proof i still need to learn about networking ... > =20 > > I suspect your ISP has some sort of transparent authentication proxy > > server set up and that it is this which your friends are finding. >=20 > Uh ? well . let's hope it is not a backdoor :-)=20 > ( on my PC ) ..play more, say 'netstat -tulepan ', nmap, nessus etc., if=20 for nothing else, you may find new tools you like better. --=20 ..med vennlig hilsen =3D with Kind Regards from Arnt... ;-) ...with a number of polar bear hunters in his ancestry... Scenarios always come in sets of three:=20 best case, worst case, and just in case.