Re: How to find a process



With the WinXP and 2k3 Server versions of netstat the '-o' option will
also output the Process ID#. Or '-b' will give you the executable name
and the PID, using '-v' along with '-b' will display the DLL(s)
responsible for that particular connected/listening port. You can also
set it automatically dump the info on a set interval. (NOTE: I don't
believe some or all of these options work on Win2k, but I don't have a
2k box handy to test)

i.e., the command 'netstat -b -v 30' will dump info on executable and
DLL responsible for the ports and it will run itself again every 30
seconds until you hit <CTRL>+C.

Now, if you want a GUI, path and command for each executable and the
ability to kill process connections, I'd check out SysInternals
TCPView.

-- Ned

"Francisco Rodrigo Cortinas Maseda"
<francisco.cortinas@xxxxxxxxxxx> 06/13/07 05:32AM >>>
Hello,

my name is Fran, im a network and system administrator, and i have a
strange case, but sure somenone have had the same problem before me.

My problem is that we have some strange traffic on the firewalls,
going
from a server on a DMZ to public client pools.

10:09:10.511978 00:0e:0c:71:7f:cd > 10:00:00:00:26:01, ethertype IPv4
(0x0800), length 61: IP XXXXX.44267 > XXXXXX.3072: UDP, length 19

The problem is: with netstat i only see the ports daemons are
listening
on. I want to know the process that is using the outgoing port, that
is,
44267.

Is there a way to know this?

Thanks in advance.
Regards.



Relevant Pages

  • Re: Is this a Virus? Spammer? Emails sent to unkown address...
    ... Giving us more info about the netstat ... results, like the port number, would be helpful. ... netstat was done on your mail server? ... If your email server is set up for relaying, which is bad, you should ...
    (comp.security.firewalls)
  • Re: SQL Server does not exist or access denied.
    ... netstat -noa shows a bunch of local local processes, ... Dumb question first: The server is running? ... Look for the process ID of the server process in task manager. ... not being able to connect with port 1443. ...
    (microsoft.public.dotnet.languages.vb)
  • Re: Ports schliessen
    ... Trotzdem wird dieser Port bei verschiedenen Portscans ... Da wage ich am Test zu zweifeln, oder daran, daß kein Server läuft. ... sagt NETSTAT, ...
    (microsoft.public.de.security.heimanwender)
  • RE: Publish a terminal server on ISA 2006
    ... Still cannot reach the internal server. ... IMPORTANT NOTE - netstat -an does not list the terminal port, ... since I don't think the ISA server is listening on ...
    (microsoft.public.isa)
  • RE: Some technical errors
    ... If the SMTP server is not running on port 25 TCP it is not a public ... Manager - Computer Assurance Services BDO Chartered Accountants & ...
    (Security-Basics)