Solved

Interpreting Netstat Reports

Posted on 2001-07-13
12
674 Views
Last Modified: 2013-12-28
I've been told that the below indicates "OPEN PORTS".
that is what i'm trying to get away from.

Can someone tell me if this is true, Open Ports, and if it's the
UDP that specifies an open port or the *:*

D:\WINNT>netstat -a
UDP    my machine3cj:epmap  *:*
UDP    my machine3cj:microsoft-ds  *:*
UDP    my machine3cj:1025   *:*
UDP    my machine3cj:1027   *:*
UDP    my machine3cj:netbios-ns  *:*
UDP    my machine3cj:netbios-dgm  *:*
UDP    my machine3cj:isakmp  *:*
UDP    my machine3cj:2278   *:*
UDP    my machine3cj:2288   *:*

I'm using Zonealarm at present.
If I'm in the wrong area of experts-exchange please let me know.

Regards, Bud
http://www.wintrouble.net
0
Comment
Question by:smeebud
  • 5
  • 4
  • 3
12 Comments
 
LVL 63

Expert Comment

by:SysExpert
ID: 6281602
As long as these are on a LAN, then you have no problem.

I would use.

Test firewall ports  and port blocking
http://grc.com/

To see if you have any real problems
or use NMAP or similar to do intrusion testing.

I hope this helps !
0
 
LVL 14

Author Comment

by:smeebud
ID: 6282214
I was hoping for moremthan that.
i need to know how tom interprete these
thinks,
For instance, can you tell me which ports are open?
What does *:* mean, and so forth.

I'm not on a Lan.

Regards, Bud
http://www.wintrouble.net
0
 
LVL 63

Expert Comment

by:SysExpert
ID: 6282549

List of TCp/IP ports ports list, port list TCP ports list              
 http://www.joemagee.com/filez/port-numbers.txt

Most of the ports are ports that MS listens on, Netbios, DHCP, WINS, DNS
etc.

I hope the list I quoted will help.


0
Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

 
LVL 1

Expert Comment

by:l8knight
ID: 6282675
Hi smeebud,

basically what it is telling you is the

protocol -> TCP/UDP

hostname/computername -> my machine3cj

service/portnumber -> epmap or 80

connection status -> *:* or bab5:1046

*:* means that it is waiting for packets... you will only find this with UDP because it is a connectionless protocol i.e. you do not need to establish a connection before sending it data.

bab5:1046 means that it has a connection to a machine called bab5 on port 1046.
 

Hope this helps

l8knight
0
 
LVL 14

Author Comment

by:smeebud
ID: 6282689
|8knight,
 
You've hit on it.

*:* means that it is waiting for packets... you will only find this with UDP because it is a connectionless
protocol i.e. you do not need to establish a connection before sending it data.

What I want to know is, (Does *:*) mean an open port that port sniffers can access.

Regards, Bud
http://www.wintrouble.net
0
 
LVL 1

Expert Comment

by:l8knight
ID: 6282702
Yes, a port sniffer can tell that you have that port open... whether they can access it or not depends on what is using that port. If it is a backdoor program like "backoriface" then yes they could... if it is a DNS server then they could only use it for doing a DNS query.

l8knight
0
 
LVL 1

Expert Comment

by:l8knight
ID: 6282734
A port sniffer will only show what ports are active on machine...

You would then need to either to use a security vulnerability in the legitimate software e.g. running an executable via script directory in a Web Server or access illegimate software such back oriface.

there is no magic way of hackers gaining access to your machine.

keep adding security updates to your machine and use a virus checker (most of these will detect a trojan) and you should be fairly safe.

hope this explains it a little better

regards

l8knight
0
 
LVL 14

Author Comment

by:smeebud
ID: 6283713
it explains it very well.

I just like to know how to close these ports.
For instance I'm using ZoneAlarm.

There are sections in it where I can specify ports to lock.
But a port with the # 1025 is used for instance when I FTP.

So if I lock it, the FTP will just look for the next highr number.
I can't lock them all.

Reason I'm paraniod is last week as I was working my screen went black, locked tight.
When I shut down and tried to re-boot, the system didn't see any drives. it took two days to rebuild my boot loader,
but when I Restored Drive D:, where I have and was working on windows 2000 when system crashed, I saw that drive had been named "John".....

I never label my drives so I'm sure someone came in and did this.

Regards, Bud
http://www.wintrouble.net

0
 
LVL 63

Expert Comment

by:SysExpert
ID: 6283914
Zone Alarm - if kept updated is not easy to bypass.
It could have been a random label caused when you crashed.

Just use 2  updated virus scanners and keep your OS security patches updated also.

Turn off all sharing.

I hope this helps !
0
 
LVL 1

Expert Comment

by:l8knight
ID: 6285748
hi bud,

Sorry I have no experience whatsoever with ZoneAlarm so I can't tell you how to block/close ports with it. :-(

I wouldn't worry about outgoing ports that get opened while you are using internet software like ftp. Your software needs to open these to communicate with the internet.

Worry about the incoming ports that are always open.

A quick check is to close all you internet apps, then do a netstat -a and check the ports with a known port list like the one SysExpert provided a link to above. This way you can work out which services are using the ports. If the ports/services seem suspect or you can't match up the port number with a known service then I would think about blocking it.

Another thing you could do is get a list of ports that trojans are known to use... you should be able to find such a list at any good security orientated website.

cheers and good hunting

l8knight
0
 
LVL 1

Accepted Solution

by:
l8knight earned 200 total points
ID: 6285822
here's a trojan port list for you courtesy of TL Security

http://www.tlsecurity.net/trojanh.htm

l8knight
0
 
LVL 14

Author Comment

by:smeebud
ID: 6286228
Thanks you both sysexpert
and |8knight.

I'm going to have to give this port subject some serious study.

Regards, Bud
http://www.wintrouble.net
0

Featured Post

Free Tool: Postgres Monitoring System

A PHP and Perl based system to collect and display usage statistics from PostgreSQL databases.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently Microsoft released a brand new function called CONCAT. It's supposed to replace its predecessor CONCATENATE. But how does it work? And what's new? In this article, we take a closer look at all of this - we even included an exercise file for…
Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
The viewer will learn how to successfully create a multiboot device using the SARDU utility on Windows 7. Start the SARDU utility: Change the image directory to wherever you store your ISOs, this will prevent you from having 2 copies of an ISO wit…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question