netstat output

From: David Jones (kk7gw_at_yahoo.com)
Date: 07/15/03


Date: Tue, 15 Jul 2003 13:34:14 -0700


Use netstat -ano

This will add a "Process ID" column on the far right.
After you get that, run "tasklist /svc", which will also
have a Process ID column. Match the two, and you'll have
the process that is using the port (which may have one
ore more services associated with it).

>-----Original Message-----
>I am running Windows XP Professional, all latest, SP,
>critical updates and security patches applied. Regarding
>netstat -a output, I can identify all LISTENING TCP
>ports, except for one that continues to change, not good.
>The port number has been 13802, 15489 and now 12900. I
>realize that this is limited info, any advice as to how
>to track down the service, other than turning off all
>services 1 by 1 ?
>.
>



Relevant Pages

  • Re: Have I been compromised? chkrootkit: "Warning: Possible LKM Trojan installed" - nmap:
    ... assuming netstat wasn't one of the programs ... listed there for port 1313 correspond to the PIDs chkproc spit out. ... all your services while you upgrade all the software that needs upgrading. ... > Every week or so I'll run chkrootkit, mostly just because I feel I ...
    (comp.os.linux.security)
  • RE: I think Ive been hacked...please help!
    ... > connecting within seconds of boot. ... port scanning the machine from the outside ... experience performing incident response activities, ... one will run netstat and see something listening on ...
    (Incidents)
  • Re: Help, my machine has been hacked
    ... >> also take a look at processes running in your system, ... >> opened (netstat -tupan), environment changesetc. ... If you provide port 80 to the outside ... filter invalid packets, in particular tcp scans with invalid flags, where ...
    (comp.os.linux.security)
  • Re: Detecting Internet activity
    ... connection and then use netstat tool to confirm whether or not the relevant ... port is 20 or 21. ... Title: Enhance netstat ... >- when I open a FTP connection, none of the listed ports match the ...
    (microsoft.public.win32.programmer.networks)
  • Re: Hidden windows ports, files and services.
    ... You need to get those processes that have port 21 open) ... so they will display in the regular task manager list by cleaning out ... whatever is hiding them, then determine what it was hiding. ... too sloppy to hide the port from netstat too. ...
    (Security-Basics)