[ale] Ports and IP spoofing??

Jonathan Rickman jonathan at xcorps.net
Mon Jan 27 21:13:13 EST 2003


On Mon, 27 Jan 2003, Adrin wrote:

> It there a away to find out what software uses a port?
> I am looking for what could be using 4101.
>
> IP spoofing. This is confusing. I have an address that starts with 0.
> and I don't think that is a valid IP range. Is it possible to back trace something like
> this?

Assuming we're talking Linux (this is ALE) the following tool should
suffice for your first question: http://freshmeat.net/projects/lsof/

As to the second question, I can probably assist with some more details.
The truly spoofed TCP connection is not that common, despite what you may
have been led to believe. UDP is anther story.

--
Jonathan Rickman
X Corps Security
http://www.xcorps.net

_______________________________________________
Ale mailing list
Ale at ale.org
http://www.ale.org/mailman/listinfo/ale






More information about the Ale mailing list