Re: strange TCP packets emited by server

From: Matt Scarborough (vexversa@verizon.net)
Date: 09/29/02


From: Matt Scarborough <vexversa@verizon.net>
Date: Sat, 28 Sep 2002 22:20:21 +0000


Do you use CA antivirus product, e.g., InoculateIT or eTrust?

Port 42510 is used to contact non-AV-Policy-compliant clients via RPC.

Matt Scarborough 2002-09-28

On Fri, 27 Sep 2002 09:26:27 +0200, Raphaël wrote
<#H6CKcfZCHA.392@tkmsftngp09>
> Hello ALL,
>
> I wonder what does mean those strange tcp packets which my Windows 2000
> Server System process is sending to all my domain's computers and the
> 0.0.0.192 adress.
> If think it is since I installed latest Windows 2000 PRE-SP4 Patches and
> reboot.
>
> extract from tcpview tool :
>
> System:8 TCP serveur1419 192.168.100.4:42510 SYN_SENT
> System:8 TCP serveur1421 192.168.100.5:42510 SYN_SENT
> System:8 TCP serveur1424 192.168.100.6:42510 SYN_SENT
> and many, many :
> System:8 TCP serveur 1450 0.0.0.192:42510 SYN_SENT
>
> This is anoying cause it's filling my firwall log on the 0.0.0.192 adress!
> Hope it is not harmfull.
>
> Thanx for any idea.
>



Relevant Pages

  • [NEWS] Buffer Overrun In RPCSS Service Could Allow Code Execution
    ... Remote Procedure Call (RPC) is a protocol used by the Windows operating ... There are three newly identified vulnerabilities in the part of RPCSS ... Service that deals with RPC messages for DCOM activation- ...
    (Securiteam)
  • [NT] Buffer Overrun in RPC Interface Could Allow Code Execution
    ... to promote the most advanced vulnerability assessment solutions today. ... Remote Procedure Call (RPC) is a protocol used by the Windows operating ... The attacker would be able to take any action on the system, ...
    (Securiteam)
  • Re: NTFRS
    ... The server holding the PDC role is down. ... Default-First-Site-Name\WIN2003 via RPC ... I have no Sysvol on the Windows 2003 server. ...
    (microsoft.public.win2000.active_directory)
  • Re: Does Microsoft Need a New Source Code for the Future?
    ... RPC, and/or not expose RPC to network surfaces (especially ... this into Internet exposure, and then rely on a firewall as a band ... I can disable RPC in Windows and still run software, ... Svyatoslav Pidgorny, MS MVP - Security, MCSE ...
    (microsoft.public.security)
  • [NT] Flaw in RPC Endpoint Mapper Could Allow Denial of Service Attacks
    ... Remote Procedure Call (RPC) is a protocol used by the Windows operating ... There is a vulnerability in the part of RPC that deals with message ... the attacker would begin the RPC ...
    (Securiteam)