Re: TCP Connection - Established

From: jmkanes (jmkanes_at_somewhere.com)
Date: 01/31/04


Date: Sat, 31 Jan 2004 03:22:15 GMT

In article <c7ESb.147041$5V2.785271@attbi_s53>, n9rou@n0spam-comcast.net
says...
> Port 1525 tcp is shown as used by Oracle applications in some port charts.
> Downloading and using TCPView from SysInternals will help by mapping ports to
> process/application and right clinking the process will give more information.
> If you have not done a spyware/parasite scan you may also want to do that as it
> could be spyware. SpyBot Search and Destroy in advanced mode/tools also will
> show processes and startup applications that may also shed some light on what
> the mystery port usage is. I believe Sygate may even be able to map ports to
> processes and has a traceback function via the logs. It definitely looks like a
> connection to an external address because of the address 207.33.111.82. ---
> Steve
>
> http://www.sysinternals.com/ntw2k/source/tcpview.shtml
> http://www.safer-networking.org/
>

Thanks Steve. I got a copy of TCPView and used it to identify the
process involved. It's the firewall! Sygate personal firewall pro.

Hmmm. I will try to contact Sygate and get their explanation. When I
get it I will let you know what it was.

Strange stuff.

Thanks again.

John.



Relevant Pages

  • Re: TCP Connection - Established
    ... Port 1525 tcp is shown as used by Oracle applications in some port charts. ... connection to an external address because of the address 207.33.111.82. ...
    (microsoft.public.win2000.security)
  • Re: Best free firewall software Kerio vs. Zone Alarm?
    ... I just noticed that BlackICE's intrusion detection system notices ... some firewall sites on the web, I got infected with the Worm32 virus. ... open port. ... It said Sygate was stealthing ALL ports. ...
    (comp.security.firewalls)
  • Re: Port 80
    ... close port 80 with Sygate PF. ... Make sure of these settings and nothing will install without you ... [[Specifies to automatically download and install Web components if a Web ...
    (microsoft.public.windowsxp.security_admin)
  • Re: svchost.exe and the internet.........HELP!!
    ... Svchost uses Dcom on port 135 which in turn negotiates a NetBIOS session on ... I use sygate to and if you create a advanced rule for svchost.exe .. ... i installed broadband on my home computer (running Windows ...
    (comp.security.firewalls)
  • Re: Sygate Security Bulletin
    ... > often recommend firewalls, Sygate among them. ... > attacker could gain access to a system with an open UDP port that was ... > protected by Sygate Personal Firewall by sending specially crafted UDP ... > Personal Firewall or Sygate Security Agent, or if NetBIOS Protection is ...
    (microsoft.public.security)