public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
From: Adam Carter <adamcarter3@gmail.com>
To: gentoo-user@lists.gentoo.org
Subject: Re: [gentoo-user] Yahoo and strange traffic.
Date: Tue, 17 Aug 2010 11:32:51 +1000	[thread overview]
Message-ID: <AANLkTi=jtx9fnLhCG+q6vgWnkEztgoO_AXHvrx6FUbyX@mail.gmail.com> (raw)
In-Reply-To: <4C69E3CD.5070108@gmail.com>

[-- Attachment #1: Type: text/plain, Size: 2139 bytes --]

>
> I just did a killall kopete and it did stop.  Is there a way to "see" what
> it is sending/receiving?  I'm talking like is it a jpeg, some other file or
> something else?
>
>
rix portage # nmap -p 5050 -sV cs210p2.msg.sp1.yahoo.com

Starting Nmap 5.21 ( http://nmap.org ) at 2010-08-17 11:27 EST
Nmap scan report for cs210p2.msg.sp1.yahoo.com (98.136.48.110)
Host is up (0.20s latency).
PORT     STATE SERVICE VERSION
5050/tcp open  mmcc?
1 service unrecognized despite returning data. If you know the
service/version, please submit the following fingerprint at
http://www.insecure.org/cgi-bin/servicefp-submit.cgi :
SF-Port5050-TCP:V=5.21%I=7%D=8/17%Time=4C69E58D%P=i686-pc-linux-gnu%r(GetR
SF:equest,195,"HTTP/1\.1\x20404\x20Not\x20Found\r\nContent-Type:\x20text/h
SF:tml\r\nCache-Control:\x20max-age=0,\x20must-revalidate\r\nExpires:\x20S
SF:un,\x2010\x20Jun\x202007\x2012:01:01\x20GMT\r\n\r\n<html><head>\r\n<met
SF:a\x20http-equiv=\"content-type\"\x20content=\"text/html;charset=utf-8\"
SF:>\r\n<title>404\x20Not\x20Found</title>\r\n</head>\r\n<body\x20text=#00
SF:0000\x20bgcolor=#ffffff>\r\n<hr><center>\r\n<H1>Not\x20Found</H1>\r\nTh
SF:e\x20requested\x20URL\x20was\x20not\x20found\x20on\x20this\x20server\.\
SF:r\n</center><p>\r\n</body></html>\r\n")%r(FourOhFourRequest,195,"HTTP/1
SF:\.1\x20404\x20Not\x20Found\r\nContent-Type:\x20text/html\r\nCache-Contr
SF:ol:\x20max-age=0,\x20must-revalidate\r\nExpires:\x20Sun,\x2010\x20Jun\x
SF:202007\x2012:01:01\x20GMT\r\n\r\n<html><head>\r\n<meta\x20http-equiv=\"
SF:content-type\"\x20content=\"text/html;charset=utf-8\">\r\n<title>404\x2
SF:0Not\x20Found</title>\r\n</head>\r\n<body\x20text=#000000\x20bgcolor=#f
SF:fffff>\r\n<hr><center>\r\n<H1>Not\x20Found</H1>\r\nThe\x20requested\x20
SF:URL\x20was\x20not\x20found\x20on\x20this\x20server\.\r\n</center><p>\r\
SF:n</body></html>\r\n");

Service detection performed. Please report any incorrect results at
http://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 112.82 seconds
rix portage #


Well its obviously HTTP, NFI why NMAP cant see that. So you could capture in
wireshark, then docode port 5050 as HTTP.

[-- Attachment #2: Type: text/html, Size: 2954 bytes --]

  reply	other threads:[~2010-08-17  1:32 UTC|newest]

Thread overview: 31+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2010-08-15 20:34 [gentoo-user] Yahoo and strange traffic Dale
2010-08-15 20:55 ` Paul Hartman
2010-08-15 21:18   ` BRM
2010-08-15 21:35     ` Dale
2010-08-15 22:25       ` Peter Humphrey
2010-08-15 22:48         ` Dale
2010-08-15 21:29   ` Alan McKinnon
2010-08-16 22:55     ` Dale
2010-08-16 23:39       ` Adam Carter
2010-08-17  1:20         ` Dale
2010-08-17  1:32           ` Adam Carter [this message]
2010-08-17  5:46             ` Dale
2010-08-17  6:09               ` Adam Carter
2010-08-17 10:23                 ` Dale
2010-08-17 11:15                   ` Jake Moe
2010-08-17 11:26                     ` Dale
2010-08-17 14:29                   ` BRM
2010-08-17 16:10                     ` Mick
2010-08-17 20:15                       ` Dale
2010-08-17 21:11                         ` Mick
2010-08-17 21:32                           ` Dale
2010-08-18  2:09                             ` BRM
2010-08-18  2:18                               ` Dale
2010-08-18  2:18                               ` Dale
2010-08-25  2:36                     ` Dale
2010-08-25  8:08                       ` Joshua Murphy
2010-08-25  9:58                         ` Dale
2010-08-25 13:21                           ` BRM
2010-08-25 13:57                             ` Joshua Murphy
2010-08-25 22:34                               ` Dale
2010-08-15 21:32 ` Mick

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to='AANLkTi=jtx9fnLhCG+q6vgWnkEztgoO_AXHvrx6FUbyX@mail.gmail.com' \
    --to=adamcarter3@gmail.com \
    --cc=gentoo-user@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox