Re: Couple of strange entries in netstat
From: Chuck (cacrollthespam_at_yahoo.com)
Date: 09/20/03
- Next message: Bill Unger: "Your Opinion - Best Site for Update IT Security News"
- Previous message: Pete: "Re: Seek on-demand AV scanner to complement NAV"
- In reply to: Donald Jacobsen: "Couple of strange entries in netstat"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Sat, 20 Sep 2003 07:52:39 -0700
On Sat, 20 Sep 2003 13:15:13 GMT, "Donald Jacobsen"
<dmj@nospam.midsouth.rr.com> wrote:
>Hello all,
>
> Started seeing some weird disk activity on my computer, so I decided to
>check my system out, looking for backdoors, etc. Antivirus and Adaware
>didn't pick up anything, but when I ran netstat, I got this:
>
>Active Connections
>
> Proto Local Address Foreign Address State
> (snipped)
> TCP balrog:2416 localhost:43958 ESTABLISHED
> TCP balrog:43958 localhost:2416 ESTABLISHED
>
>No clue what these port numbers are. Why would my system be connecting to
>itself on these 2 ports?
>
>Thanks,
>--Donald
>
You need to know what process has attached those ports. A good, free
port mapper is Active Ports.
http://www.ntutility.com/freeware.html
Much more useful than netstat.
Cheers,
Chuck
Chuck
cacrollthespam@yahoo.com
Spam sucks - PLEASE get rid of the spam before emailing me!
- Next message: Bill Unger: "Your Opinion - Best Site for Update IT Security News"
- Previous message: Pete: "Re: Seek on-demand AV scanner to complement NAV"
- In reply to: Donald Jacobsen: "Couple of strange entries in netstat"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|