Menu ▾ ▴

#6 False positive unhide-tcp

v1.0_(example)
open
nobody
None
5
2015-11-10
2015-11-10
Kitserve
No

Stock AMD64 Debian Jessie install running Dovecot IMAPS on port 993 with unencrypted IMAP on port 143 disabled. Server also runs Privoxy bound on an IPv4 address that ends in .143, which I suspect is the cause of the false positive. Relevant debugging output follows. Further information can be supplied if useful.

root@host:~# unhide-tcp -flov
Unhide-tcp 20121229
Copyright © 2012 Yago Jesus & Patrick Gouin
License GPLv3+ : GNU GPL version 3 or later
http://www.unhide-forensics.info
Used options: verbose use_lsof use_fuser logtofile 
[*]Starting TCP checking

Found Hidden port that not appears in ss: 143
    fuser reports :
    lsof reports :
[*]Starting UDP checking

root@host:~# ss | grep 143
u_str  ESTAB      0      0      /var/run/dbus/system_bus_socket 14321                 * 14320  
u_str  ESTAB      0      0                    * 14320                 * 14321  

root@host:~# ss | grep imap
tcp    ESTAB      0      0       x.x.x.x:imaps     y.y.y.y:47851
tcp    ESTAB      0      0       x.x.x.x:imaps     y.y.y.y:36128
tcp    ESTAB      0      0       x.x.x.x:imaps     y.y.y.y:47832

root@host:~# netstat -anpt | grep 143
tcp        0      0 x.x.x.143:8118     0.0.0.0:*               LISTEN      876/privoxy     

root@host:~# nc -l -p 143
<works successfully, I can communicate with nc by running `telnet localhost 143`>

root@host:~# nc -l -p 993
Can't grab 0.0.0.0:993 with bind

Discussion


Log in to post a comment.