Re: BackOrifice on Linux?

> >>I just ran the command "sudo nmap  -sT -sU localhost" which listed the 
> >>12345/tcp  open        NetBus                 
> >>12346/tcp  open        NetBus                 
> >>27665/tcp  open        Trinoo_Master          
> >>31335/udp  open        Trinoo_Register        

> >>Should I be concerned, or is this maybe part of portsentry or something 
> >>similar?

> Looks like it may just be part of portsentry. Thanks!
One of the annoying aspects of portsentry is that it opens the ports it
listens on.  This can lead to false-positive alerts when scanning your
own systems.

Snort is another package which detects traffic on ports but doesn't open
them.  I'd recommend it as an alternative.


