Re: NT Compromise

From: Nexus (nexus@patrol.i-way.co.uk)
Date: 12/19/01


From: "Nexus" <nexus@patrol.i-way.co.uk>
To: "Eric Hines" <eric3+@pitt.edu>, <incidents@securityfocus.com>
Date: Wed, 19 Dec 2001 21:52:39 -0000

This will do the trick:
http://www.winternals.com/products/monitoringtools/tcpviewpro.asp

Cheers.

> I am responding to several compromised NT boxes and am trying to find a
> utility that will allow you to see what program is bound to a particular
> port. I think I've seen one that shows what ports are bound to

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: NT Compromise
    ... > I am responding to several compromised NT boxes and ... > port. ... Check out Yahoo! ...
    (Incidents)
  • RE: RWW fails from Internet
    ... Port 80 is not the general problem. ... >This newsgroup only focuses on SBS technical issues. ... When responding to posts via your newsreader, ... >| Subject: RE: RWW fails from Internet ...
    (microsoft.public.windows.server.sbs)
  • Re: [fw-wiz] FW: OT? New compromise.
    ... If you suspect you have a rootkit, it shouldn't be that hard to find it, ... depending on whether you can shut down any of these boxes and run Knoppix ... Port 1863 is the port for Microsoft's Instant Messenger client ...
    (Firewall-Wizards)
  • Re: Automated Nmap Scans / Front End
    ... I am responsible for monitoring hundreds of machines ... -Have the tool scan all ranges to determine responding ... You can also consider using hping to check for the netbios port rather than a basic icmp. ...
    (Pen-Test)
  • Re: Port scan causing system crashes
    ... Well, I have such problems last year as well, on old Sun boxes. ... same result than a port scan Dos. ... Port scan causing system crashes ...
    (Pen-Test)