Re: Port Zero

From: Harlan Carvey (keydet89_at_yahoo.com)
Date: 07/19/05

  • Next message: Andrew Simmons: "Re: Port Zero"
    Date: Tue, 19 Jul 2005 07:38:23 -0700 (PDT)
    To: nony101@last.za.net, incidents@securityfocus.com
    
    

    > I had in incident yesterday (18 June 2005), where a
    > client's Windows box listed almost every possible
    > port as open, listening in the same way described
    > above. Similiar netstat -an output as above. From my
    > experience this isn't normal.
    >
    > A few hours later the machine rapidly starting
    > sending packets to random addresses on port 443.
    >
    > What could this possibly be? Is it a
    > virus/backdoor/something malicious?

    Well, there is a way to find out. One tool to use is
    Foundstone's fport.exe, but I prefer DiamondCS's
    openports.exe. These tools are used for
    process-to-port mapping; ie, determining which
    processes on the system are using which port.

    If the client's system is/was Windows XP, take a look
    at the output of "netstat /?", paying particular
    attention to the '-o' and '-b' options.

    Harlan

    ------------------------------------------
    Harlan Carvey, CISSP
    "Windows Forensics and Incident Recovery"
    http://www.windows-ir.com
    http://windowsir.blogspot.com
    ------------------------------------------


  • Next message: Andrew Simmons: "Re: Port Zero"

    Relevant Pages

    • Re: Port Zero
      ... I had in incident yesterday, where a client's Windows box listed almost every possible port as open, listening in the same way described above. ... Similiar netstat -an output as above. ... is that your whole netstat output? ...
      (Incidents)
    • Re: keeping ports open
      ... If a port is open, it means that 1) a software or service is running on your ... and 2) you're not using a firewall or your firewall isn't ... Use firewall software and hardware and antivirus software that is ... Follow the instructions for hardening Windows and IIS at ...
      (microsoft.public.security)
    • [Full-Disclosure] ron1n phone home, episode 4
      ... Hacking from Windows 3.x, 95 and NT ... Use secret Windows 95 DOS commands to track down and port surf computers ... Download hacker tools such as port scanners and password crackers designed ... Now you have the option of eight TCP/IP utilities to play with: telnet, ...
      (Full-Disclosure)
    • Re: How to Maintain an IIS Server?
      ... > server running on a Windows 2000 server. ... before a firewall and antivirus have been installed]. ... open ports; however, this will not identify which program is using the port. ...
      (microsoft.public.inetserver.iis.security)
    • Re: How to Maintain an IIS Server?
      ... >> server running on a Windows 2000 server. ... > before a firewall and antivirus have been installed]. ... > program or executable using that port. ...
      (microsoft.public.inetserver.iis.security)