Interesting Network Traffic...

  • Hope this is in the correct forum..??


    Hello everyone!!



    I'm trying to figure out what is going on with this network connection to my server.


    I ran tcptrack -i eth0 and was looking at the various TCP connections made to the server and they IPs associated with them. This one seems out of place and I have no idea what it could be.


    192.168.0.253:55885 <---------- Server 45.56.106.157:443 <------- IDK who or what this is ESTABLISHED 5s 0 B/s


    looking up in ARIN it shows it belongs to LINODE's block 45.56.64.0/18 http://whois.arin.net/rest/net/NET-45-56-64-0-1/pft


    LINODE provides Linux VPS for rent. https://www.linode.com/


    I have no idea what TCP port 55885 is and it looks like its communicating with port 443 (https/SSL/TLS) - SSL VPN maybe??


    Does anyone else have that port /IP used on their server. To be safe I changed root's password via ssh. After running the who command it only shows my established sessions for my logins.


    Looking at tcptrack there isn't much data being transmitted in the session. I even ran wireshark on another LAN PC and wasn't able to find anything yet...



    Please let me know if you have any info on this!!!???!!!


    - Heman22union

    • Offizieller Beitrag

    Outgoing connections are on random ports, nothing unusual there, so don't worry about that, many applicatiions will do the same unless you speciffy it (like deluge torrent)


    Now, why is connecting there no idea. Is your server you need to figure it out. 443 could be https also.


    Do you use ssh with just password and port 22?

    • Offizieller Beitrag

    Did you look at what processes were running?

    omv 7.0.5-1 sandworm | 64 bit | 6.8 proxmox kernel

    plugins :: omvextrasorg 7.0 | kvm 7.0.13 | compose 7.1.4 | k8s 7.1.0-3 | cputemp 7.0.1 | mergerfs 7.0.4


    omv-extras.org plugins source code and issue tracker - github - changelogs


    Please try ctrl-shift-R and read this before posting a question.

    Please put your OMV system details in your signature.
    Please don't PM for support... Too many PMs!

  • I looked even further...


    root@OMV:~# lsof -i :55885
    COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
    Plex 18095 plex 69u IPv4 5868591 0t0 TCP OMV.home:55885->li908-157.m embers.linode.com:https (ESTABLISHED)


    Looks like its PLEX.... Kinda worries me still, but I guess its ok...

Jetzt mitmachen!

Sie haben noch kein Benutzerkonto auf unserer Seite? Registrieren Sie sich kostenlos und nehmen Sie an unserer Community teil!