next up previous
Next: Kernel processes Up: Firewall audit for Ottawa Previous: Inbound port scan

Firewall internals: active processes

The following process table was observed on the firewall. (it has been slightly edited to fit the page)

Following this is a detailed breakdown of all processes found on the firewall, a description of what the process does and whether or not the process should be running.

  PID TTY STAT TIME COMMAND
    1  ?  S    0:03 init 
    2  ?  SW   0:00 (kflushd)
    3  ?  SW<  0:00 (kswapd)
   46  ?  S    0:00 /sbin/kerneld 
  278  ?  S    0:00 syslogd 
  287  ?  S    0:00 klogd 
  309  ?  S    0:00 crond 
  331  ?  S    0:00 inetd 
  342  ?  S    0:00 named 
  353  ?  S    0:00 lpd 
  368  ?  S    0:00 sendmail: accepting connections on port 25                 
  380  ?  S    0:00 gpm -t ps/2 
  395   1 S    0:00 /sbin/mingetty tty1 
  396   2 S    0:00 /sbin/mingetty tty2 
  397   3 S    0:00 /sbin/mingetty tty3 
  398   4 S    0:00 /sbin/mingetty tty4 
  399   5 S    0:00 /sbin/mingetty tty5 
  400   6 S    0:00 /sbin/mingetty tty6 
  401  ?  S    0:00 /usr/bin/X11/xdm -nodaemon 
  403  ?  S    0:00 update (bdflush) 
  405  ?  S    0:06 /usr/X11R6/bin/X 
  406  ?  S    0:00 -:0                        
  417  ?  S    0:00 fvwm2 -cmd FvwmM4 
  497  ?  S    0:00 /usr/X11R6/lib/X11/fvwm2//FvwmTaskBar 
  498  ?  S    0:00 /usr/X11R6/lib/X11/fvwm2//FvwmButtons 
  503  ?  S    0:00 /usr/X11R6/lib/X11/fvwm2//FvwmPager 
  500  ?  S    0:00 nxterm +ut -geometry +153+115 
  501  ?  S    0:00 control-panel -geometry -0+0 
  502  ?  S N  0:00 xload -nolabel -geometry 32x20+0+0 
  504  p1 S    0:00 -csh 
  518  p1 S    0:00 xterm -name TOP 
  519  p0 S    0:00 -csh 
  530  p0 S    0:01 top 
  552  p1 S    0:00 script 
  553  p1 S    0:00 script 
  554  p2 S    0:00 -csh -i 
  566  ?  S    0:00 nxterm 
  567  p3 S    0:00 -csh 
  589  p2 R    0:00 ps ax 
  320  ?  S    0:00 portmap 
  298  ?  S    0:00 /usr/sbin/atd



 

Michael C. Richardson
1998-11-15