Checking Port Activity with TCPView shows a lot of sqlservr.exe TIME_WAIT

From: msnews.microsoft.com (vincentnospamsoremovethistomailme_at_marlonpointandthenbe.com)
Date: 04/28/04


Date: Wed, 28 Apr 2004 13:22:51 +0200

Hi,

I used TCPView (http://www.sysinternals.com/ntw2k/source/tcpview.shtml) on a
Windows 2003 server, used as a webserver. The server is behind a firewall.
I saw a lot of entries like:

sqlservr.exe:1928 TCP 2colt397:ms-sql-s
rrcs-se-24-73-127-66.biz.rr.com:15628 TIME_WAIT
or
sqlservr.exe:1928 TCP 2colt397:ms-sql-s
rrcs-se-24-73-127-66.biz.rr.com:15628 SYN_RCVD

Is this a domain trying to find an open port to break in? What does the
TIME_WAIT part mean? Do I have to get worried or is this not that strange?

Thank you for your advice,
Vincent



Relevant Pages

  • Re: CEICW fails at firewall config
    ... Do you or do you not have ISA 2000 or ISA 2004 installed on the SBS server? ... Do you have 2 NICs in the SBS? ... CEICW fails on firewall configuration every time. ... >>> Call to Creating the protected networks access rule returned ok. ...
    (microsoft.public.windows.server.sbs)
  • Re: Recycler security issues on IIS server
    ... > latest upates to the server. ... > like to see the server put behind our firewall, ... other software, install all patches, IISlockdown, URLscan, use the correct ... the procedures you follow may vary depending on your security needs. ...
    (microsoft.public.inetserver.iis.security)
  • Re: ISA SERVER NOT STARTING
    ... I delete the nat/basic firewall and stop and started the RRAS an tried to ... There were no critical events in the DNS Server Log in the last 24 hours. ... An error occurred during logon ... Caller User Name: - ...
    (microsoft.public.windows.server.sbs)
  • Re: For Microsoft Partners and Customers Who Cant Download or Access
    ... to reconfigure the firewall, but to use a static IP on your client ... and to make sure that the DNS server entries on the client are ... Microsoft for msdn2.microsoft.com. ... use a static IP and set the DNS server addresses to the DNS ...
    (microsoft.public.dotnet.general)
  • RE: Is this as bad as it seems?
    ... The network being protected by the router or firewall is still vulnerable to ... > circumvented - the administrator has explicitly allowed HTTP traffic on ... this exploit has the effect of allowing the attacker to send *INBOUND* HTTP ... The HTTP server (located on the internal network or anywhere else that is ...
    (Security-Basics)