Possible security problem?
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


comp.security.firewalls archive

Possible security problem?

From: Tony Cameron <Darkscribe01@hotmail.com>
Date: Wed Jul 27 2005 - 16:16:30 CEST

I am running a Mac G5 with 10.3.9 and have just discovered that at
regular but intermittent intervals, several times an hour, the process
nmbd attempts to make a UDP contact with a wide variety of addresses
mostly US based, but some European, on various ports ranging from 135 to
62253.

I run Firewalk X2 but have not worried in the past about what apps and
processes were getting out, just incoming, but turned logging on the
other day and discovered this consistent communication. I have blocked
nmbd for the moment, with no apparent ill effects, but I am very curious
as to the reason behind it. I don't see how I could have been hacked,
but it does look suspicious.

This occurs regardless of the apps running at the time, even after
rebooting and with nothing aside from system services started. I do have
Virtual PC on the system, but even with it not started, or killing it
from the activity monitor makes no difference to the activity. Samba is
not running.

Can anybody shed some light on this? Google doesn't seem to offer much
in the way of explanation.

Regards

Tony
Received on Thu Sep 29 19:59:32 2005