Help!!VPS access other websites without my knowing

Discussion in 'Site & Server Administration' started by wlanguide, Dec 26, 2011.

  1. #1
    Hi guys, I just installed CentOS 6, LAMP, and after finishing everything I found something weird.

    When I type this command netstat -an I find lots of Time-wait, the foreign address are as follows:

    184.72.186.1
    74.125.224.79
    74.125.127.103
    74.125.127.106

    I do not use commands that require internet connection, actually its a web server. So I have no idea my VPS visits other websites.

    When I type lsof -i port and it gives me nothing, I also tried netstat command with lots of variants but just could NOT find which process opened these ports?

    I tried some anti rootkit thing and found nothing infected, so what should I do? Is there anything wrong with my VPS?

    Thanks
     
    wlanguide, Dec 26, 2011 IP
  2. ProxyFreak

    ProxyFreak Peon

    Messages:
    57
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Those are Google IP's so I do not believe Google has hacked your server :) netstat -anp and ps aux shows a lot more.
     
    ProxyFreak, Dec 26, 2011 IP
  3. wlanguide

    wlanguide Peon

    Messages:
    42
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Neither do I :), I tried netstat -anp, but there is no PID, I have no idea what is going on, could you help?

    Thanks
     
    wlanguide, Dec 27, 2011 IP
  4. BigTim3

    BigTim3 Guest

    Messages:
    266
    Likes Received:
    1
    Best Answers:
    2
    Trophy Points:
    0
    #4
    is this the http service?
     
    BigTim3, Dec 30, 2011 IP
  5. secureax

    secureax Member

    Messages:
    22
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    38
    #5
    Why not you post the entire netstat output for us to review?
     
    secureax, Jan 1, 2012 IP
  6. olddocks

    olddocks Notable Member

    Messages:
    3,275
    Likes Received:
    165
    Best Answers:
    0
    Trophy Points:
    215
    #6
    i think those are resolver ips, necessary to resolve names. checkout /etc/resolv.conf
     
    olddocks, Jan 5, 2012 IP