Open/Listening Ports

From: gigawatt (gigawatt@cyberspace.org)
Date: 06/27/02


From: "gigawatt" <gigawatt@cyberspace.org>
Date: Thu, 27 Jun 2002 09:58:57 -0400

Heres the dilema.

I have an in-house box that utilizes various software apps that are
not commercial. The apps run on ports that have not been assigned
and are therefore difficult to determine through the services file.

I have the ability sometimes to run LSOF and this does help, actually
it tells me the exact thing (daemon etc) running there. However, in the
event that I cannot run LSOF on the box, is there a way to determine what
is running there as well as the "structure" of the packets.

I am thnking that the best way is to sniff the ether traffic associated
with that port then deconstruct the actual information to determine
the structure. Is this the best way? Is there another way?

Additionally, I have in the past always used telnet to connect, but as
you are all aware it just hangs once the connection is made due to the
service probably not understanding what to send back or expect from
the remote connection. Any ideas on actual connection and manipulation
techniques.

Hope I didnt bore you too much.

TIA
Gig



Relevant Pages

  • Open/Listening Ports
    ... I have an in-house box that utilizes various software apps that are ... The apps run on ports that have not been assigned ... I have the ability sometimes to run LSOF and this does help, ... you are all aware it just hangs once the connection is made due to the ...
    (comp.security.misc)
  • Re: Correction
    ... > I have an ADSL connection which polls my computer from time to time, ... > disables the questioned ports unless the user intervenes and allows the ... disallow each and every port with Windows Firewall? ... This policy setting also allows ...
    (microsoft.public.windowsxp.messenger)
  • D-link dsl 504 and Iptables problems
    ... I have a Bto Adsl connection plugged into a D-link DSL 504 router. ... I have then set up port forwarding on the d-link to forward ports ... $MPB ip_conntrack ... #ICMP Dead Error Messages protection ...
    (comp.os.linux.security)
  • d-link DSL-504 and IPtables trouble
    ... I have a Bto Adsl connection plugged into a D-link DSL 504 router. ... I have then set up port forwarding on the d-link to forward ports ... $MPB ip_conntrack ... #ICMP Dead Error Messages protection ...
    (comp.security.firewalls)
  • Re: Whats a decent modem/router for tech savy user?
    ... It is not possible to route or deny traffic to specific ports based on the source IP address. ... But it wont route back inside the LAN - needs internal DNS server spoofing. ... Normally, this option should be Enabled, so that an Internet connection will be made automatically, whenever Internet-bound traffic is detected. ... Specifying a Default DMZ Server allows you to set up a computer or server that is available to anyone on the Internet for services that you haven't defined. ...
    (uk.telecom.broadband)