Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.computer.security
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-19-2005, 10:39 PM
Patrick Sullivan
Guest
 
Posts: n/a
Default netstat -a question

I have been trying to figure out why this computer (Jim) has all these
ded.pacbell.net listeners in it. It's my boss's systenm, uses the same
connections I do, same software etc. But mine (w2005) looks more normal.
TIA!

Active Connections (in computer Jim)

Proto Local Address Foreign Address State
TCP jim:epmap ded.pacbell.net:0 LISTENING
TCP jim:microsoft-ds ded.pacbell.net:0 LISTENING
TCP jim:1025 ded.pacbell.net:0 LISTENING
TCP jim:1026 ded.pacbell.net:0 LISTENING
TCP jim:10110 ded.pacbell.net:0 LISTENING
UDP jim:microsoft-ds *:*

Active Connections (in computer w2005)

Proto Local Address Foreign Address State
TCP w2005:epmap w2005:0 LISTENING
TCP w2005:microsoft-ds w2005:0 LISTENING
TCP w2005:1025 w2005:0 LISTENING
TCP w2005:1026 w2005:0 LISTENING
TCP w2005:10110 w2005:0 LISTENING
UDP w2005:microsoft-ds *:*
UDP w2005:isakmp *:*

Patrick



Reply With Quote
  #2 (permalink)  
Old 07-21-2005, 02:26 PM
Wolfman's Brother
Guest
 
Posts: n/a
Default Re: netstat -a question

Patrick Sullivan wrote:

> I have been trying to figure out why this computer (Jim) has all these
> ded.pacbell.net listeners in it. It's my boss's systenm, uses the same
> connections I do, same software etc. But mine (w2005) looks more normal.
> TIA!
>
> Active Connections (in computer Jim)
>
> Proto Local Address Foreign Address State
> TCP jim:epmap ded.pacbell.net:0 LISTENING
> TCP jim:microsoft-ds ded.pacbell.net:0 LISTENING
> TCP jim:1025 ded.pacbell.net:0 LISTENING
> TCP jim:1026 ded.pacbell.net:0 LISTENING
> TCP jim:10110 ded.pacbell.net:0 LISTENING
> UDP jim:microsoft-ds *:*
>
> Active Connections (in computer w2005)
>
> Proto Local Address Foreign Address State
> TCP w2005:epmap w2005:0 LISTENING
> TCP w2005:microsoft-ds w2005:0 LISTENING
> TCP w2005:1025 w2005:0 LISTENING
> TCP w2005:1026 w2005:0 LISTENING
> TCP w2005:10110 w2005:0 LISTENING
> UDP w2005:microsoft-ds *:*
> UDP w2005:isakmp *:*
>
> Patrick


try the "-n" flag on the netstat command line. That'll show you the IP
addresses instead of the names, which might give you the clues you need.
My first guess would be that there's some oddiosity with the DNS.

How many network cards does the machine have?

What operating system are you using?

Chris
--
Minimal false-possitive packet matching for complex protocols with Linux
and IpTables .. http://www.lowth.com/rope


Reply With Quote
  #3 (permalink)  
Old 07-22-2005, 06:38 AM
Patrick Sullivan
Guest
 
Posts: n/a
Default Re: netstat -a question

Using Win2k on both machines, no NICs, just modems. I'll see what -n says
tomorrow, thanks.


"Wolfman's Brother" <my.address@is.chris.at.lowth.dot.com> wrote in message
news:voNDe.9603$Fx3.6879@newsfe7-gui.ntli.net...
> Patrick Sullivan wrote:
>
> > I have been trying to figure out why this computer (Jim) has all these
> > ded.pacbell.net listeners in it. It's my boss's systenm, uses the same
> > connections I do, same software etc. But mine (w2005) looks more normal.
> > TIA!
> >
> > Active Connections (in computer Jim)
> >
> > Proto Local Address Foreign Address State
> > TCP jim:epmap ded.pacbell.net:0 LISTENING
> > TCP jim:microsoft-ds ded.pacbell.net:0 LISTENING
> > TCP jim:1025 ded.pacbell.net:0 LISTENING
> > TCP jim:1026 ded.pacbell.net:0 LISTENING
> > TCP jim:10110 ded.pacbell.net:0 LISTENING
> > UDP jim:microsoft-ds *:*
> >
> > Active Connections (in computer w2005)
> >
> > Proto Local Address Foreign Address State
> > TCP w2005:epmap w2005:0 LISTENING
> > TCP w2005:microsoft-ds w2005:0 LISTENING
> > TCP w2005:1025 w2005:0 LISTENING
> > TCP w2005:1026 w2005:0 LISTENING
> > TCP w2005:10110 w2005:0 LISTENING
> > UDP w2005:microsoft-ds *:*
> > UDP w2005:isakmp *:*
> >
> > Patrick

>
> try the "-n" flag on the netstat command line. That'll show you the IP
> addresses instead of the names, which might give you the clues you need.
> My first guess would be that there's some oddiosity with the DNS.
>
> How many network cards does the machine have?
>
> What operating system are you using?
>
> Chris
> --
> Minimal false-possitive packet matching for complex protocols with Linux
> and IpTables .. http://www.lowth.com/rope
>




Reply With Quote
  #4 (permalink)  
Old 07-22-2005, 07:58 AM
winged
Guest
 
Posts: n/a
Default Re: netstat -a question

Patrick Sullivan wrote:
> Using Win2k on both machines, no NICs, just modems. I'll see what -n says
> tomorrow, thanks.
>
>
> "Wolfman's Brother" <my.address@is.chris.at.lowth.dot.com> wrote in message
> news:voNDe.9603$Fx3.6879@newsfe7-gui.ntli.net...
>
>>Patrick Sullivan wrote:
>>
>>
>>>I have been trying to figure out why this computer (Jim) has all these
>>>ded.pacbell.net listeners in it. It's my boss's systenm, uses the same
>>>connections I do, same software etc. But mine (w2005) looks more normal.
>>>TIA!
>>>
>>>Active Connections (in computer Jim)
>>>
>>> Proto Local Address Foreign Address State
>>> TCP jim:epmap ded.pacbell.net:0 LISTENING
>>> TCP jim:microsoft-ds ded.pacbell.net:0 LISTENING
>>> TCP jim:1025 ded.pacbell.net:0 LISTENING
>>> TCP jim:1026 ded.pacbell.net:0 LISTENING
>>> TCP jim:10110 ded.pacbell.net:0 LISTENING
>>> UDP jim:microsoft-ds *:*
>>>
>>>Active Connections (in computer w2005)
>>>
>>> Proto Local Address Foreign Address State
>>> TCP w2005:epmap w2005:0 LISTENING
>>> TCP w2005:microsoft-ds w2005:0 LISTENING
>>> TCP w2005:1025 w2005:0 LISTENING
>>> TCP w2005:1026 w2005:0 LISTENING
>>> TCP w2005:10110 w2005:0 LISTENING
>>> UDP w2005:microsoft-ds *:*
>>> UDP w2005:isakmp *:*
>>>
>>>Patrick

>>
>>try the "-n" flag on the netstat command line. That'll show you the IP
>>addresses instead of the names, which might give you the clues you need.
>>My first guess would be that there's some oddiosity with the DNS.
>>
>>How many network cards does the machine have?
>>
>>What operating system are you using?
>>
>>Chris
>>--
>>Minimal false-possitive packet matching for complex protocols with Linux
>>and IpTables .. http://www.lowth.com/rope
>>

>
>
>

I would think of potential ms rpc compromise though i can't be sure from
what's provided. Are these machines going through a common firewall or
is w2005 (your maachine) using boss machine as a network gateway?

I must be tired to ask the question...
winged

Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Question about Asus P4R800-VM motherboard Jethro alt.comp.hardware 3 03-22-2007 10:16 AM
Router Security Question... spooker Network Troubleshooting 3 10-11-2006 01:29 PM
Dell case cooling fan for XPS B-series ... rant and question The poster formerly known as Colleyville Alan alt.comp.hardware 16 10-07-2006 09:52 PM
OT question about small office server John Hyde comp.security.misc 14 10-13-2005 09:51 PM
Case Security Question Justin Case comp.security.misc 25 10-02-2005 06:25 PM


All times are GMT. The time now is 01:44 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45