Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.computer.security
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 10-17-2005, 12:24 AM
Doug Fox
Guest
 
Posts: n/a
Default What are these tcp ports?

Did an internal port scan on a number of Windows Server 2003 and found the
following ports, but they seems weired. Any
comments/suggestions/information are thankful.

85 (MIT ML Device)
264 (BGMP)
039 (Streamlined Blackhole)
1041 (AK2 Product)
1043 (BONIC Client Control)
$1051 (Optima VNET)
1052 (Dynamic DNS Tools)
1074 (FASTechnologies License Manager)
1098 (RMI Activation)
1106 (ISOIPSIGPORT-1)
1119 (Battle.net Chat/Game Protocol)
1208 (SEAGULL AIS)
1264 (PRAT)
1302 (Cl3-Software-2)
1360 (MIMER)
1366 (Novell NetWare Comm Service Platform) - We don't have Novell stuff on
our network!!
1378 Elan License Manager
4000 (Terabase)
5998 (Asp module for Apache servers(
6001 (Rainbow SuperPro Net network Services)
6071 (SSDTP)
6502 (BoKS Servm)
6503 (BoKS Clntd)
6504 ??

Best regards,



Reply With Quote
  #2 (permalink)  
Old 10-17-2005, 06:11 AM
Chuck
Guest
 
Posts: n/a
Default Re: What are these tcp ports?

On Sun, 16 Oct 2005 19:24:49 -0400, "Doug Fox" <dfox138-no-spam@hotmail.com>
wrote:

>Did an internal port scan on a number of Windows Server 2003 and found the
>following ports, but they seems weired. Any
>comments/suggestions/information are thankful.
>
>85 (MIT ML Device)
>264 (BGMP)
>039 (Streamlined Blackhole)
>1041 (AK2 Product)
>1043 (BONIC Client Control)
>$1051 (Optima VNET)
>1052 (Dynamic DNS Tools)
>1074 (FASTechnologies License Manager)
>1098 (RMI Activation)
>1106 (ISOIPSIGPORT-1)
>1119 (Battle.net Chat/Game Protocol)
>1208 (SEAGULL AIS)
>1264 (PRAT)
>1302 (Cl3-Software-2)
>1360 (MIMER)
>1366 (Novell NetWare Comm Service Platform) - We don't have Novell stuff on
>our network!!
>1378 Elan License Manager
>4000 (Terabase)
>5998 (Asp module for Apache servers(
>6001 (Rainbow SuperPro Net network Services)
>6071 (SSDTP)
>6502 (BoKS Servm)
>6503 (BoKS Clntd)
>6504 ??


Doug,

Suspecting a malware problem, why not start by checking for malware.
<http://nitecruzr.blogspot.com/2005/05/dealing-with-malware-adware-spyware.html>

Knowing that malware will use any ports that it considers convenient, not
according to registration, look at those ports using TCPView (free) from
<http://www.sysinternals.com/ntw2k/source/tcpview.shtml>

Once you identify the process(es) that have opened those ports, find the
relevant program modules, and submit them for analysis to Jotti and VirusTotal.
Find all components of those processes using Process Explorer (also free), and
run interesting components thru Jottia dn VirusTotal too.
<http://virusscan.jotti.org/>
<http://www.virustotal.com/flash/index_en.html>
<http://www.sysinternals.com/ntw2k/freeware/procexp.shtml>

--
Cheers,
Chuck, MS-MVP [Windows - Networking]
http://nitecruzr.blogspot.com/
Paranoia is not a problem, when it's a normal response from experience.
My email is AT DOT
actual address pchuck mvps org.

Reply With Quote
  #3 (permalink)  
Old 10-17-2005, 06:49 AM
Winged
Guest
 
Posts: n/a
Default Re: What are these tcp ports?

Doug Fox wrote:
> Did an internal port scan on a number of Windows Server 2003 and found the
> following ports, but they seems weired. Any
> comments/suggestions/information are thankful.
>
> 85 (MIT ML Device)
> 264 (BGMP)
> 039 (Streamlined Blackhole)
> 1041 (AK2 Product)
> 1043 (BONIC Client Control)
> $1051 (Optima VNET)
> 1052 (Dynamic DNS Tools)
> 1074 (FASTechnologies License Manager)
> 1098 (RMI Activation)
> 1106 (ISOIPSIGPORT-1)
> 1119 (Battle.net Chat/Game Protocol)
> 1208 (SEAGULL AIS)
> 1264 (PRAT)
> 1302 (Cl3-Software-2)
> 1360 (MIMER)
> 1366 (Novell NetWare Comm Service Platform) - We don't have Novell stuff on
> our network!!
> 1378 Elan License Manager
> 4000 (Terabase)
> 5998 (Asp module for Apache servers(
> 6001 (Rainbow SuperPro Net network Services)
> 6071 (SSDTP)
> 6502 (BoKS Servm)
> 6503 (BoKS Clntd)
> 6504 ??
>
> Best regards,
>
>

Seems odd to me since by default server 2003 Is locked down requiring
ports to be opened specifically. What software is installed on system?
I see battlenet which indicates at least 1 game service. It is
running BOINC which is a distributed computing platform.
The novell stuff is required for IPX. there is a virtual net installed
on system.

All of the nfo can be googled. Seems pretty straight forward to me.

This appears to be someones game server, I suspect perhaps battlenet
itself, though I haven't checked. But there are some pricey toys
installed on system, seems like one who administered such a system would
know what was there.

Winged

Reply With Quote
  #4 (permalink)  
Old 10-17-2005, 10:52 AM
Hairy One Kenobi
Guest
 
Posts: n/a
Default Re: What are these tcp ports?

"Doug Fox" <dfox138-no-spam@hotmail.com> wrote in message
news:2oGdnZruKfejfM_eRVn-ug@rogers.com...
> Did an internal port scan on a number of Windows Server 2003 and found the
> following ports, but they seems weired. Any
> comments/suggestions/information are thankful.


<snip>

http://www.codecutters.org/resources/knownports.html
http://www.codecutters.org/resources/regports.html

and their lik are the official lists: I would have half-suspected a mix-up
with ephermeral posts, but for that glaring port 85.

A few seconds in Google found this:
http://www.doshelp.com/Ports/Trojan_Ports.htm

There's a new -b parameter in XP's netstat - not sure if that's in 2003
(although I'd have thought so). systinternals.com provide duplicate
functionality, if you'd care to download.

HTH

Hairy One Kenobi

Disclaimer: the opinions expressed in this opinion do not necessarily
reflect the opinions of the highly-opinionated person expressing the opinion
in the first place. So there!



Reply With Quote
Sponsored Links
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Security & Ports. The One alt.computer.security 3 04-02-2007 05:54 AM
USB Card and Front Ports Grinder alt.comp.hardware 3 02-27-2007 10:09 PM
How to close the unnecessary Ports Nick alt.computer.security 26 10-25-2005 05:27 AM
Wireless router William alt.comp.hardware 28 08-09-2005 03:37 PM
Re: Router settings with VoIP - any explanatory documentation? Tony uk.telecom.voip 1 07-12-2005 12:03 AM


All times are GMT. The time now is 07:44 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45