Re: DCOM Listening Ports

From: alan (me_at_privacy.net)
Date: 12/25/03


Date: Thu, 25 Dec 2003 14:15:32 -0000


"Anonymous" <monster5001@hotmail.com> wrote in message
news:1d6d478d.0312242143.3b37fad@posting.google.com...
| I do a netstat -an and I have several ports related to DCOM
which are listening. Ports 1025 and 1027 particularly.

| Here is an example exactly as shown in Netstat
|
| TCP 0.0.0.0:1025 0.0.0.0:0 LISTENING

The link below explains that some ports will continue to be
shown as 'listening' in netstat despite tightening up your
security. This does not necessarily mean you are at risk.
To quote the article "The netstat command does not exactly
report TCP and UDP ports states".

http://www.hsc.fr/ressources/breves/min_srv_res_win.en.html

You will find that disabling the service Task Scheduler will
eventually be needed (after following the other advice) to
ensure the netstat display is free of these entries.

If you disable Task Scheduler of course you will lose some
other functionality - for example Windows Prefetch will no
longer work and I am not prepared to lose this useful
feature of XP.

The article has been translated from the original French so it is
a little uneven but I managed to implement all the
recommended changes (apart from disabling Task Schedule).

Hope it helps

Alan



Relevant Pages

  • Re: ServU-deamon trojan warning with McAfee
    ... This PLAIN and SIMPLE shouldn't happen in an ISA controlled ... A NETSTAT can reveal some information, ... listening on that port and passes 'normal' traffic to my SMTP but also ... > only needed TCP ports listening. ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Firewalls offer no REAL outbound protection????
    ... At least, on my Win2K ... There is a known bug in Win2K netstat, showing ports as "listening" ...
    (comp.security.firewalls)
  • Re: How to find a process
    ... "netstat -lp" will show all ports in the listening state and the PID ... of the process listening on that port. ... with netstat i only see the ports daemons are listening ...
    (Security-Basics)
  • Re: hacked?
    ... So I ssh'd in and did a netstat and saw what looked like an unwanted SSH connection... ... On the local host type nmap -sV localhost -p 1-65535 to see what ports respond and which apps/services. ...
    (comp.os.linux.misc)
  • Win2k Netstat sockets interpretation
    ... BUT, netstat /a indicates netbios ports 137,138,139,445 listening when I allow ZA to allow T-bird to act as a server to connect to the ... but Akamaitech~ is frequently there and firefox always has 4 connections local and 4 remote open inaddition to the url i am browsing???? ... The output from Ethereal showed a big download in the background from google...hex and what looks like certificates or host file additions to banks .....I no option to control F.F. updates and like to know when/what is updated since permissions and options have a nasty habit of being reset to 'lame' when updates happen silently ...
    (alt.computer.security)