Re: AIM Send out random messages

From: Lord Loki (LordLoki_at_discussions.microsoft.com)
Date: 05/24/05


Date: Tue, 24 May 2005 14:50:06 -0700

ok.... i have....

WkCalRem.exe
msmsgs.exe
wmiapsrv.exe
taskmgr.exe
WkUFind.exe
msnmsgr.exe
CDAEMON.EXE
PCMService.exe
iexplore.exe
iexplore.exe
NotifyAlert.exe
CCAPP.EXE
ViewMgr.exe
mmtask.exe
realsched.exe
DadApp.exe
tfswctrl.exe
Dsentry.exe
BCMSMMSG.exe
atipaxx.exe
SynTPEnh.exe
SynTPLpr.exe
Support.exe
alg.exe
spoolsv.exe
CCEVTMGR.EXE
SPBBCSvc.exe
SNDSrvc.exe
explorer.exe
ISSVC.exe
CCSETMGR.EXE
CCPROXY.EXE
NAVAPSVC.EXE
cisvc.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
ati2evxx.exe
lsass.exe (that might be Isass.exe cant tell if its an i or l)
services.exe
winlogon.exe
csrss.exe
smss.exe
BCMWLTRY.EXE
WLTRYSVC.EXE
wdfmgr.exe
symlcsvc.exe
svchost.exe
System
System Idle Process

there, thats whats currently up, there should be 52... (thats about the
number i almost always have... i have 2 msn messages open and the msn unit, 4
internet explores, task manager and thats all i personally turned on today)
well.... I dont wanna make an error going through that list and removing
duplicates and or things that are the same as yours since some are only
different from one letter... I just hope that its info that can be freely
shared...
then again, as i just read, my ip address is included so i shouldnt worry.. XD

as for firewalls... i dont belive i have any "personal" firewalls, but i use
the windows sp2 one, i'm not positive but i belive Norton Internet Security
has a firewall of somesort, and I'm connected on a wireless connection in the
house, so i think my router also has a firewall, not positive about that

and now for the testing, for the first one, the file sharing it told me my
IP address and after the "attempting" thing it says *too lazy to summerize*
- Your Internet port 139 does not appear to exist!
One or more ports on this system are operating in FULL STEALTH MODE!
Standard Internet behavior requires port connection attempts to be answered
with a success or refusal response. Therefore, only an attempt to connect to
a nonexistent computer results in no response of either kind. But YOUR
computer has DELIBERATELY CHOSEN NOT TO RESPOND (that's very cool!) which
represents advanced computer and port stealthing capabilities. A machine
configured in this fashion is well hardened to Internet NetBIOS attack and
intrusion.
and
-Unable to connect with NetBIOS to your computer.
All attempts to get any information from your computer have FAILED. (This is
very uncommon for a Windows networking-based PC.) Relative to vulnerabilities
from Windows networking, this computer appears to be VERY SECURE since it is
NOT exposing ANY of its internal NetBIOS networking protocol over the
Internet.

under common files it said "Your system has achieved a perfect "TruStealth"
rating. Not a single packet — solicited or otherwise — was received from your
system as a result of our security probing tests. Your system ignored and
refused to reply to repeated Pings (ICMP Echo Requests). From the standpoint
of the passing probes of any hacker, this machine does not exist on the
Internet. Some questionable personal security systems expose their users by
attempting to "counter-probe the prober", thus revealing themselves. But your
system wisely remained silent in every way. Very nice."
"GRC Port Authority Report created on UTC: 2005-05-24 at 21:32:19

Results from scan of ports: 0, 21-23, 25, 79, 80, 110, 113,
                            119, 135, 139, 143, 389, 443, 445,
                            1002, 1024-1030, 1720, 5000

    0 Ports Open
    0 Ports Closed
   26 Ports Stealth
---------------------
   26 Ports Tested

ALL PORTS tested were found to be: STEALTH.

TruStealth: PASSED - ALL tested ports were STEALTH,
                   - NO unsolicited packets were received,
                   - NO Ping reply (ICMP Echo) was received.
"

and for the last thing everything was green and i bleive it said the same
thing as the one before which was
"Your system has achieved a perfect "TruStealth" rating. Not a single packet
— solicited or otherwise — was received from your system as a result of our
security probing tests. Your system ignored and refused to reply to repeated
Pings (ICMP Echo Requests). From the standpoint of the passing probes of any
hacker, this machine does not exist on the Internet. Some questionable
personal security systems expose their users by attempting to "counter-probe
the prober", thus revealing themselves. But your system wisely remained
silent in every way. Very nice."

i WAS going to ask you if they're not just doing it all good to make you
say.. feel better XD, but you said you've been using them since 98 so...
doesnt seem so...
so i read that whole page and stuff (only understood a little) at the end
when they're taling about the port 113 stuff... did you want me to go step by
step and click the stuff, or is that only for that firewall users? (i got a
little lost there)

sorry you have to read this horrendiously long post... thank you ^^



Relevant Pages

  • [SLE] Tighten SuSEfirewall2
    ... SuSE 8.2 with a Dlink 302G adsl modem connected to etho and an internal ... The only machine needing internet is this primary box running ... 15 Ports Stealth ... Other than what is listed above, all ports are STEALTH. ...
    (SuSE)
  • Re: Port forwarding to a client for VOIP
    ... the ports aren't doing anything are going anywhere. ... Instant Messaging with ISA Server ... Firewall client can handle complex protocols without an application filter. ... Microsoft Internet Security & Acceleration Server: ...
    (microsoft.public.isa.configuration)
  • [VulnWatch] 3Com OfficeConnect Remote 812 ADSL router exposes internal LAN computers ports during ou
    ... ports during outbound and inbound TCP and UDP sessions. ... The 3Com 812 is a widely-deployed router, found in many ISPs ADSL lines. ... for internet access. ...
    (VulnWatch)
  • Re: What should I block out with my new firewall software?
    ... > block out that I don't use or need, like UDP or TCP. ... TCP/UDP on ports 135-139 and 445 are file sharing for networking. ... No one else, especially not internet IP ...
    (comp.security.firewalls)
  • RE: Port Forwarding XP Client
    ... 59101 and 6320 from the XP client to the internet. ... First could you tell me what the three ports are in aid of? ... from client to the internet. ... SBS Server on the router. ...
    (microsoft.public.windows.server.sbs)