I have recently had a message from MSEC telling me there was a new user listening at port 12. It was blacklisted and no further warnings have been seen. I am running Mageia 2 with KDE 4 desktop. I looked at /var/log/security/mail.daily.today and saw the following:
*** Security Check, Nov 23 09:15:16 ***
*** Check type: daily ***
*** Check executed from: /etc/cron.daily/msec ***
Report summary:
Test started: Nov 23 09:15:16
Test finished: Nov 23 09:15:22
Total of open network ports: 34
Total of configured firewall rules: 101
Total local users: 29
Total local group: 52
Detailed report:
These are the ports listening on your machine :
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State Program name
tcp 0 0 *:ipp : LISTEN cupsd
tcp 0 0 *:omniorb : LISTEN java
tcp 0 0 *:microsoft-ds : LISTEN smbd
tcp 0 0 *:nfs : LISTEN -
tcp 0 0 *:38210 : LISTEN rpc.mountd
tcp 0 0 *:47911 : LISTEN -
tcp 0 0 *:netbios-ssn : LISTEN smbd
tcp 0 0 *:49100 : LISTEN rpc.mountd
tcp 0 0 *:59694 : LISTEN rpc.mountd
tcp 0 0 *:52239 : LISTEN rpc.statd
tcp 0 0 *:sunrpc : LISTEN rpcbind
tcp 0 0 localhost:7634 : LISTEN hddtemp
udp 0 0 *:nfs : -
udp 0 0 *:52290 : avahi-daemon: r
udp 0 0 *:bootpc : dhclient
udp 0 0 *:47175 : rpc.mountd
udp 0 0 *:sunrpc : rpcbind
udp 0 0 *:ipp : cupsd
udp 0 0 192.168.0.255:netbios-ns : nmbd
udp 0 0 localhost:netbios-ns : nmbd
udp 0 0 *:netbios-ns : nmbd
udp 0 0 192.168.0.255:netbios-dgm : nmbd
udp 0 0 localhost:netbios-dgm : nmbd
udp 0 0 *:netbios-dgm : nmbd
udp 0 0 localhost:676 : rpc.statd
udp 0 0 *:mdns : avahi-daemon: r
udp 0 0 *:26393 : dhclient
udp 0 0 *:34606 : rpc.statd
udp 0 0 *:48472 : -
udp 0 0 *:58728 : rpc.mountd
udp 0 0 *:53702 : rpc.mountd
udp 0 0 *:1003 : rpcbind
I am concerned about the entries mentioning microsoft, the ones with no name, those called mdns and nmbd. Can anyone please advise?