Been Haxx0red.

From: Andrew Weaver (drew_at_orbityl.com)
Date: 06/11/03


Date: Wed, 11 Jun 2003 09:36:11 -0400


    Howdy, I have a server, it appears that someone has gained access to it
and installed a FXP daemon on it, its running on port 444, when I use FPORT
to try to determine where the file is, it shows this:

608 secsrvc -> 444 TCP C:\WINNT\System32\secsrvc.exe

if i do a dir c:\winnt\system32\secsrvc.exe

file not found

if I look for PID 608 in the task manager it doesnt exist.

Yet this stupid FXP daemon remains.

Fport hasnt ever failed me before so im not sure what to do ;-)
-Drew



Relevant Pages

  • RE: SYN_SENT to port 8081
    ... I received many responses to my ... fport only seems to be available for NT based OS's. ... You could narrow it down to the application utilizing the outgoing port ... I have a Windows 98 Second Edition machine that's consistently ...
    (Focus-Microsoft)
  • RE: Remote tool
    ... I know other tool that show port vs process "Essential Net Tool" ... Use fport is good solution but is not recommendable for server DMZ zone. ... Subject: Remote tool ... remotely use psexec from www.sysinternals.com. ...
    (Focus-Microsoft)
  • Re: FPORT issues
    ... >That's what I thought fport was for. ... >>the network on port 6666. ... I see the events in the firewall log, ... >>it runs, but lists NOTHING. ...
    (Security-Basics)
  • Re: FPORT issues
    ... :: wander around the network on port 6666. ... I dl-ed fport from foundstone.com at the ... If I run FPORT on my computer it lists a ton ... AFAIK IRC is the only thing that uses port 6666. ...
    (Security-Basics)
  • Re: Open Ports on windoze 95/98
    ... There is, for example, a port blocker from AnalogX, but little else. ... >> Click Intrusion Detection and Fport ... >> Freeware Oracle ... >Send FREE Valentine eCards with Yahoo! ...
    (Security-Basics)