Open Ports on 2003 Server (No firewall)

From: Bruce Vander Werf (bvanderw-news5021_at_mailblocks.com)
Date: 08/24/04

  • Next message: Steven L Umbach: "Re: Open Ports on 2003 Server (No firewall)"
    Date: Mon, 23 Aug 2004 21:40:27 -0500
    
    

    We have been having some problems with a hacker on a new 2003 Server.
    The server is not behind any type of firewall - it has a direct
    connection to the Internet.

    The following ports appear to be open:

    21: FTP
    80: HTTP
    445: Microsoft-DS, SMB over TCP
    1025: network blackjack, System V R3 listener (uucp)
    1026: MSTASK/Remote Login Network Terminal, nterm
    1027:
    1028:
    1030: BBN IAD
    1031: InetInfo, BBN IAD
    1032: InetInfo, BBN IAD
    3306: MySQL
    3389: MS Terminal Server
    13782: VERTIAS NetBackup

    The program names are what is being reported to us by a couple of
    different port scanners.

    Of these, we know FTP, HTTP, MySQL, and MS Terminal Server (Remote
    Desktop) are installed. Veritias NetBackup is also installed.

    What I don't know about are 445, 1025-1028, and 1030-1032. Can someone
    shed some light on what is listening on these ports and why they might
    need to be open?

    FWIW, it appears the hacker is using this box to store files.

    --Bruce
      


  • Next message: Steven L Umbach: "Re: Open Ports on 2003 Server (No firewall)"

    Relevant Pages

    • Re: [Full-Disclosure] Severe exploit found, all UNIX are affected!
      ... > I get into the bank and start to look around and I poke and prod the box ... > and always lost his wallet because he wore those baggy hacker pants). ... > It seems that this black head hacker, named Charlie Root, has been busy ... > I looked into the front directory on my server and saw a folder called ...
      (Full-Disclosure)
    • Re: 2003 Web Server - Sicherheitsbedenken
      ... dass die Hauptgefahr nicht irgendwelche Top Hacker ... Er hat doch gar kein Interesse, sich irgend einen Server genauer anzusehen! ... Windows ist in meinen Augen sicherheitstechnisch nicht unbedingt ... Eine richtige Firewall ist etwas feines - und richtig heisst, ...
      (microsoft.public.de.german.windows.server.setup)
    • Re: Which one is the best encryption algorithm
      ... > thinking about storing the Key itself within the code-behind DLL. ... If there is a significant risk that the hacker might gain ... the server, ... to use symmetric encryption in the way you had in mind. ...
      (borland.public.delphi.non-technical)
    • Re: VPN server
      ... > I am just testing installing a test VPN server in win2k machine. ... It's hard to tell what a file does and what a hacker did with it from a file ... installing and running an antivirus program might help as well. ... Installing Sygate firewall and running fprot from foundstone.com might also ...
      (microsoft.public.win2000.security)
    • Re: Is Hiding Server Controls Enough ?
      ... unlikely that a hacker would go to these lengths. ... These controls use JavaScript to send information ... > about themselves in hidden form fields back to the server. ...
      (microsoft.public.dotnet.framework.aspnet)