[ale] Ports and IP spoofing??
Jonathan Rickman
jonathan at xcorps.net
Mon Jan 27 21:13:13 EST 2003
On Mon, 27 Jan 2003, Adrin wrote:
> It there a away to find out what software uses a port?
> I am looking for what could be using 4101.
>
> IP spoofing. This is confusing. I have an address that starts with 0.
> and I don't think that is a valid IP range. Is it possible to back trace something like
> this?
Assuming we're talking Linux (this is ALE) the following tool should
suffice for your first question: http://freshmeat.net/projects/lsof/
As to the second question, I can probably assist with some more details.
The truly spoofed TCP connection is not that common, despite what you may
have been led to believe. UDP is anther story.
--
Jonathan Rickman
X Corps Security
http://www.xcorps.net
_______________________________________________
Ale mailing list
Ale at ale.org
http://www.ale.org/mailman/listinfo/ale
More information about the Ale
mailing list