From owner-freebsd-questions@FreeBSD.ORG Sat Sep 18 23:27:50 2010 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 3848D106566C for ; Sat, 18 Sep 2010 23:27:50 +0000 (UTC) (envelope-from carlj@peak.org) Received: from redcondor2.peak.org (redcondor2.peak.org [69.59.192.56]) by mx1.freebsd.org (Postfix) with ESMTP id 108CE8FC17 for ; Sat, 18 Sep 2010 23:27:49 +0000 (UTC) Received: from peak-mail-gateway.peak.org ([69.59.192.41]) by redcondor2.peak.org ({e8dac926-1ec8-47e6-b410-31008b345fb7}) via TCP (outbound) with ESMTP id 20100918232749254 for ; Sat, 18 Sep 2010 23:27:49 +0000 X-RC-FROM: X-RC-RCPT: Received: from oak.localnet (207.55.91.197.peak.org [207.55.91.197] (may be forged)) by peak-mail-gateway.peak.org (8.12.10/8.12.8) with ESMTP id o8INRmSl066070 for ; Sat, 18 Sep 2010 16:27:49 -0700 (PDT) Received: from oak.localnet (localhost [127.0.0.1]) by oak.localnet (Postfix) with ESMTP id 653FDCC95 for ; Sat, 18 Sep 2010 16:27:48 -0700 (PDT) Received: (from carlj@localhost) by oak.localnet (8.14.4/8.14.4/Submit) id o8INRl0q020204; Sat, 18 Sep 2010 16:27:47 -0700 (PDT) (envelope-from carlj@peak.org) X-Authentication-Warning: oak.localnet: carlj set sender to carlj@peak.org using -f From: Carl Johnson To: freebsd-questions@freebsd.org Date: Sat, 18 Sep 2010 16:27:47 -0700 Message-ID: <87pqwar5sc.fsf@oak.localnet> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/23.2 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Subject: extra open ports in rkhunter X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 18 Sep 2010 23:27:50 -0000 I am running rkhunter and it keeps reporting a port inconsistency between sockstat and netstat -a. Netstat shows an extra 5 ports open, but netstat doesn't show what is holding ports open, so I don't know what they are. Does anybody know how to determine what is holding open a port? I have been looking around but none of my ideas show anything. This is a full desktop system with KDE4 and VirtualBox running, so it has a lot of things running. The following are the ports if anybody has any ideas, but I would also like to know how to trace them down myself: tcp4 0 0 *.876 *.* LISTEN tcp6 0 0 *.921 *.* LISTEN udp4 0 0 *.608 *.* udp6 0 0 *.952 *.* udp6 0 0 *.804 *.* -- Carl Johnson carlj@peak.org