Sponsored Content
Special Forums Cybersecurity FTP logfile shows strange activity at login Post 302349777 by TonyFullerMalv on Tuesday 1st of September 2009 07:15:57 PM
Old 09-01-2009
Try running a whois against each unexpected IP address but one thought is that there is a DNS problem causing "odd" IP addresses to turn up for the name of your host perhaps?
 

7 More Discussions You Might Find Interesting

1. HP-UX

setup a logfile for user login/logout ???

Hi everybody, im a newer, i want to setup a logfile to capture information about user login/logout (and some other events ex: a user ftp, run a speacial command) on my system in HP-UX, pls help me. i think only edit file /etc/syslog.conf but dont know how to do it. Help me. (0 Replies)
Discussion started by: pwd
0 Replies

2. UNIX for Dummies Questions & Answers

setup a logfile for user login/logout ???

Hi everybody, im a newer, i want to setup a logfile to capture information about user login/logout (and some other events ex: a user ftp, run a speacial command) on my system in HP-UX, pls help me. i think only edit file /etc/syslog.conf but i dont know how to do it. Help me. (3 Replies)
Discussion started by: pwd
3 Replies

3. HP-UX

HP-UX strange login problem

Hi, I am faceing strange login problem in HP-UX. I am sending login username through tcl script in telnet session. After opening new telnet session prompt comes as, login: but it not able to handle or get username whatever i am sending.If i press an enter then every thing goes... (1 Reply)
Discussion started by: ashokd009
1 Replies

4. HP-UX

Strange login behaviour

Hi all, I am using HP-UX and I have just noticed that when I log into the network it seems to save the previous windows that were subsequently closed on previous occasions. Does anyone know when I log in, it seems to display these previous windows, e.g. nedit windows open again? Does... (1 Reply)
Discussion started by: cyberfrog
1 Replies

5. UNIX for Dummies Questions & Answers

FTP that works correctly in command prompt and shows issue in UNIX server

Hi All, FTP ports opens with the given user name and password and allows to download file through COMMAND PROMPT. Code as below: H:\>ftp ftpxxxxx Connected to entvc2ft07-pub.xxxxx.com. 220 Microsoft FTP Service User (entvc2ft07-pub.xxxxx.com:(none)): userxxxxx 331 User name okay, need... (1 Reply)
Discussion started by: vijayalakshmi.r
1 Replies

6. UNIX for Dummies Questions & Answers

Strange system activity no matter what I try

When I choose to encrypt my drive during a Linux install, it encryps it, but I receive errors in dmesg and in ~/.xsessions-errors during use. The first error is in dmesg where it sometimes shows errors writing to the encypted device. The second error is in ~/.xsessions-errors with an error about... (0 Replies)
Discussion started by: justgoogleit
0 Replies

7. Solaris

FTP log only shows FTP LOGIN FROM entry?

OS: Solaris 9 Configuration /etc/syslog.conf daemon.debug /etc/inetd.conf ftp stream tcp6 nowait root /usr/sbin/in.ftpd in.ftpd -A -l -d Found the ftp.log only generate those entries from other servers/hosts. Can we trace on all ftp entries either from/to the server? ... (6 Replies)
Discussion started by: KhawHL
6 Replies
WHOIS(1)						    BSD General Commands Manual 						  WHOIS(1)

NAME
whois -- Internet domain name and network number directory service SYNOPSIS
whois [-aAdgilmQrR6] [-c country-code | -h host] [-p port] name ... DESCRIPTION
The whois utility looks up records in the databases maintained by several Network Information Centers (NICs). The options are as follows: -a Use the American Registry for Internet Numbers (ARIN) database. It contains network numbers used in those parts of the world covered neither by APNIC nor by RIPE. (Hint: All point of contact handles in the ARIN whois database end with "-ARIN".) -A Use the Asia/Pacific Network Information Center (APNIC) database. It contains network numbers used in East Asia, Australia, New Zea- land, and the Pacific islands. -c country-code This is the equivalent of using the -h option with an argument of "country-code.whois-servers.net". -d Use the US Department of Defense database. It contains points of contact for subdomains of .MIL. -g Use the US non-military federal government database, which contains points of contact for subdomains of .GOV. -h host Use the specified host instead of the default variant. Either a host name or an IP address may be specified. By default whois constructs the name of a whois server to use from the top-level domain (TLD) of the supplied (single) argument, and appending ".whois-servers.net". This effectively allows a suitable whois server to be selected automatically for a large number of TLDs. In the event that an IP address is specified, the whois server will default to the American Registry for Internet Numbers (ARIN). If a query to ARIN references APNIC, LACNIC, or RIPE, that server will be queried also, provided that the -Q option is not specified. If the query is not a domain name or IP address, whois will fall back to whois.crsnic.net. -i Use the Network Solutions Registry for Internet Numbers (whois.networksolutions.com) database. It contains network numbers and domain contact information for most of .COM, .NET, .ORG and .EDU domains. NOTE! The registration of these domains is now done by a number of independent and competing registrars and this database holds no information on the domains registered by organizations other than Network Solutions, Inc. Also, note that the InterNIC database (whois.internic.net) is no longer handled by Network Solutions, Inc. For details, see http://www.internic.net/. (Hint: Contact information, identified by the term handle, can be looked up by prefixing "handle " to the NIC handle in the query.) -l Use the Latin American and Caribbean IP address Regional Registry (LACNIC) database. It contains network numbers used in much of Latin America and the Caribbean. -m Use the Route Arbiter Database (RADB) database. It contains route policy specifications for a large number of operators' networks. -p port Connect to the whois server on port. If this option is not specified, whois defaults to port 43. -Q Do a quick lookup. This means that whois will not attempt to lookup the name in the authoritative whois server (if one is listed). This option has no effect when combined with any other options. -r Use the R'eseaux IP Europ'eens (RIPE) database. It contains network numbers and domain contact information for Europe. -R Use the Russia Network Information Center (RIPN) database. It contains network numbers and domain contact information for subdomains of .RU. This option is deprecated; use the -c option with an argument of "RU" instead. -6 Use the IPv6 Resource Center (6bone) database. It contains network names and addresses for the IPv6 network. The operands specified to whois are treated independently and may be used as queries on different whois servers. EXAMPLES
Most types of data, such as domain names and IP addresses, can be used as arguments to whois without any options, and whois will choose the correct whois server to query. Some exceptions, where whois will not be able to handle data correctly, are detailed below. To obtain contact information about an administrator located in the Russian TLD domain "RU", use the -c option as shown in the following example, where CONTACT-ID is substituted with the actual contact identifier. whois -c RU CONTACT-ID (Note: This example is specific to the TLD "RU", but other TLDs can be queried by using a similar syntax.) The following example demonstrates how to obtain information about an IPv6 address or hostname using the -6 option, which directs the query to 6bone. whois -6 IPv6-IP-Address The following example demonstrates how to query a whois server using a non-standard port, where ``query-data'' is the query to be sent to ``whois.example.com'' on port ``rwhois'' (written numerically as 4321). whois -h whois.example.com -p rwhois query-data SEE ALSO
Ken Harrenstien and Vic White, NICNAME/WHOIS, 1 March 1982, RFC 812. HISTORY
The whois command appeared in 4.3BSD. BSD
December 15, 2001 BSD
All times are GMT -4. The time now is 03:43 AM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy